Two MoTacon attendees are on the left. The MoTaacon logo is in the center, and to the right a prompt to Get Your Ticket.
CVE, short for Common Vulnerabilities and Exposures, is a list of publicly disclosed computer security flaws. The CVE system works by assigning unique, standardized identification numbers to publicly disclosed software vulnerabilities so organizations can track and share security information across different tools and databases.

CVE entries are brief. They don’t include technical data or information about risks, impacts, and fixes. Those details appear in other databases, including the U.S. National Vulnerability Database (NVD), the CERT/CC Vulnerability Notes Database, and various lists maintained by vendors and other organizations.

What qualifies as a CVE?

According to the CVE Numbering Authority operational rules, CVE IDs are assigned to flaws that meet specific criteria. Flaws must:
  • Be independently fixable. The flaw can be fixed independently of any other bugs.
  • Be acknowledged by the affected vendor or documented. The software or hardware vendor acknowledges the bug's existence and confirms that it negatively impacts security. Alternatively, the reporter must have shared a vulnerability report that demonstrates both the negative impact of the bug and that it violates the security policy of the affected system.
  • Affect only 1 codebase. If a flaw impacts more than 1 product, it gets a separate CVE for each product. In cases of shared libraries, protocols or standards, the flaw gets a single CVE only if there’s no way to use the shared code without being vulnerable. Otherwise each affected codebase or product gets a unique CVE.

Explore MoT
MoTaCon 2026 image
Thu, 1 Oct
A tech conference to help you navigate the ever-shifting landscape of Quality Engineering, AI, Leadership, Product, Accessibility and Security.
Everyday security testing: A practical guide to getting started image
Mitigate security risks by building simple security testing techniques into your daily routine
This Week in Quality image
Debrief the week in Quality via a community radio show hosted by Simon Tomes and members of the community
Subscribe to our newsletter