Mission and Overview
NVD is the U.S. government repository of standards based vulnerability management data. This data enables automation of vulnerability management, security measurement, and compliance (e.g. FISMA).
Resource Status
NVD contains:

Last updated: 10/31/2014 7:29:38 AM

CVE Publication rate: 46.4

Email List

NVD provides four mailing lists to the public. For information and subscription instructions please visit NVD Mailing Lists

Workload Index
Vulnerability Workload Index: 13.81
About Us
NVD is a product of the NIST Computer Security Division and is sponsored by the Department of Homeland Security's National Cyber Security Division. It supports the U.S. government multi-agency (OSD, DHS, NSA, DISA, and NIST) Information Security Automation Program. It is the U.S. government content repository for the Security Content Automation Protocol (SCAP).

Official Common Platform Enumeration (CPE) Dictionary

CPE is a structured naming scheme for information technology systems, software, and packages. Based upon the generic syntax for Uniform Resource Identifiers (URI), CPE includes a formal name format, a method for checking names against a system, and a description format for binding text and tests to a name.

Below is the current official version of the CPE Product Dictionary. The dictionary provides an agreed upon list of official CPE names. The dictionary is provided in XML format and is available to the general public. Please check back frequently as the CPE Product Dictionary will continue to grow to include all past, present and future product releases. The CPE Dictionary is updated nightly when modifications or new names are added. Archived CPE dictionaries are available at http://static.nvd.nist.gov/feeds/xml/cpe/dictionary/.

As of December 2009, The National Vulnerability Database is now accepting contributions to the Official CPE Dictionary. Organizations interested in submitting CPE Names should contact the NVD CPE team at cpe_dictionary@nist.gov for help with the processing of their submission.

The CPE Dictionary hosted and maintained at NIST may be used by nongovernmental organizations on a voluntary basis and is not subject to copyright in the United States. Attribution would, however, be appreciated by NIST.

CPE Dictionary:

  1. official-cpe-dictionary_v2.3.xml - 24.06MB, Updated: 10/30/2014 12:33:39 AM EST - gz format
  2. official-cpe-dictionary_v2.2.xml - 26.46MB, Updated: 10/30/2014 12:33:39 AM EST - gz format
  3. CPE Dictionary Search
  4. CPE Dictionary Growth Statistics

CPE Standards Information

  1. General information on CPE
  2. The CPE 2.3 XML Schema
  3. The CPE 2.3 Dictionary Extension XML Schema
  4. The CPE 2.2 XML Schema

NIST Dictionary CPE Repository Metadata

  1. The NIST CPE Metadata 0.2 XML Schema