Accreditation
Standard
Formal independent recognition that a conformity-assessment body is competent to perform specified assessment or certification activities.
A public program and identifier system that gives disclosed cybersecurity vulnerabilities a common, globally recognizable reference. A deeper explanation shows how CVE fits into vulnerability management and security operations, including the distinctions that prevent common confusion.
Definition
A public program and identifier system that gives disclosed cybersecurity vulnerabilities a common, globally recognizable reference.
— Common Vulnerabilities and Exposures (CVE)
In depth
A public program and identifier system that gives disclosed cybersecurity vulnerabilities a common, globally recognizable reference. The fuller explanation connects CVE with vulnerability management and security operations and shows how the standard or reference term functions in practice.
A CVE identifier lets vendors, scanners, advisories, defenders, and researchers refer to the same disclosed vulnerability without relying on inconsistent product-specific names.
Key points
The CVE Program publishes records for publicly disclosed cybersecurity vulnerabilities. Authorized numbering organizations reserve identifiers, determine whether an issue fits the program's scope, and publish a concise record. The identifier acts as a join key across vendor advisories, vulnerability databases, scanners, patch systems, and threat intelligence.
A CVE Record identifies and briefly describes a vulnerability; it is not by itself a severity rating, proof of exploitation, patch, or statement that every installed product is affected. Defenders still need vendor applicability guidance, product versions, configuration context, exploit intelligence, and asset inventory. Two organizations can agree on the CVE identifier while reaching different remediation priorities because their exposure and business impact differ.
Examples
Common misconceptions
Certification context
A reliable understanding of CVE helps readers interpret technical documentation, exam objectives and system-design discussions with greater precision. The certification context connects the term with vulnerability management and security operations while avoiding assumptions about a particular provider, exam or credential.
Why it matters
Shared identifiers make vulnerability information interoperable and allow teams to correlate findings across tools and sources.
In certification contexts
Security candidates encounter CVEs in scanning, patch management, threat intelligence, risk triage, and questions that distinguish identification from severity and organizational risk.
Also known as
Topics
More terms
Common Vulnerabilities and Exposures (CVE) is grouped with other standards and reference terms to support structured terminology browsing. Each result offers a concise definition and a deeper explanation for technical certification study and professional practice. The grouping reflects the kind of term rather than claiming that every item shares the same topic, provider or certification.
Standard
Formal independent recognition that a conformity-assessment body is competent to perform specified assessment or certification activities.
An IP addressing and routing approach that represents networks with variable-length prefixes instead of fixed address classes.
An open framework for describing the technical characteristics and severity of a software, hardware, or firmware vulnerability.
Return to the glossary to search another acronym, concept, standard, technology or assessment term. Category and type filters make it easier to move from an unfamiliar phrase to a concise definition and a fuller practical explanation.