NIST National Vulnerability Database CVEs (last 2 years, 50k+ cybersecurity vulnerabilities)

Dataset · National Institute of Standards and Technology · source URL ↗

Every cybersecurity CVE published in the last 2 years from NIST NVD — typically 50-80k records. Each row: CVE ID, source identifier, published + last_modified dates, vulnerability status, English description, CVSS v3 base score + severity (CRITICAL/HIGH/MEDIUM/LOW) + vector string, CVSS v2 fallback, CWE Common Weakness IDs, top reference URLs, count of affected CPE configurations. Powers /cve/{CVE-ID} canonical Article pages with deep links to nvd.nist.gov + cve.org + vendor advisories. Superset of CISA KEV (which only tracks known-exploited).

Source organization
National Institute of Standards and Technology
License / terms
Coverage
50,000+ recent CVEs
Latest local indexed-row date
2026-05-18
API endpoint

Keywords

CVENVDcybersecurity vulnerabilityCVSSCWEcritical vulnerabilitypatch management

Provenance

The listed URL identifies a referenced source; it does not by itself document the ingestion endpoint. Referenced source URL: https://nvd.nist.gov/developers/vulnerabilities. Source-specific terms apply. US federal employee-authored works are generally public domain under 17 USC 105; non-federal and third-party material retains source terms. Free or keyless access does not alter source terms. Metadata and normalization authored by MORVS (AI Analytics LLC) are CC0 only where expressly stated.

For agents