A CVE identifier lets suppliers, researchers, databases, tools, and defenders refer to the same disclosed issue without relying on product-specific names. It identifies a vulnerability; it does not assign severity, confirm exploitation, or prescribe remediation.
Authorized CVE Numbering Authorities (CNAs) reserve identifiers, determine whether issues meet program rules within their scope, and publish records to the CVE List. Records can be updated as descriptions, affected products, references, or other information improves.
Key points
Identifier formatA CVE identifier combines the prefix “CVE,” a year, and a sequence number; the year is part of the identifier and does not reliably state when discovery, exploitation, or remediation occurred.
Record purposeA CVE Record supplies a common identity and core descriptive data so advisories, databases, inventories, and security tools can exchange information about the same disclosed vulnerability.
Consumer workflowConfirm the affected product and version against authoritative advisories, then combine the record with deployment context, severity, exploitation evidence, and remediation guidance.
Important limitationNot every security defect receives a CVE identifier, and the presence, absence, age, or sequence of an identifier does not establish severity, exploitability, disclosure quality, patch availability, or organizational risk.