at 17:55, Jack Clark in San Francisco 14 Mar 2013. "Downed US vuln catalog infected for at least TWO MONTHS". www.theregister.co.uk. Retrieved 2019-10-29.{{cite web}}: CS1 maint: numeric names: authors list (link) https://www.theregister.co.uk/2013/03/14/adobe_coldfusion_vulns_compromise_us_malware_catalog/
"US national vulnerability database hacked." https://www.theregister.co.uk/2013/03/14/us_malware_catalogue_hacked/
"75% of Vulns Shared Online Before NVD Publication". Dark Reading. 7 June 2017. Retrieved 2019-10-29. https://www.darkreading.com/vulnerabilities---threats/75--of-vulns-shared-online-before-nvd-publication/d/d-id/1329066
Zhang, Su; Ou, Xinming; Caragea, Doina (2015-12-31). "Predicting Cyber Risks through National Vulnerability Database". Information Security Journal: A Global Perspective. 24 (4–6): 194–206. doi:10.1080/19393555.2015.1111961. ISSN 1939-3555. S2CID 30587194. http://www.tandfonline.com/doi/full/10.1080/19393555.2015.1111961
"NVD - CVSS v2 Equations". nvd.nist.gov. Archived from the original on 2013-12-21. https://web.archive.org/web/20131221044001/http://nvd.nist.gov/cvsseq2.htm
Stenberg, Daniel (26 August 2023). "CVE-2020-19909 is everything that is wrong with CVEs". Daniel Stenberg's Blog. Retrieved 2023-08-26. https://daniel.haxx.se/blog/2023/08/26/cve-2020-19909-is-everything-that-is-wrong-with-cves/
"curl - Bogus report filed by anonymous - CVE-2020-19909". curl.se. Retrieved 2023-08-31. https://curl.se/docs/CVE-2020-19909.html
"NVD - CVE-2020-19909". nvd.nist.gov. Archived from the original on 2023-09-05. Retrieved 2023-09-07. https://web.archive.org/web/20230905213507/https://nvd.nist.gov/vuln/detail/CVE-2020-19909