CVE
Common Vulnerabilities and Exposures
A public identifier for one specific, disclosed vulnerability in one product.
A CVE record names a vulnerability, the product and versions it affects and, usually, the version that fixes it. Identifiers look like CVE-2025-53355 and are assigned by organisations authorised under the programme MITRE operates.
A CVE is about one instance. Its cousin the CWE names the kind of mistake, and the same kind of mistake can need a new CVE every time it turns up somewhere else, including in a fork that copied the original code before the fix.
It is how a dependency advisory reaches the listing pages here: a published advisory against a version is a fact the catalogue checks nightly.
Assuming a fork inherits its original's fixes. A fork taken before the fix keeps the vulnerability and none of the advisory.
Related terms
See CVE on a real listing
Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.
Open the catalogue