SECAI Core · phase 14 of 15 · noun
MITRE Common Vulnerability and Exposures (CVE) Database
A publicly available catalog of known cybersecurity vulnerabilities, where each vulnerability is assigned a unique CVE ID and brief description so that organizations, tools, and security professionals can consistently identify, track, and share information about specific security flaws.
The Explain card
- Plain English
- The CVE database is MITRE's public catalogue of known cybersecurity vulnerabilities. Each entry has a unique CVE ID and a short description so organisations, tools and professionals can identify, track and share information about a specific flaw.
- Example
- A consultant auditing an AI platform exports its software bill of materials and checks every component against the CVE database, discovering that the vector database version in use has a known authentication bypass.
- Why it matters
- AI systems are built from dozens of libraries and services. The CVE database is the master index that turns "is this safe?" into a checkable question.
- Hook
- The phone book of known flaws.
Word knowledge
How the word is built, where it came from, and what it sits beside in memory.
In a sentence
The security analyst used the MITRE Common Vulnerability and Exposures (CVE) Database to match a scanner finding with its published identifier.
Why these words
- MITRE English organizational name adopted in 1958 identifies the organization that created and maintains the naming program
- Common Latin communis, shared by all signals a standardized vocabulary shared across security systems
- Vulnerability Late Latin vulnerabilis, able to be wounded names the type of weakness recorded
- and Old English and, also or in addition joins the two coordinated security nouns
- Exposures Latin exponere, to put forth or leave open adds security conditions that expose systems to risk
- CVE English initialism formed from Common Vulnerabilities and Exposures provides the standard shortened form
- Database English compound of data and base identifies the organized collection associated with the program
Where it came from
- Origin
- English name coined by MITRE as Common Vulnerabilities and Exposures, abbreviated CVE
- Entered the language
- 1999
- What changed
- The institutional name produced the initialism CVE, which became the usual modifier in compounds such as CVE ID, CVE record, and CVE database.
How it is spelled
- Pattern
- The principal words are capitalized as parts of an institutional name.
- Pattern
- The initialism CVE takes the first letters of Common, Vulnerabilities, and Exposures.
- Pattern
- Database is written as one closed compound.
- Breaks the pattern
- The established official name uses the plural Vulnerabilities, not the singular Vulnerability.
- Breaks the pattern
- MITRE is conventionally written in capitals, although MITRE states that its name is not an acronym.
Spelled like
- Common Weakness Enumeration
- Common Attack Pattern Enumeration and Classification
- National Vulnerability Database
Broken into chunks
-
commun
- community
- communal
- communicate
-
vulner
- vulnerable
- invulnerable
-
expos
- expose
- exposure
- exposition
-
data
- datum
- metadata
- dataset
-
base
- basis
- basic
- baseline
What it sits beside
Same subject
- CVE ID
- National Vulnerability Database
- Common Weakness Enumeration
- CVSS score
- security advisory
Same shape
- Common Weakness Enumeration (CWE)
- Common Platform Enumeration (CPE)
- Common Vulnerability Scoring System (CVSS)
cybersecurity initialisms
- CVE
- CWE
- CPE
- CVSS
vulnerability reference resources
- CVE List
- National Vulnerability Database
Where it sits in the deck
Phase 14: Incident Response, Evaluation, and Knowledge Bases
When detection fires, teams need structured response plans, scoring frameworks, and curated knowledge bases to triage, measure, and learn from AI security events.