# What is Common Vulnerabilities and Exposures (CVE)?

> Common Vulnerabilities and Exposures (CVE) is an international program that gives publicly disclosed cybersecurity vulnerabilities stable identifiers and publishes structured CVE Records in the CVE List.

- Canonical URL: https://yellowcube.eu/glossary/common-vulnerabilities-and-exposures/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

A CVE identifier lets suppliers, researchers, databases, tools, and defenders refer to the same disclosed issue without relying on product-specific names. It identifies a vulnerability; it does not assign severity, confirm exploitation, or prescribe remediation.

Authorized CVE Numbering Authorities (CNAs) reserve identifiers, determine whether issues meet program rules within their scope, and publish records to the CVE List. Records can be updated as descriptions, affected products, references, or other information improves.

### Key points

- **Identifier format:** A CVE identifier combines the prefix “CVE,” a year, and a sequence number; the year is part of the identifier and does not reliably state when discovery, exploitation, or remediation occurred.
- **Record purpose:** A CVE Record supplies a common identity and core descriptive data so advisories, databases, inventories, and security tools can exchange information about the same disclosed vulnerability.
- **Consumer workflow:** Confirm the affected product and version against authoritative advisories, then combine the record with deployment context, severity, exploitation evidence, and remediation guidance.
- **Important limitation:** Not every security defect receives a CVE identifier, and the presence, absence, age, or sequence of an identifier does not establish severity, exploitability, disclosure quality, patch availability, or organizational risk.

### Related terms

[Vulnerability](<https://yellowcube.eu/glossary/vulnerability/>) · [National Vulnerability Database (NVD)](<https://yellowcube.eu/glossary/national-vulnerability-database/>) · [Common Vulnerability Scoring System (CVSS)](<https://yellowcube.eu/glossary/common-vulnerability-scoring-system/>) · [Coordinated vulnerability disclosure (CVD)](<https://yellowcube.eu/glossary/coordinated-vulnerability-disclosure/>) · [Zero-day vulnerability](<https://yellowcube.eu/glossary/zero-day-vulnerability/>)

### Sources

[CVE Program: Overview](https://www.cve.org/About/Overview) · [CVE Program: Glossary](https://www.cve.org/ResourcesSupport/Glossary) · [CVE Program: Structure](https://www.cve.org/ProgramOrganization/Structure)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

