Security & Compliance Glossary

CVE (Common Vulnerabilities and Exposures)

A CVE, or Common Vulnerabilities and Exposures identifier, is a unique public reference number assigned to a specific, publicly disclosed security vulnerability. The format is CVE-YYYY-NNNN, and the system is coordinated by MITRE. CVEs give vendors, researchers, and defenders a shared name for the same flaw.

In practice

When a CVE is published it usually appears in the National Vulnerability Database (NVD) with details, affected products, and a CVSS severity score. Scanners and patch tools key off CVE IDs to tell you what you are exposed to.

A CVE identifies the flaw but does not by itself measure its danger; that is what the CVSS score adds. traztech's founder has six published CVEs, including CVE-2024-45163, a CVSS 9.1 kill-switch for the Mirai botnet.

// how traztech helps

traztech delivers security research and CVE disclosure for startups and growth-stage companies, led by a published CVE researcher.

Book a call