Searching for vulnerabilities in the NVD
In this section, we’ll look at how to search for and find vulnerabilities in NIST’s NVD.
Introducing NIST’s NVD
If we use the NIST NVD to get information about a specific CVE identifier, then we can see more information including the severity of the vulnerability, a Common Vulnerability Scoring System (CVSS) code, and a base score depending on the criticality level. For example, the following URL – https://nvd.nist.gov/vuln/detail/CVE-2023-0001 – contains information about the first vulnerability found in 2023.
CVSS scores provide a set of standard criteria that makes it possible to determine which vulnerabilities are more likely to be successfully exploited. The CVSS score introduces a system for scoring vulnerabilities, considering a set of standardized and easy-to-measure criteria.
Vulnerabilities are given a high, medium, or low severity in the scan report. The severity is dependent on...