Finding
One issue raised by verification, with a severity and a mapping to a standard weakness class.
Findings are mapped to the common weakness and OWASP categories so they can be compared across listings and looked up independently.
A summary is public. The full detail goes to the buyer and to subscribers, because complete vulnerability detail on an unfixed issue published to the open internet is a disclosure rather than a review.
It is the unit that makes verification comparable rather than a single word.
Counting findings. Two low severity advisories in unused code are not worse than one reachable authentication bypass.
Related terms
See Finding on a real listing
Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.
Open the catalogue