How a CVE is assigned
When a vulnerability is reported, a CVE Numbering Authority (usually the software vendor or a security organisation) assigns an identifier made of the year and a sequence number, such as CVE-2024-3094. The CVE Program, run by MITRE, publishes the record with a short description.
CVE and severity
A CVE identifies a vulnerability but does not rate it. Severity is usually added through a CVSS score, published in databases such as the US National Vulnerability Database. In Europe, ENISA also maintains the European Vulnerability Database.
Why it matters
CVEs let scanners, vendors, security teams and advisories refer to the same issue without ambiguity. When a patch note, a scan report and a threat alert mention the same CVE, you know they are talking about the same problem.
Prioritising CVEs
Thousands of CVEs are published every year, so not all can be fixed at once. Teams combine the CVSS score with signs of active exploitation, such as the CISA KEV catalogue or EPSS, and with whether the affected system is actually exposed.




