Common Vulnerabilities and Exposures (CVE)
A Common Vulnerabilities and Exposures (CVE) identifier is a unique, publicly cataloged reference for a specific cybersecurity vulnerability, assigned by CVE Numbering Authorities and maintained by MITRE.
What CVE Provides
CVE gives the security community a shared identifier for every publicly disclosed vulnerability. When a vulnerability is reported and cataloged, it receives a CVE ID (e.g., CVE-2024-12345) that lets vendors, defenders, and tools all reference the same thing without ambiguity.
Related systems layer on top of CVE. CVSS scores rate technical severity. EPSS estimates exploitation likelihood. CISA's Known Exploited Vulnerabilities (KEV) catalog identifies CVEs known to be actively exploited.
Why CVE Alone Is Not Enough for Prioritization
The number of new CVEs published each year exceeds what any security team can remediate. Prioritization is essential, and CVSS alone does not provide it well. A CVE with a high CVSS score on a system that is not internet-exposed and not connected to sensitive data may be less urgent than a lower-CVSS vulnerability on a critical asset.
Effective prioritization combines CVE data with asset context, exploitation likelihood, and business impact. This is where CVE meets cyber risk quantification.
CVE in Quantified Programs
Quantified programs use CVE-level data as one input into modeled loss scenarios, but do not treat vulnerability counts as risk metrics. The question is not how many CVEs exist, it is how much loss exposure specific vulnerabilities represent given the assets and controls in place.
Related Terms
Turn Cyber Risk Into Financial Exposure the Board Can Act On
Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.


