Public vulnerability identifier
CVE · A unique identifier in the form CVE-year-number given to a publicly disclosed vulnerability, so everyone knows they are talking about the same flaw.
- 01
Why it matters
A CVE number makes sure everyone talking about the same flaw means the same thing: vendor advisories, security bulletins and scan reports all use the same identifier. It lets you quickly check whether the version of a product you use is affected, whether a patch exists and whether the flaw is being exploited in real attacks.
- 02
Example
If a scan report says “CVE-2024-XXXX: version 3.2 of your form plugin is affected”, the team uses that number to find the vendor's advisory, learn the fixed version and plan the update.
- 03
Common mistake
Treating every CVE with the same urgency. Prioritising without checking whether a flaw is actually reachable in your setup, and how critical the system is, buries the team in unimportant work.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.