Vulnerabilities Checklists Product Dictionary Impact Metrics Data Feeds Statistics
Home SCAP SCAP Validated Tools SCAP Events About Contact Vendor Comments
Mission and Overview
NVD is the U.S. government repository of standards based vulnerability management data. This data enables automation of vulnerability management, security measurement, and compliance (e.g. FISMA).
Resource Status

NVD contains:

39671 CVE Vulnerabilities
129Checklists
187 US-CERT Alerts
2351 US-CERT Vuln Notes
2517OVAL Queries

Last updated:  11/20/09

CVE Publication rate:

12 vulnerabilities / day
Email List

NVD provides four mailing lists to the public. For information and subscription instructions please visit NVD Mailing Lists

Workload Index
Vulnerability Workload Index: 6.19
About Us

NVD is a product of the NIST Computer Security Division and is sponsored by the Department of Homeland Security’s National Cyber Security Division. It supports the U.S. government multi-agency (OSD, DHS, NSA, DISA, and NIST) Information Security Automation Program. It is the U.S. government content repository for the Security Content Automation Protocol (SCAP).

Security Content Automation Protocol Content Utilities

This page contains utilities available to help ease the process of working with the security content automation XML files. The files are in the Extensible Configuration Checklist Description Format (XCCDF) and the Open Vulnerability Assessment Language (OVAL) format. The content files are large and difficult to browse with a basic text editor, so the following tools are available to help edit and read the content.

The following utilities are standard XSL stylesheets. They can be used with any tool that can perform transformations using XSL.

Document Generator XSL Stylesheet - Example (Using stylesheet with Windows XP XCCDF)
This XSL stylesheet pulls together the different descriptions that have been provided in an XCCDF file and generates an HTML file that attempts to replicate the paper guidance that many are used to. In short, it transforms the XCCDF file into a text document that someone can read.
Thanks to Drew Buttner of Mitre for developing and contributing this utility.

CCE Mapping XSL Stylesheet - Example (Using stylesheet with Windows XP XCCDF)
This XSL Stylesheet generates a tab delimited list of references that serves as the CCE mapping for all the sources represented in the XCCDF file. The mapping should be sent to the CCE team at MITRE to help build up the CCE dictionary. **NOTE** This stylesheet has been hardcoded for the NSA, DISA, and NIST guides. Some tweaking will have to be done to produce a mapping for other guides.
Thanks to Drew Buttner of Mitre for developing and contributing this utility.

GPOAccelerator Checklist
The GPOAccelerator automatically deploys the security recommended settings (Group Policy Objects) in the Windows Server 2008 Security Guide, 2007 Microsoft Office Security Guide, the Windows Vista Security Guide and the Windows XP Security Guide.