Cyber Resilience

CVSS Trust IndexStanding

Whose CVSS scores NVD overrules: Oracle at 3%, VulDB at 95%

Updated 12 August 2026 · Timeframe: All CVEs scored by both NVD and the vendor

3.4Oracle18.8Adobe39.4Juniper47.3Cisco49.3Siemens51.2Sap53.6Hpe55.1CISA ICS-CERT81.7Vulncheck85.5Samsung86.5Intel89.8Patchstack89.9Huawei92.9Hcl95.4VulDB
How often NVD overrules each vendor's CVSS (%), all years · security-resilience.ai

NVD re-scores some vendors' CVEs almost never and others almost always. Across all their scored CVEs it overruled Oracle on just 3%, but VulDB on 95% (and almost always upward). The number on a CVE tells you as much about who filed it as about the flaw.

Why it matters

If your triage leans on the vendor-supplied CVSS, its reliability depends entirely on the vendor. Some CNAs' scores are effectively final; others are a first draft NVD routinely rewrites.

What to do

Our take

A severity score is only as trustworthy as its source. Publishing which sources NVD actually stands behind is a service no vendor feed provides.

Earlier issues

Past states of this signal, most recent first.

08 August 2026 Whose CVSS scores NVD overrules: Oracle at 4%, VulDB at 95%

Timeframe: All CVEs scored by both NVD and the vendor

3.5Oracle18.8Adobe39.4Juniper47.3Cisco49.3Siemens51.2Sap53.6Hpe55.1CISA ICS-CERT81.7Vulncheck85.5Samsung86.5Intel89.8Patchstack89.9Huawei92.9Hcl95.4VulDB

NVD re-scores some vendors' CVEs almost never and others almost always. Across all their scored CVEs it overruled Oracle on just 4%, but VulDB on 95% (and almost always upward). The number on a CVE tells you as much about who filed it as about the flaw.