Software Vulnerability Primer

National Institute of Standards and Technology (US Department of Commerce) has created a National Vulnerability database.

The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, misconfigurations, product names, and impact metrics. 

NIST – NVD

NVD Vulnerability Severity Ratings

NVD provides qualitative severity ratings of “Low”, “Medium”, and “High” for CVSS v2.0 base score ranges in addition to the severity ratings for CVSS v3.0 as they are defined in the CVSS v3.0 specification.

CVSS v2.0 Ratings CVSS v3.0 Ratings
SeverityBase Score RangeSeverityBase Score Range
  None0.0
Low0.0-3.9Low0.1-3.9
Medium4.0-6.9Medium4.0-6.9
High7.0-10.0High7.0-8.9
  Critical9.0-10.0

References