CVE
Common Vulnerabilities and Exposures
In short
A CVE is a unique public identifier, such as CVE-2021-44228, given to one known security vulnerability so everyone can refer to the same flaw by one name.
What is a CVE?
CVE, short for Common Vulnerabilities and Exposures, is a public catalog of known security vulnerabilities in software and hardware. Each entry gets an ID in the form CVE-YEAR-NUMBER, for example CVE-2021-44228, the Log4Shell flaw in the Log4j logging library, along with a short description and references. The shared ID lets vendors, security tools, advisories, and developers talk about exactly the same problem without confusion.
The CVE program began in 1999, and today IDs are assigned by hundreds of CVE Numbering Authorities (CNAs), including software vendors, open-source foundations, and security companies. When a researcher reports a vulnerability, a CNA reserves an ID, and the details are usually published once a fix is available. Databases such as the US National Vulnerability Database then enrich entries with lists of affected versions and a severity score from the Common Vulnerability Scoring System (CVSS), which rates flaws from 0.0 to 10.0.
CVE IDs are how the software industry tracks what needs patching. Dependency scanners compare the libraries in your project against CVE data and warn about vulnerable versions, container image scanners do the same for operating system packages, and security teams prioritize fixes by severity and by whether a flaw is being actively exploited. A CVE ID works like a case number at a hospital: it doesn't cure anything, but it makes sure every doctor, lab, and pharmacy is talking about the same patient.
A CVE is often confused with a CWE or with the OWASP Top 10. A CVE is one specific vulnerability in a specific product, while a CWE, an entry in the Common Weakness Enumeration, names a general type of mistake, such as CWE-79 for cross-site scripting, and the OWASP Top 10 groups such weaknesses into broad risk categories. Also, a CVSS score measures technical severity, not your actual risk: a critical flaw in code you never call may matter less than a medium one exposed to the internet.
Key takeaways
- A CVE ID uniquely identifies one publicly known vulnerability.
- IDs follow the format
CVE-YEAR-NUMBERand are assigned by CVE Numbering Authorities. - CVSS scores from 0.0 to 10.0 describe a vulnerability's technical severity.
- Dependency and image scanners match your software against CVE data.
- A CWE names a type of weakness; a CVE names one concrete instance of it.
Example
# Scan a Node.js project's dependencies for known vulnerabilities
npm audit
# Scan the packages installed in a Python environment
pip-audit
# Look up one CVE in the open OSV vulnerability database
curl -s https://api.osv.dev/v1/vulns/CVE-2021-44228 | head -c 400Readers ask
What does a CVE number mean?
The first number is the year the ID was assigned or the vulnerability was made public, and the second is a sequence number, as in CVE-2024-3094. The ID itself says nothing about severity; that comes from separate scoring such as CVSS.
What is the difference between CVE and CVSS?
A CVE is an identifier for a specific vulnerability. CVSS is a scoring system that rates how severe a vulnerability is on a scale from 0.0 to 10.0, and a CVE entry often carries a CVSS score.
Does every vulnerability get a CVE?
No. CVEs are for publicly disclosed vulnerabilities in products that others use, so bugs in private, internal systems or flaws fixed before release usually never get one.
See also
- OWASP Top 10Security, p. 24The OWASP Top 10 is a widely used list of the ten most critical security risks to web applications, published by the nonprofit OWASP and updated regularly.
- Supply Chain AttackSecurity, p. 43A supply chain attack compromises software through something it relies on, like an open-source package, a build tool or an update server, not the app itself.
- Penetration TestingSecurity, p. 26Penetration testing is an authorized, simulated attack on a system that helps an organization find and fix security weaknesses before real attackers do.
- Semantic VersioningVersion Control, p. 35Semantic versioning is a MAJOR.MINOR.PATCH numbering scheme in which each part signals whether a release breaks compatibility, adds features, or fixes bugs.
- Static AnalysisTesting & Quality, p. 26Static analysis is the automated examination of source code without running it, to find bugs, security vulnerabilities, and quality problems early.
- Zero-DaySecurity, p. 50A zero-day is a software vulnerability that the vendor doesn't know about or hasn't fixed yet, so attackers can exploit it before any patch exists.
Spotted a mistake or something missing on this page?Suggest an edit