we_are_coded.by CODE · The world, decoded
БГ
Who's who

NVD and who counts the holes

The BasicsUpdated on 13 July 2026we are coded

One system holds the registry of known holes in software. The other walks the internet every night - checking which of them are already open doors.

Checked on13 July 2026
In short: NVD is the official US registry where every publicly known hole in software gets a number and a rating of how dangerous it is. It's run by NIST, a federal standards lab. The problem: in 2026 the registry choked on the sheer volume of holes and stopped describing most of them. Shadowserver is a different organization that doesn't wait for someone to bring it the case - it walks the internet every day and checks who has already fallen through the hole.

Every hole in software gets a name in the CVE format (Common Vulnerabilities and Exposures) - something like a registration number, but for a breach in code. The numbers are issued by companies and researchers with the right to hand out such numbers - listed as a CNA (CVE Numbering Authority). But the bare number says nothing about the danger. That's where NVD steps in - the National Vulnerability Database. It's run by NIST (National Institute of Standards and Technology), the US federal standards lab, the same one that defines how a kilogram and a second are measured. NVD takes the number and slaps a label on it: how dangerous it is by CVSS (Common Vulnerability Scoring System, a score from zero to ten), which product it affects, how it's used in an attack.

But holes don't stop appearing, and in recent years they've been pouring in at a pace NIST can't digest. The registry clogged up - thousands of CVE numbers waited months, even years, for someone to tag them with a danger rating. Between 2020 and 2025 alone, submitted CVEs jumped by 263% - a pace the team can't catch up to no matter how much it speeds up. In April 2026 NIST essentially threw up its hands: it announced it would now only label what's a priority - holes already actively used in attacks, holes in federal government software, and software declared critical by presidential order. Everything published before March 2026 and left unprocessed goes into the "Not Scheduled" category. Put simply, nobody promises it a label anymore.

While NVD is a registry that waits for a case to be brought to it, the Shadowserver Foundation (an independent nonprofit) doesn't wait. It scans the entire addressable internet - the billions of IPv4 addresses (addresses from the old, still the most widespread device-numbering system) - every day. It doesn't ask who reported the problem; it finds on its own which device has been left open, which is already infected, which site is compromised right now. Then it sends free daily reports to more than 8,000 vetted subscribers - network owners and national cybersecurity teams around the world.

The two systems do different jobs on the same registry of damage. NVD is the catalog of known defects: what's broken in principle, where the hole in the code sits. Shadowserver is the walk on the ground: who specifically stands with an open door right now, who's already been robbed through it. One says 'this type of lock breaks easily'. The other knocks on doors and checks exactly which one is broken tonight.

If the registry stops describing half the damage, the damage doesn't disappear. Only the knowledge of it does.

Where the risk is

Let's not kid ourselves - a US government body, buried in work, threw up its hands and said "we'll only watch what matters". The problem is that "what matters" on paper means "already hit or on the government's list". Everything else hangs in a waiting room with no diagnosis, while a pile of automated tools around the world pull exactly those labels to decide whether something is dangerous.

For a team guarding its own perimeter, the conclusion is simple: don't rely on one source telling you "it's clean". The registry tells you what's known. The walk on the ground tells you what's real. I want both, because "unverified" isn't "safe" - it's just unverified, and that's exactly the distinction we hold onto.

The visual is generated code art. No third-party images.
Official primary sources
→NIST - NVD Updates Operations to Address Record CVE Growth (April 15, 2026: priority only for KEV/federal/critical software; everything published before March 1, 2026 goes to 'Not Scheduled'; +263% submitted CVEs between 2020 and 2025)→Shadowserver Foundation - What We Do (daily internet scanning, free reports to more than 8,000 vetted subscribers)