Common Vulnerabilities and Exposures (CVE)

A Common Vulnerabilities and Exposures (CVE) identifier is a unique, publicly cataloged reference for a specific cybersecurity vulnerability, assigned by CVE Numbering Authorities and maintained by MITRE.

What CVE Provides

CVE gives the security community a shared identifier for every publicly disclosed vulnerability. When a vulnerability is reported and cataloged, it receives a CVE ID (e.g., CVE-2024-12345) that lets vendors, defenders, and tools all reference the same thing without ambiguity.

Related systems layer on top of CVE. CVSS scores rate technical severity. EPSS estimates exploitation likelihood. CISA's Known Exploited Vulnerabilities (KEV) catalog identifies CVEs known to be actively exploited.

Why CVE Alone Is Not Enough for Prioritization

The number of new CVEs published each year exceeds what any security team can remediate. Prioritization is essential, and CVSS alone does not provide it well. A CVE with a high CVSS score on a system that is not internet-exposed and not connected to sensitive data may be less urgent than a lower-CVSS vulnerability on a critical asset.

Effective prioritization combines CVE data with asset context, exploitation likelihood, and business impact. This is where CVE meets cyber risk quantification.

CVE in Quantified Programs

Quantified programs use CVE-level data as one input into modeled loss scenarios, but do not treat vulnerability counts as risk metrics. The question is not how many CVEs exist, it is how much loss exposure specific vulnerabilities represent given the assets and controls in place.

Related Terms

Turn Cyber Risk Into Financial Exposure the Board Can Act On

Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.