Glossary Security

Vulnerability

A vulnerability is a weakness in software, hardware or a process that an attacker could exploit to do something unintended.

Last reviewed:

AdSense Placeholder
Slot: header_reference_page

In more detail

Vulnerabilities come from coding mistakes, bad configuration or design flaws. Publicly known ones get a CVE identifier and a CVSS severity score, and are fixed by patches. The risk depends on how easy the flaw is to exploit, whether it is exposed and what it would give an attacker.

Try these tools

See also

  • Glossary CVE
    A CVE (Common Vulnerabilities and Exposures) is a unique identifier, such as CVE-2021-44228.
  • Glossary CVSS
    CVSS (Common Vulnerability Scoring System) is the standard way to rate how severe a vulnerability is, on a scale from 0.0 to 10.0.
  • Glossary Zero-day
    A zero-day is a vulnerability unknown to the software's maker, or without an available fix.
  • Cheat sheet CVSS Metrics Cheat Sheet
    The eight CVSS v3.1 base metrics with their weights, the severity bands.
AdSense Placeholder
Slot: footer_leaderboard