CidraOpen the platform

Methodology

No single source has been complete since April 2026.

NIST abandoned universal CVE enrichment on 15 April 2026. Roughly 29,000 backlogged records were reclassified Not Scheduled and will never receive the applicability data version matching needs. Any product still describing itself as an NVD comparison is missing them silently.

Operational sources and the source roadmap

Status is explicit. Planned feeds are not counted as current finding coverage.

SourceContributionStatusLicence
OSV.devPURL-native ecosystem ranges for package matchingLiveApache-2.0
CISA KEVConfirmed exploitation in the wildOperational enrichmentFree
EPSS v4 (FIRST)30-day exploit probabilityOperational enrichmentFree
NVD API 2.0CPE applicability statements where they existConnector only; not syncedPublic domain
CVE Program 5.1CNA-supplied affected ranges and CVSSPlannedFree
CISA VulnrichmentCVSS, CWE and SSVC for records NVD skippedPlannedPublic domain
VulnCheck NVD++NVD mirror and independent enrichmentPlannedFree, attribution required
GitHub Advisory DatabaseOpen-source advisoriesPlannedCC-BY-4.0
Vendor CSAF and OVALAuthoritative fixed versions and backportsPlannedFree
ENISA EUVDEU identifiers for CRA workflowsPlannedFree

Prioritisation, layered

CVSS is a filter, not a ranking. A 9.8 with a 0.04% exploit probability and no KEV entry is less urgent than a KEV-listed 7.5.

CVSS

Reduces the corpus. Ranks nothing on its own.

CISA KEV

A fact, not a forecast: it is being exploited right now.

EPSS v4

Probability over the next 30 days. Covers the unenriched backlog.

SSVC

Turns the signals into act, attend, track-star or track.

Your context

Exposure, asset tier, compensating controls. The part no feed contains.

BOD 26-04

Exposed, exploited, automatable and total control together mean three days.

Questions

What exactly changed at the NVD in 2026?

On 15 April 2026 NIST announced it would no longer routinely enrich all CVEs, moving to a risk-based model that prioritises vulnerabilities in CISA's KEV catalogue and in software used by the US federal government. Around 29,000 backlogged CVEs published before 1 March 2026 were reclassified as Not Scheduled. Those records will never receive CPE applicability data, which is precisely the data that version-range matching depends on.

Why does provenance per field matter?

Because a CVSS score's origin now carries information. A score asserted by the CNA, one analysed by NVD, and one injected by CISA's ADP container are different claims with different reliability. Collapsing them into a single number hides real uncertainty from the person deciding what to patch. Cidra shows which source supplied each field.

How is the priority score calculated?

CVSS contributes a modest weight because it filters rather than ranks. A KEV listing adds substantially, and a known-ransomware association adds more. EPSS contributes proportionally to the probability. Exposure and asset criticality — the only inputs a competitor cannot copy from a public feed — finish it, and a low-confidence identity match reduces the score. When exposure, KEV, automatability and total system control all apply, the SLA drops to the three-day clock BOD 26-04 sets. Every finding shows its own arithmetic.