CVE, NVD, and the Vulnerability Intelligence Ecosystem

A Common Vulnerability and Exposure (CVE) identifier is the universal language of vulnerability management. Assigned by CVE Numbering Authorities (CNAs) — MITRE, major vendors like Microsoft and Cisco, and coordinating bodies like CISA — a CVE ID (e.g., CVE-2021-44228, the Log4Shell vulnerability) uniquely identifies a specific flaw in a specific product version. The National Vulnerability Database (NVD), maintained by NIST, enriches CVE entries with CVSS scores, CWE classifications, CPE applicability statements (what product versions are affected), and reference links to vendor advisories, exploit databases, and patches.