Vulnerabilities Checklists Product Dictionary Impact Metrics Data Feeds Statistics
Home ISAP/SCAP SCAP Validated Tools SCAP Events About Contact Vendor Comments
Mission and Overview
NVD is the U.S. government repository of standards based vulnerability management data. This data enables automation of vulnerability management, security measurement, and compliance (e.g. FISMA).
Resource Status

NVD contains:

32678 CVE Vulnerabilities
161Checklists
151 US-CERT Alerts
2257 US-CERT Vuln Notes
2097OVAL Queries

Last updated:  09/15/08

CVE Publication rate:

11 vulnerabilities / day
Email List

NVD provides four mailing lists to the public. For information and subscription instructions please visit NVD Mailing Lists

Workload Index
Vulnerability Workload Index: 6.66
About Us

NVD is a product of the NIST Computer Security Division and is sponsored by the Department of Homeland Security’s National Cyber Security Division. It supports the U.S. government multi-agency (OSD, DHS, NSA, DISA, and NIST) Information Security Automation Program. It is the U.S. government content repository for the Security Content Automation Protocol (SCAP).

NVD Announcement and Discussion Lists

How to Subscribe
Below are the four discussion lists provided by NVD. Please subscribe to the below lists by selecting the "Subscribe" hyperlink located to the right of each list. The "Subscribe" hyperlink will open your email client with a pre-populated message, simply send the message in order to subscribe. You will then receive an email confirmation of your request. Please see the bottom of this page for manual subscription instructions as well as troubleshooting information.

NVD Announcements List (Subscribe) (UnSubscribe)
The NVD staff maintain a mailing list for sending out announcements regarding NVD developments. The list is extremely low volume and subscribers should expect to receive only a few e-mails a year. We appreciate the opportunity to keep you updated on recent developments.

Checklist/SCAP Announcements List (Subscribe) (UnSubscribe)
The NVD staff maintain a mailing list for sending out announcements regarding the Security Content Automation Protocol (SCAP), the National Checklist Program (NCP), and the SCAP Validation Program. The list is extremely low volume and subscribers should expect to receive only a few e-mails a year. We appreciate the opportunity to keep you updated on recent developments.

SCAP Discussion List (Subscribe) (UnSubscribe)
The NVD staff maintain a moderated discussion list that users can post to, regarding the Security Content Automation Protocol (SCAP). This list is moderate in volume.

XCCDF Discussion List (Subscribe) (UnSubscribe)
The NVD staff maintain a moderated discussion list that users can post to, regarding the Extensible Configuration Checklist Description Format (XCCDF). This list is moderate in volume.


Manual Subscription Process
To manually subscribe to an NVD mailing list please follow the instructions below:
  1. Open a blank email message and enter "listproc@nist.gov in the 'To' field.
  2. In the body of the email type 'subscribe' followed by the specific mailing list name. For example, in order to subscribe to the NVD Announcements mailing list the text "subscribe nvdupdate" must appear in the body of the email message. Below is a listing of the official NVD mailing list names:
    • nvdupdate - NVD Announcements List
    • scap-update - Checklist/SCAP Announcements List
    • scap-dev - SCAP Discussion List
    • xccdf-dev - XCCDF Discussion List
  3. Ensure that there are no spaces or carriage returns following the body of the pre-populated email message.
  4. Send message
Troubleshooting
Please ensure that there are no spaces or carriage returns following the body of the pre-populated email message. Extra spaces or carriage returns will usually result in the following error: "You attempted to subscribe to or unsubscribe from a mailing list ("mailing-list-name=20") that that is not hosted by this system"

Return to the NVD Home Page

Disclaimer Notice & Privacy Statement / Security Notice

Send comments or suggestions to nvd@nist.gov

NIST Computer Security Resource Center (CSRC)

NIST is an Agency of the U.S. Commerce Department

Full vulnerability listing