Methodology
No single source has been complete since April 2026.
NIST abandoned universal CVE enrichment on 15 April 2026. Roughly 29,000 backlogged records were reclassified Not Scheduled and will never receive the applicability data version matching needs. Any product still describing itself as an NVD comparison is missing them silently.
Operational sources and the source roadmap
Status is explicit. Planned feeds are not counted as current finding coverage.
| Source | Contribution | Status | Licence |
|---|---|---|---|
| OSV.dev | PURL-native ecosystem ranges for package matching | Live | Apache-2.0 |
| CISA KEV | Confirmed exploitation in the wild | Operational enrichment | Free |
| EPSS v4 (FIRST) | 30-day exploit probability | Operational enrichment | Free |
| NVD API 2.0 | CPE applicability statements where they exist | Connector only; not synced | Public domain |
| CVE Program 5.1 | CNA-supplied affected ranges and CVSS | Planned | Free |
| CISA Vulnrichment | CVSS, CWE and SSVC for records NVD skipped | Planned | Public domain |
| VulnCheck NVD++ | NVD mirror and independent enrichment | Planned | Free, attribution required |
| GitHub Advisory Database | Open-source advisories | Planned | CC-BY-4.0 |
| Vendor CSAF and OVAL | Authoritative fixed versions and backports | Planned | Free |
| ENISA EUVD | EU identifiers for CRA workflows | Planned | Free |
Prioritisation, layered
CVSS is a filter, not a ranking. A 9.8 with a 0.04% exploit probability and no KEV entry is less urgent than a KEV-listed 7.5.
CVSS
Reduces the corpus. Ranks nothing on its own.
CISA KEV
A fact, not a forecast: it is being exploited right now.
EPSS v4
Probability over the next 30 days. Covers the unenriched backlog.
SSVC
Turns the signals into act, attend, track-star or track.
Your context
Exposure, asset tier, compensating controls. The part no feed contains.
BOD 26-04
Exposed, exploited, automatable and total control together mean three days.
Questions
What exactly changed at the NVD in 2026?
On 15 April 2026 NIST announced it would no longer routinely enrich all CVEs, moving to a risk-based model that prioritises vulnerabilities in CISA's KEV catalogue and in software used by the US federal government. Around 29,000 backlogged CVEs published before 1 March 2026 were reclassified as Not Scheduled. Those records will never receive CPE applicability data, which is precisely the data that version-range matching depends on.
Why does provenance per field matter?
Because a CVSS score's origin now carries information. A score asserted by the CNA, one analysed by NVD, and one injected by CISA's ADP container are different claims with different reliability. Collapsing them into a single number hides real uncertainty from the person deciding what to patch. Cidra shows which source supplied each field.
How is the priority score calculated?
CVSS contributes a modest weight because it filters rather than ranks. A KEV listing adds substantially, and a known-ransomware association adds more. EPSS contributes proportionally to the probability. Exposure and asset criticality — the only inputs a competitor cannot copy from a public feed — finish it, and a low-confidence identity match reduces the score. When exposure, KEV, automatability and total system control all apply, the SLA drops to the three-day clock BOD 26-04 sets. Every finding shows its own arithmetic.