Common Vulnerability Enumeration (CVE)
A Common Vulnerability Enumeration, or CVE, is a security flaw that has been discovered in an open source software package. We can think of CVEs like report cards for problems identified in computer programs.
With this in mind, let's look at what elements make up a CVE:
- CVE ID: A unique identifier for the CVE
- Description: A description of what the problem is and why
- Impact: An explanation of how bad the problem potentially is
- Severity Score (CVSS): A number that tells us how serious the problem is
- Reference: Links or notes with additional information about the problem