In cybersecurity, what does the acronym CVE officially stand for?
Answer
Common Vulnerabilities and Exposures
Answer
Common Vulnerabilities and Exposures
In cybersecurity, CVE officially stands for Common Vulnerabilities and Exposures. The CVE program gives publicly known software and hardware security flaws standardized identification numbers.
A CVE record normally describes one vulnerability and assigns it an identifier such as CVE-2014-0160, the identifier for Heartbleed. The identifier helps researchers, vendors, security teams, and databases discuss the same flaw without relying on different product-specific names.
The CVE program was launched in 1999. MITRE has operated the program for many years, while the U.S. National Institute of Standards and Technology uses CVE data in the National Vulnerability Database.
CVE is not itself a severity score, patch, or vulnerability scanner. Severity is commonly assessed separately with systems such as CVSS, while CVE supplies the shared reference label.
Source: Wikipedia · fact-checked Sept. 2026