Live CVE Feed: Real-Time Vulnerability Intelligence for Your Organization
Live CVE Feed: Real-Time Vulnerability Intelligence for Your Organization
On April 15, 2026, NIST effectively stopped enriching the majority of CVEs. Only KEV entries, federal CVEs, and EO 14028 critical-software CVEs receive full CVSS and CPE enrichment. The rest land in "Awaiting Analysis" or "Not Scheduled" with bare CNA submissions. When CVE-2024-3094 (the xz backdoor) demonstrated that supply-chain vulnerabilities can sit in plain sight for years, the security community learned that enrichment latency is not an inconvenience --- it is an attack surface.
Why Now: The NVD Policy Change and CISA BOD 26-04
The April 2026 NVD policy change is not a temporary backlog. It is a deliberate scope reduction. NIST will enrich only three categories going forward: CISA KEV entries, federal information system CVEs, and EO 14028 critical-software CVEs. Everything else --- the vast majority of the vulnerability ecosystem --- receives no NVD CVSS score, no CPE matching, no CWE classification.
This coincides with CISA BOD 26-04 (issued June 10, 2026), which replaces blanket patch-in-14-days directives with risk-based remediation timelines. Agencies must prioritize based on exploitation probability, asset criticality, and business impact --- metrics that require enrichment NVD no longer provides. Organizations running vulnerability management pipelines anchored on NVD CVSS scores are now operating on degraded intelligence, making risk-based prioritization decisions without the data those decisions require.
CVSS without context is noise, not intelligence. A CVSS 9.8 on an isolated build server is not the same risk as a CVSS 6.5 on an internet-facing CUI system with active exploitation. The NVD gave you the 9.8 and the 6.5. It never gave you the context. Now it does not even give you the scores.
What the Live CVE Feed Is
A continuously updated vulnerability intelligence service that aggregates, correlates, and enriches CVE data from 12+ authoritative sources, delivering sub-3-hour enrichment on new disclosures.
Available at two levels:
- Public (unauthenticated): Free, searchable, filterable vulnerability intelligence. CC-BY-4.0 licensed. Rate-limited at 100 requests per minute per IP.
- Organizational (authenticated): CVE impact mapped to your specific asset inventory, compliance framework exposure, and TRACE Score prioritization.
Both tiers served via REST APIs designed for integration into existing tooling.
The Data Pipeline: 12+ Sources, One Enriched Record
Every CVE record is assembled from a deliberately wide set of upstream sources:
| Source | Authority Tier | What It Provides |
|---|---|---|
| NIST NVD | Tier 1 | CVSS vectors, CWEs, CPE match criteria (when available) |
| VulnCheck Extended KEV | Tier 1 | Known Exploited Vulnerability status (superset of CISA KEV) |
| OSV.dev | Tier 2 | CVSS, affected version ranges for open-source packages |
| GitHub Security Advisory DB | Tier 2 | CVSS, affected ranges, patch references |
| CNA-submitted (CVE.org) | Tier 2 | CNA-only CVSS when NVD has not enriched |
| Metasploit Framework | Tier 3 | Weaponized exploit module availability |
| Exploit-DB | Tier 3 | Public proof-of-concept availability |
| Nuclei Templates | Tier 3 | Detection template availability |
| EPSS daily snapshots | -- | Exploitation probability (0-1 daily prediction) |
| Vendor advisories | -- | Patch availability, affected product confirmation |
| CISA KEV Catalog | -- | Binding operational directive applicability |
Authority tiers reflect a deliberate hierarchy. Tier 1 values take precedence over Tier 2 or 3 for the same field. All sources contribute to per-field confidence, but their weights prevent a Tier 3 proof-of-concept observation from pretending to know more than it does.
Enrichment Pipeline
When a new CVE is published anywhere in the ecosystem:
- Ingest --- new records on a 2-hour sync cycle; enrichment typically completes within 3 hours of NVD publication.
- Correlate --- match vendor advisories to CVE identifiers, link exploit database entries, cross-reference GitHub Security Advisories with affected package ecosystems.
- Enrich --- CVSS scoring from the best available source, CWE classification, EPSS exploitation probability, KEV status, exploit maturity signals, affected product/version ranges.
- Publish --- enriched record to the public feed with full per-field provenance: every data point cites its source, confidence level, and observation timestamp.
Per-Field Provenance and Confidence
Every field carries provenance metadata. You know whether a CVSS score came from NVD (Tier 1, 0.95 confidence) or a CNA submission (Tier 2, 0.80 confidence). In a post-NVD world, this distinction determines whether you trust the score enough to base a remediation decision on it.
The Public Feed: Free Intelligence for the Security Community
Four unauthenticated endpoints:
Single CVE Lookup --- full enriched record for any CVE: CVSS, CWE, EPSS, KEV status, exploit availability, affected products, patch references, all with per-field provenance.
Recently Enriched --- paginated list of CVEs enriched within a configurable window (24h, 7d, 30d). The endpoint most integrators poll.
NVD Gap Coverage --- CVEs that Advisedly has scored and enriched but NVD has not. Post-April 2026, this surfaces the growing delta. The gap is measured in tens of thousands.
Coverage Statistics --- aggregate metrics: total tracked, total enriched, NVD-gap count, enrichment latency percentiles, source coverage breakdowns.
Filtering by severity, vendor/product (CPE-based), date range, KEV status, EPSS threshold, and exploit availability.
Organizational Context: CVEs That Matter to You
Authenticated users gain organizational context on top of the raw intelligence:
Asset impact mapping. Every CVE cross-referenced against your inventory. An internet-facing web server running the affected library is a different risk than an isolated build agent. The feed reflects that.
Compliance framework impact. Through the cross-framework crosswalk engine, each CWE maps to affected controls across your contracted frameworks. A single CVE on a regulated workload might affect NIST 800-53, ISO 27001, CMMC L2, PCI DSS, and HIPAA simultaneously. The organizational view shows the union.
TRACE Score integration. Per-asset, per-organization prioritization: Threat, Reachability, Asset criticality, Compliance impact, Exploit maturity. Produces a 0-100 score. A CVSS 9.8 on an isolated build agent scores differently than the same CVE on an internet-facing CUI system. Every score is reproducible from persisted signal references --- a federal auditor can replay it offline weeks later and arrive at the same number.
Affected systems dashboard. Assets by criticality, remediation status through the full lifecycle (discovered, acknowledged, in progress, verified fixed), automated POA&M entries for compliance-driven organizations.
API Access for Integration
Designed for programmatic consumption:
- SIEM enrichment --- CVE context in correlation rules. When a detection fires on exploit traffic, the feed provides EPSS, KEV status, and exploit maturity.
- Ticketing automation --- new high-severity CVEs into remediation workflow, filtered by EPSS threshold or KEV status.
- Scanner correlation --- enrich scanner output with data scanners do not provide (EPSS, TRACE Score, compliance impact).
- Compliance reporting --- CVE-to-control mappings for evidence packages across frameworks and information systems.
Why This Is Not Another NVD Mirror
Multi-source enrichment. NVD mirrors give you NVD data with NVD latency. The CVE feed aggregates 12+ sources independently. When NVD has not scored a CVE, the feed provides CNA scores, EPSS predictions, and exploit intelligence NVD never carried.
Per-field provenance. Every data point cites its source and confidence. Mirrors strip this context.
Organizational context. Mirrors give you the vulnerability universe. The authenticated feed gives you the vulnerabilities that matter to your organization, mapped to your assets, frameworks, and risk posture.
TRACE Score integration. No mirror provides per-asset prioritization accounting for threat intelligence, reachability, asset criticality, compliance impact, and exploit maturity simultaneously.
Reproducible scoring. Every TRACE Score is reproducible byte-for-byte from persisted signals. A federal auditor can replay offline. This is an ATO defensibility requirement no NVD mirror addresses.
The CVE Feed in the Broader Vulnerability Management Workflow
The feed is the intelligence layer powering the full lifecycle:
- Scan --- ~350,000+ scanner plugins discover what is running and what is vulnerable.
- Discover --- findings correlated against the CVE feed for enrichment.
- Enrich --- EPSS, KEV, exploit maturity, vendor advisory status, and TRACE Score components attached.
- Prioritize --- TRACE Score ranks by actual risk to the organization, not abstract severity.
- Remediate --- prioritized findings drive workflows with tracked POA&M entries.
- Verify --- re-scan confirms the fix, evidence recorded, finding lifecycle closes.
Without enrichment, step 4 degrades to "fix all the 9.8s first" --- which is why most organizations are fixing the wrong vulnerabilities first.
Data Licensing and Community Commitment
The public feed is CC-BY-4.0. Vulnerability intelligence should be freely accessible. The enrichment pipeline, organizational context, and TRACE Score prioritization are the value-added services; raw intelligence is a public good.
Key Takeaways
- NVD's April 2026 policy change is permanent scope reduction, not a temporary backlog --- most CVEs will never receive NVD enrichment again
- 12+ source aggregation delivers sub-3-hour enrichment independent of NVD processing timelines
- Per-field provenance lets consumers distinguish high-confidence NVD scores from lower-confidence CNA estimates
- TRACE Score adds the organizational context (asset criticality, reachability, compliance impact) that CVSS alone cannot provide
- Public feed is free (CC-BY-4.0, 100 req/min) --- the value-add is organizational context and prioritization
- CISA BOD 26-04 mandates risk-based patching timelines that require enrichment data NVD no longer provides
Frequently Asked Questions
How does the feed handle CVEs that NVD later enriches?
When NVD publishes enrichment for a CVE the feed already scored, the NVD data (Tier 1) takes precedence for the affected fields. The record updates, per-field provenance reflects the source change, and any TRACE Score that references the updated field is automatically recomputed. Historical provenance is preserved --- you can see what the pre-NVD score was and when it changed.
What is the enrichment SLA?
Sub-3-hour enrichment from NVD publication for CVEs with available upstream data. Some CVEs (especially hardware-specific or embedded-system vulnerabilities) may have limited upstream sources and take longer to reach full enrichment. The coverage statistics endpoint reports actual enrichment latency percentiles in real time.
Can we use the public feed to replace our NVD integration?
For CVSS scores, CWE classification, and exploit intelligence --- yes. The feed provides these fields with per-field provenance. For CPE match criteria specifically, coverage depends on whether upstream sources provide affected product data. The NVD Gap Coverage endpoint shows exactly which CVEs have enrichment the NVD does not, letting you measure the delta for your environment.
How does TRACE Score differ from EPSS?
EPSS predicts exploitation probability for a CVE globally --- across all organizations, all deployments. TRACE Score is per-asset and per-organization: it accounts for where the vulnerable asset sits in your network (reachability), how critical that asset is to your operations, which compliance frameworks it falls under, and the current threat landscape for that CVE. Two organizations with the same EPSS score for a CVE will have different TRACE Scores based on their unique contexts.
Is the feed available in air-gapped deployments?
Yes. The feed data is included in the periodic media transfer package for air-gapped deployments. Signal sources (EPSS snapshots, KEV catalog, exploit database) are bundled. Enrichment operates against the bundled data rather than live APIs. Update frequency depends on the media transfer cadence.
How Advisedly Helps
The Live CVE Feed fills the intelligence gap the NVD left behind --- aggregating 12+ sources with sub-3-hour enrichment, adding per-field provenance and confidence scoring, and layering organizational context through TRACE Score prioritization so your team fixes the vulnerabilities that actually matter to your environment, not just the ones with the highest abstract severity. begin@advisedly.ai
<!-- LI hook: NVD stopped scoring most CVEs. Now what? -->