Fragmentation of CVSS scores in the NVD: A quantitative analysis of inconsistency across vulnerability scoring standards
inforesearchPeer-Reviewed
security
Source: Elsevier Security JournalsMay 24, 2026
Summary
This research paper analyzes inconsistencies in CVSS scores (numerical ratings that measure how serious software vulnerabilities are) within the NVD (National Vulnerability Database, a public repository of known security flaws). The study found that the same vulnerability often receives different CVSS scores depending on which scoring standard or organization assigns the rating, revealing a fragmentation problem in how vulnerability severity is measured and reported.
Classification
Attack SophisticationModerate
Monthly digest — independent AI security research
Original source: https://www.sciencedirect.com/science/article/pii/S0167404826001549?dgcid=rss_sd_all
First tracked: May 24, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 85%