What is a CVE?
Common Vulnerabilities and Exposures: the public ID system for disclosed security flaws, written as CVE-YEAR-NUMBER, for example CVE-2021-44228.
The CVE Program gives each publicly disclosed vulnerability one identifier so that vendors, scanners, advisories and patch notes can all refer to the same flaw. IDs are issued by CVE Numbering Authorities (CNAs): software vendors, research groups and national CERTs authorised for their own scope.
The year in the ID is the year the ID was reserved, not necessarily when the flaw was found or published, and the number part has four or more digits. A CVE record holds a description, affected products and references; scores such as CVSS are often added later by the CNA or by other enrichers.
Sources
Related terms
- CNA (CVE Numbering Authority)An organisation authorised by the CVE Program to assign CVE IDs and publish CVE records for vulnerabilities in its scope.
- NVDThe National Vulnerability Database run by NIST, which republishes CVE records and adds analysis such as CVSS scores, CWE types and CPE product names.
- CVSSCommon Vulnerability Scoring System: FIRST's standard 0.0–10.0 score for how severe a vulnerability is, based on how it can be exploited and what it affects.
- KEV catalogCISA's Known Exploited Vulnerabilities catalog: the list of CVEs with reliable evidence of exploitation in the wild, each with a required action and a due date.