What is Vulnerability?
Definition
A vulnerability is a weakness in software, configuration or a process that, if exploited, can compromise the confidentiality, integrity or availability of a system. It can stem from a coding error, an insecure setting, a design flaw or an outdated dependency. Publicly disclosed vulnerabilities are catalogued with CVE identifiers, and their severity is commonly expressed as a CVSS score.
Also known as: security vulnerability, security flaw, CVE, CVSS, zero-day vulnerability

Vulnerability, threat, exploit, risk
These words are often used interchangeably, but they describe different things:
| Term | Meaning | Example |
|---|---|---|
| Vulnerability | The weakness in the system | Search input concatenated straight into a database query |
| Threat | Who or what could take advantage of it | Bots scanning the internet automatically |
| Exploit | The technique or code that uses the weakness | A crafted request that pulls data from the database |
| Risk | Likelihood combined with impact | The chance of customer data leaking, and what that would cost |
The same flaw can carry very different risk in two systems: one on an internet-facing checkout page is far more urgent than one in a reporting tool reachable only from the office network.
Where vulnerabilities come from
- Coding errors: untrusted input interpreted as a query or as HTML, as in SQL injection and XSS.
- Configuration: debug mode left on, default credentials, publicly readable storage buckets.
- Design: flows that are unsafe however cleanly coded, such as a checkout that accepts the price from the client.
- Third-party code: flaws in libraries and plugins; in modern projects most of the shipped code comes from dependencies.
The current ranking of these classes for web applications is published as the OWASP Top 10.
CVE: an ID for each flaw
The CVE (Common Vulnerabilities and Exposures) programme assigns a unique identifier to publicly disclosed vulnerabilities. IDs follow the pattern CVE-YEAR-NUMBER; the Apache Log4j flaw found in late 2021 and known as “Log4Shell” is CVE-2021-44228. IDs are assigned by CVE Numbering Authorities (CNAs), organisations authorised for a defined scope; most large software vendors act as CNAs for their own products.
Don't confuse CVE with CWE. A CWE names a type of weakness (say, SQL injection); a CVE names a specific instance in a specific product. Dependency scanners and security advisories speak in CVE IDs, so the fixed CVEs are the first thing to read when judging how urgent a library update is.
CVSS: severity is not risk
CVSS (the Common Vulnerability Scoring System), maintained by FIRST, expresses a vulnerability's severity as a score from 0 to 10. The current version, CVSS v4.0, was published in November 2023 and has four metric groups: Base, Threat, Environmental and Supplemental. The qualitative scale is 0.1–3.9 low, 4.0–6.9 medium, 7.0–8.9 high and 9.0–10.0 critical.
A common mistake is prioritising by the Base score alone. The CVSS v4.0 specification stresses that Base metrics capture intrinsic qualities and should be enriched with threat and environmental context. Whether the flaw is actually reachable in your deployment, evidence of active exploitation (for example, CISA's Known Exploited Vulnerabilities catalogue) and the data at stake matter more than the number.
From discovery to patch
A typical path: a researcher, a customer or a penetration test finds the flaw; it is reported privately to the vendor; a fix is prepared; the vulnerability and the patch are announced together. Coordinated disclosure only works if finders can reach you, and a /.well-known/security.txt file, defined in RFC 9116, is the standard way to publish a security contact. A flaw exploited before the vendor knows about it or before a patch exists is called a zero-day. Until a patch lands, compensating controls such as WAF rules or temporarily disabling the affected feature buy time, but they do not replace the fix.

