Why Do I Need This?
Every CVE enriched. No exceptions. Get started with a simple host swap.
Complete CVE Enrichment. No Coverage Gaps.
The National Vulnerability Database can no longer provide enrichment for every published CVE. As vulnerability volumes continue to grow, enrichment efforts are increasingly focused on a prioritized subset of vulnerabilities, leaving many CVEs without the scoring and metadata security teams depend on. We tracked the fallout in our two-month review of NIST's enrichment cutbacks.
We restore complete coverage. Our automated enrichment pipeline provides CVSS 3.1 and CVSS 4.0 vectors, dictionary-validated CPEs, categorized references, and extended summaries for all new CVEs, not just a select few.
Every CVSS vector is derived from an auditable attack graph generated for the CVE. We map and evaluate all viable exploitation paths, assess each path independently, and use the highest-severity path to produce the final vector. This methodology was presented at VulnCon 2026 and powers the same enrichment used throughout our enterprise offerings.
We analyze and classify every reference associated with a CVE, including advisories, patches, exploits, and technical write-ups, so your tools can automate triage and prioritization without manual review. Enriched descriptions summarize the information that matters most, reducing the time analysts spend reviewing source material.
Deployment is simple. Our API is fully compatible with NVD 2.0 endpoints and response formats, allowing it to serve as a drop-in replacement for existing integrations. Maintain complete visibility across the vulnerability landscape without changing your workflows.
"https://services.nvd.nist.gov/rest/json/cves/2.0""https://api.volerion.com/v1/nvd/rest/json/cves/2.0"One endpoint change. Full NVD 2.0 compatibility.
“Volerion gives us what NVD can't: instant, accurate context on every CVE. With remediation steps ready to go. When Hadrian finds the risk, Volerion makes sure nobody wastes time figuring out what it means.”

Hadrian
Security vendor, Amsterdam
Is this compatible with my current integration?
Yes, our API is intentionally designed to be compatible with existing NVD 2.0 clients. Migration requires nothing more than a URL swap.
Why not use a free public feed?
Free feeds typically rely on aggregation from third party sources that are plagued by low-coverage, low-quality, and significant delays. The exact issues we address by providing authentic enrichment.
How do you keep up with the high influx of new vulnerabilities?
We have developed a fully automated enrichment pipeline that processes all new CVEs. This pipeline consists of a data harness and a dozen trained large language models to guarantee stability, accuracy and consistency.
How do you ensure the quality of your data?
We have a dedicated quality assurance program where we compare against public data to see if any discrepancies arise due to an error on our side. So far, we have submitted hundreds of corrections to CISA's Vulnrichment, and all CVEs have had their CVSS vector updated. Our data has a proven track record of accuracy and consistency, and we are committed to maintaining the highest standards.
What sources do you use for enrichment?
We use authoritative sources such as vendor advisories, patch notes, and technical blog posts. Our models are trained to extract and derive meaningful information without contradicting the source material.
NIST Cuts Back On Enrichment Efforts
NIST now prioritizes only a narrow subset, leaving most new CVEs without CVSS, CWE and CPE metadata.
Read the NIST announcement →Vulnerability Management Strained By Low-Quality Enrichment
Our peer-reviewed corrections of public data show recurring enrichment errors that significantly decrease triage efficiency.
Read the full analysis →