What is Common Vulnerabilities and Exposures (CVE)?
A public catalogue of known security vulnerabilities, where each entry gets a unique identifier, such as CVE-2024-3400, so everyone can refer to the same flaw.
How it works
The CVE programme is run by MITRE with funding from the US Cybersecurity and Infrastructure Security Agency (CISA). Vendors and researchers request identifiers, and scanners use them to report what they find.
A CVE identifier says nothing about risk on its own. Severity is usually expressed with a CVSS score, and real-world exploitation is tracked in sources such as CISA’s Known Exploited Vulnerabilities catalogue.
Key points
- A shared naming system for known vulnerabilities
- Format: CVE-year-number
- Paired with CVSS for severity
- Exploitation status matters more than the score alone
Common questions
What is CVSS?
The Common Vulnerability Scoring System, a 0–10 score describing a vulnerability’s technical severity.
What is the KEV catalogue?
CISA’s list of vulnerabilities known to be exploited in the wild, a strong signal for prioritisation.
Talk to someone who does this every day
Questions about CVE? Our team will give you a straight answer.