CVE Severity Digest methodology
How the CVE Severity Digest classifies, ranks, and updates vulnerability records.
Inputs and coverage
Once per day we sample at most the fifty most recently published CVE records from the NVD CVE API 2.0. The request is restricted to the latest twenty-four-hour publication window, with a small overlap on later runs. Because NVD returns CVEs in ascending publication order, we use its result count to request only the final fifty offsets. MongoDB retains every unique normalized record accepted by the pilot.
Classification method
Affected configurations are read from CPE criteria supplied in each CVE. Vendor and product tokens are grouped into broad operational families such as operating systems, browsers, network infrastructure, server software, developer libraries, hardware, and business applications. Reference URLs and NVD tags are classified as patches, vendor advisories, mitigations, or general references. These labels are VUGA computations and are not NVD findings.
Ranking
The public significance score combines the highest available CVSS base score, NVD severity, recent publication or modification, CISA known-exploited fields when present, and whether a patch or mitigation reference is available. The score prioritizes editorial usefulness; it is not a risk score for any particular organization and must not replace an asset-specific vulnerability assessment.
Limitations and updates
NVD records can be incomplete, disputed, or revised after publication. This pilot is a daily sample of newly published CVEs, not a complete NVD mirror and not a feed of every later modification. Product-family inference depends on available CPE data, while remediation classification depends on reference tags and URL patterns. An absent patch reference does not prove that no fix exists. Duplicate CVE identifiers are rejected before staging, and visible dates change only when normalized content changes.