Weakness Under-RatingWeekly
The weaknesses NVD marks up most: CWE-707 averages +2.4 over the vendor
Updated 12 August 2026 · Timeframe: All re-scored pairs, by CWE (>=80 pairs)
When NVD re-scores a vendor's CVE, the size of the upward correction depends on the weakness type. Injection and impact-heavy classes lead: CWE-707 (Improper Neutralization) averages +2.4 points over the vendor's score. Vendors systematically under-rate the impact of these classes; NVD does not.
Why it matters
If your stack is heavy in the weakness types NVD marks up most, the vendor CVSS understates your real exposure by a predictable amount. Knowing which classes lets you correct for it.
What to do
- Security leaders. For CVEs in these weakness classes, treat the vendor score as a floor, not the answer.
- Lean IT orgs. Injection and impact-heavy weaknesses are where vendor scores understate risk the most.
- MSPs. Flag the weakness classes NVD consistently upgrades when advising clients on vendor-scored CVEs.
Our take
Showing which weakness types the vendor-vs-NVD gap concentrates in turns a broad disagreement into an actionable correction.
The data behind this