A CVE, or Common Vulnerabilities and Exposures, is a unique identifier assigned to a known, publicly disclosed cybersecurity vulnerability. Its purpose is to allow professionals, businesses and software vendors to refer to the same vulnerability using a common reference.
A CVE usually follows the format CVE-year-number, for example CVE-2025-12345. This identifier makes it possible to find available information about the vulnerability concerned, including the affected software or system, the nature of the flaw and any available fixes.
When a new vulnerability is discovered, having a common identifier makes it much easier to track. Software vendors, equipment manufacturers and cybersecurity specialists can therefore identify the affected systems more precisely and determine the measures that need to be taken.
Secure your data with our cybersecurity experts
Not all CVEs present the same level of risk. Some vulnerabilities are relatively difficult to exploit or have a limited impact, while others may allow a cybercriminal to take control of a system, access sensitive information or install malware. Their severity can notably be assessed using the CVSS (Common Vulnerability Scoring System).
For a business, monitoring CVEs that affect the software and equipment it uses is therefore an integral part of vulnerability management. When a significant vulnerability is identified, IT teams need to assess the risk and, where a fix is available, deploy the appropriate security patch quickly.
A CVE is therefore neither a cyberattack nor a virus: it is first and foremost a standardised reference used to identify and track a known vulnerability.