Common Vulnerabilities and Exposures (CVE)
A programme that assigns unique identifiers, such as CVE-2021-44228, to publicly disclosed cybersecurity vulnerabilities, so that vendors, security tools and defenders can refer to the same issue consistently.
Each CVE record contains an identifier made up of the prefix CVE, a year and a sequence number, a description of the vulnerability, the affected products and versions, and references to advisories. The programme was launched by the MITRE Corporation in 1999, and identifiers are now assigned by a large network of CVE Numbering Authorities (CNAs), including software vendors, open-source projects and national CERTs. Other sources, notably the National Vulnerability Database (NVD) run by the US National Institute of Standards and Technology, add severity scores and further analysis.
CVE identifiers are the common key linking vulnerability scanners, software composition analysis tools, patch advisories, threat intelligence feeds and SBOM-based impact analysis. Security teams use them to track remediation, vendors cite them in release notes and security bulletins, and national authorities use them in advisories, including advisories for industrial control system products.
A CVE identifier states that a vulnerability exists, not how dangerous it is in a particular environment. Severity is commonly expressed with CVSS, while exploitation evidence, such as the list of known exploited vulnerabilities maintained by the US Cybersecurity and Infrastructure Security Agency or the EPSS probability score, helps prioritisation. Not every vulnerability receives a CVE, notably flaws in custom code and in some cloud services, and record quality varies between CNAs.
Key points
- Identifiers combine the prefix CVE, the year and a sequence number.
- Assigned by CVE Numbering Authorities such as vendors and CERTs.
- A CVE identifies a vulnerability; CVSS and exploit data indicate priority.
- Flaws in custom code usually do not receive a CVE.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.
Related terms
- Common Vulnerability Scoring System (CVSS)Cybersecurity & Compliance
- Vulnerability ManagementCybersecurity & Compliance
- Software Composition Analysis (SCA)Cybersecurity & Compliance
- Software Bill of Materials (SBOM)Cybersecurity & Compliance
- Zero-Day VulnerabilityCybersecurity & Compliance
- Threat IntelligenceCybersecurity & Compliance