In more detail
The format is CVE-year-number. Having one shared name lets vendors, scanners and security teams talk about the same flaw. Entries are catalogued in the CVE programme and enriched with severity data in databases such as the US National Vulnerability Database.