NIST National Vulnerability Database CVEs (last 2 years, 50k+ cybersecurity vulnerabilities)

Dataset · National Institute of Standards and Technology · primary source ↗

Every cybersecurity CVE published in the last 2 years from NIST NVD — typically 50-80k records. Each row: CVE ID, source identifier, published + last_modified dates, vulnerability status, English description, CVSS v3 base score + severity (CRITICAL/HIGH/MEDIUM/LOW) + vector string, CVSS v2 fallback, CWE Common Weakness IDs, top reference URLs, count of affected CPE configurations. Powers /cve/{CVE-ID} canonical Article pages with deep links to nvd.nist.gov + cve.org + vendor advisories. Superset of CISA KEV (which only tracks known-exploited).

Source agency
National Institute of Standards and Technology
License
CC0 / US public domain
Coverage
50,000+ recent CVEs
API endpoint

Keywords

CVENVDcybersecurity vulnerabilityCVSSCWEcritical vulnerabilitypatch management

Provenance

Every record in this dataset can be traced back to its primary source at https://nvd.nist.gov/developers/vulnerabilities. Underlying content is a US federal government work (public domain under 17 USC §105); our derived data is licensed CC0 1.0.

For agents