Company Partners Our Teams Contact Blog
Services
Industries
Talk to an expert

What is CVE?

DefinitionCVE (Common Vulnerabilities and Exposures) is the public system that assigns a unique identifier, in the format CVE-year-number, to each disclosed vulnerability, so vendors, tools and teams can refer to the same flaw without ambiguity.

How it works

The CVE program was created in 1999 and is operated by MITRE, sponsored by CISA, the United States cybersecurity agency. Identifiers are assigned by CNAs (CVE Numbering Authorities): software vendors, response centers and researchers authorized to number flaws within their scope.

Each record includes:

  • An identifier, such as CVE-2021-44228, the Log4j flaw known as Log4Shell.
  • A short description of the flaw and the affected products.
  • References, such as vendor advisories and security bulletins.

CVE is not a risk score

A CVE only identifies and describes. Severity comes from CVSS; likelihood of exploitation, from EPSS; and confirmation of real-world exploitation, from sources such as CISA's KEV catalog. NIST's NVD (National Vulnerability Database) is one of the databases that enrich records with CVSS scores and lists of affected products. Having a CVE does not mean the flaw is serious, nor that it is under attack.

In practice

The CVE identifier is the link between scanners, vendor advisories, threat intelligence and the remediation process. It lets you match what the scanner found with what is being exploited and track the flaw until it is closed. Since thousands of CVEs are published every year, the challenge is not knowing them but deciding which to handle first in your own environment.

Network Secure offers Vulnerability Management as a continuous service.

Frequently asked questions

What is the difference between CVE and CVSS?

A CVE is the unique identifier of a vulnerability. CVSS is the 0 to 10 score that describes that vulnerability's technical severity.

Does every vulnerability have a CVE?

No. Flaws in in-house systems, misconfigurations and vulnerabilities not yet disclosed usually do not get a CVE, but they still need to be handled.

Go deeper