CyberMax
Home › Glossary › Vulnerability management

What is a CVE?

Vulnerability management glossary · 1 primary source

Common Vulnerabilities and Exposures: the public ID system for disclosed security flaws, written as CVE-YEAR-NUMBER, for example CVE-2021-44228.

The CVE Program gives each publicly disclosed vulnerability one identifier so that vendors, scanners, advisories and patch notes can all refer to the same flaw. IDs are issued by CVE Numbering Authorities (CNAs): software vendors, research groups and national CERTs authorised for their own scope.

The year in the ID is the year the ID was reserved, not necessarily when the flaw was found or published, and the number part has four or more digits. A CVE record holds a description, affected products and references; scores such as CVSS are often added later by the CNA or by other enrichers.

Sources

Related terms

On this site

All vulnerability management terms · Full glossary