CVE

Common Vulnerabilities and Exposures

Allgemeine Schwachstellen und Risiken

A CVE-ID is the globally recognised, unique identifier per publicly known vulnerability in the format CVE-YYYY-NNNN(N). It is issued by the MITRE Corporation and a network of authorised partners (CNAs). Importantly, the CVE-ID names a vulnerability but on its own says nothing about its severity or likelihood of exploitation — for that, CVSS, EPSS and the KEV catalogue apply.

History. The CVE programme was launched by MITRE in 1999 to give the Babylonian confusion around vulnerabilities a common frame of reference — without CVE, every vendor would name the same flaw differently. It is traditionally funded by the US Department of Homeland Security (DHS) via CISA. In April 2025 the programme came close to ending when the MITRE contract was about to lapse; CISA extended it at the last minute by eleven months, and members of the CVE board founded the independent CVE Foundation in parallel. Facts. Actual assignment happens in a decentralised way via CNAs (CVE Numbering Authorities) — vendors, research teams and coordination bodies authorised to issue IDs for their scope. A CVE record describes the vulnerability, affected products and references; risk assessment is deliberately externalised. Outlook & recommendation. The near-shutdown of 2025 painfully exposed the global security world's dependence on a single, state-funded programme. In response, complementary sources such as the European EUVD are gaining importance. In practice: a CVE list is raw material, not an action plan — only prioritisation by exploitability and one's own context turns it into the capacity to act, as the NEOSEC Intel platform reflects.
CVE — Common Vulnerabilities and Exposures