To the dismay of many security pros, the U.S. Department of Commerce’s National Institute of Standards and Technology has announced that it is scaling back the enrichment of Common Vulnerabilities and Exposures (CVEs) in the National Vulnerability Database (NVD).