Contact

What is Vulnerability?

Definition

A vulnerability is a weakness in software, configuration or a process that, if exploited, can compromise the confidentiality, integrity or availability of a system. It can stem from a coding error, an insecure setting, a design flaw or an outdated dependency. Publicly disclosed vulnerabilities are catalogued with CVE identifiers, and their severity is commonly expressed as a CVSS score.

Also known as: security vulnerability, security flaw, CVE, CVSS, zero-day vulnerability

Lifecycle of a vulnerability: discovered, disclosed with a CVE ID, scored with CVSS, patched and verified by retesting

Vulnerability, threat, exploit, risk

These words are often used interchangeably, but they describe different things:

TermMeaningExample
VulnerabilityThe weakness in the systemSearch input concatenated straight into a database query
ThreatWho or what could take advantage of itBots scanning the internet automatically
ExploitThe technique or code that uses the weaknessA crafted request that pulls data from the database
RiskLikelihood combined with impactThe chance of customer data leaking, and what that would cost

The same flaw can carry very different risk in two systems: one on an internet-facing checkout page is far more urgent than one in a reporting tool reachable only from the office network.

Where vulnerabilities come from

  • Coding errors: untrusted input interpreted as a query or as HTML, as in SQL injection and XSS.
  • Configuration: debug mode left on, default credentials, publicly readable storage buckets.
  • Design: flows that are unsafe however cleanly coded, such as a checkout that accepts the price from the client.
  • Third-party code: flaws in libraries and plugins; in modern projects most of the shipped code comes from dependencies.

The current ranking of these classes for web applications is published as the OWASP Top 10.

CVE: an ID for each flaw

The CVE (Common Vulnerabilities and Exposures) programme assigns a unique identifier to publicly disclosed vulnerabilities. IDs follow the pattern CVE-YEAR-NUMBER; the Apache Log4j flaw found in late 2021 and known as “Log4Shell” is CVE-2021-44228. IDs are assigned by CVE Numbering Authorities (CNAs), organisations authorised for a defined scope; most large software vendors act as CNAs for their own products.

Don't confuse CVE with CWE. A CWE names a type of weakness (say, SQL injection); a CVE names a specific instance in a specific product. Dependency scanners and security advisories speak in CVE IDs, so the fixed CVEs are the first thing to read when judging how urgent a library update is.

CVSS: severity is not risk

CVSS (the Common Vulnerability Scoring System), maintained by FIRST, expresses a vulnerability's severity as a score from 0 to 10. The current version, CVSS v4.0, was published in November 2023 and has four metric groups: Base, Threat, Environmental and Supplemental. The qualitative scale is 0.1–3.9 low, 4.0–6.9 medium, 7.0–8.9 high and 9.0–10.0 critical.

A common mistake is prioritising by the Base score alone. The CVSS v4.0 specification stresses that Base metrics capture intrinsic qualities and should be enriched with threat and environmental context. Whether the flaw is actually reachable in your deployment, evidence of active exploitation (for example, CISA's Known Exploited Vulnerabilities catalogue) and the data at stake matter more than the number.

From discovery to patch

A typical path: a researcher, a customer or a penetration test finds the flaw; it is reported privately to the vendor; a fix is prepared; the vulnerability and the patch are announced together. Coordinated disclosure only works if finders can reach you, and a /.well-known/security.txt file, defined in RFC 9116, is the standard way to publish a security contact. A flaw exploited before the vendor knows about it or before a patch exists is called a zero-day. Until a patch lands, compensating controls such as WAF rules or temporarily disabling the affected feature buy time, but they do not replace the fix.

Related terms

← Back to the glossary