GlossaryAttack surface and pentesting

CVE

Short answer

A CVE (Common Vulnerabilities and Exposures) is a unique public identifier given to a known security vulnerability in software or hardware. It gives everyone a common name for the same flaw, so vendors, scanners and security teams can track and fix it consistently.

How a CVE is assigned

When a vulnerability is reported, a CVE Numbering Authority (usually the software vendor or a security organisation) assigns an identifier made of the year and a sequence number, such as CVE-2024-3094. The CVE Program, run by MITRE, publishes the record with a short description.

CVE and severity

A CVE identifies a vulnerability but does not rate it. Severity is usually added through a CVSS score, published in databases such as the US National Vulnerability Database. In Europe, ENISA also maintains the European Vulnerability Database.

Why it matters

CVEs let scanners, vendors, security teams and advisories refer to the same issue without ambiguity. When a patch note, a scan report and a threat alert mention the same CVE, you know they are talking about the same problem.

Prioritising CVEs

Thousands of CVEs are published every year, so not all can be fixed at once. Teams combine the CVSS score with signs of active exploitation, such as the CISA KEV catalogue or EPSS, and with whether the affected system is actually exposed.

Related terms

Keep reading on this topic

External and internal attack surface management, cloud configuration and application security: finding exposures and prioritising them by real risk.

Go to the topic hub