SECAI Core · phase 14 of 15 · noun

MITRE Common Vulnerability and Exposures (CVE) Database

A publicly available catalog of known cybersecurity vulnerabilities, where each vulnerability is assigned a unique CVE ID and brief description so that organizations, tools, and security professionals can consistently identify, track, and share information about specific security flaws.

The Explain card

Plain English
The CVE database is MITRE's public catalogue of known cybersecurity vulnerabilities. Each entry has a unique CVE ID and a short description so organisations, tools and professionals can identify, track and share information about a specific flaw.
Example
A consultant auditing an AI platform exports its software bill of materials and checks every component against the CVE database, discovering that the vector database version in use has a known authentication bypass.
Why it matters
AI systems are built from dozens of libraries and services. The CVE database is the master index that turns "is this safe?" into a checkable question.
Hook
The phone book of known flaws.

Word knowledge

How the word is built, where it came from, and what it sits beside in memory.

In a sentence

The security analyst used the MITRE Common Vulnerability and Exposures (CVE) Database to match a scanner finding with its published identifier.

Why these words
  • MITRE English organizational name adopted in 1958 identifies the organization that created and maintains the naming program
  • Common Latin communis, shared by all signals a standardized vocabulary shared across security systems
  • Vulnerability Late Latin vulnerabilis, able to be wounded names the type of weakness recorded
  • and Old English and, also or in addition joins the two coordinated security nouns
  • Exposures Latin exponere, to put forth or leave open adds security conditions that expose systems to risk
  • CVE English initialism formed from Common Vulnerabilities and Exposures provides the standard shortened form
  • Database English compound of data and base identifies the organized collection associated with the program
Where it came from
Origin
English name coined by MITRE as Common Vulnerabilities and Exposures, abbreviated CVE
Entered the language
1999
What changed
The institutional name produced the initialism CVE, which became the usual modifier in compounds such as CVE ID, CVE record, and CVE database.
How it is spelled
Pattern
The principal words are capitalized as parts of an institutional name.
Pattern
The initialism CVE takes the first letters of Common, Vulnerabilities, and Exposures.
Pattern
Database is written as one closed compound.
Breaks the pattern
The established official name uses the plural Vulnerabilities, not the singular Vulnerability.
Breaks the pattern
MITRE is conventionally written in capitals, although MITRE states that its name is not an acronym.

Spelled like

  • Common Weakness Enumeration
  • Common Attack Pattern Enumeration and Classification
  • National Vulnerability Database
Broken into chunks
  • commun
    • community
    • communal
    • communicate
  • vulner
    • vulnerable
    • invulnerable
  • expos
    • expose
    • exposure
    • exposition
  • data
    • datum
    • metadata
    • dataset
  • base
    • basis
    • basic
    • baseline
What it sits beside

Same subject

Same shape

  • Common Weakness Enumeration (CWE)
  • Common Platform Enumeration (CPE)
  • Common Vulnerability Scoring System (CVSS)

cybersecurity initialisms

  • CVE
  • CWE
  • CPE
  • CVSS

vulnerability reference resources

  • CVE List
  • National Vulnerability Database

Where it sits in the deck

Phase 14: Incident Response, Evaluation, and Knowledge Bases

When detection fires, teams need structured response plans, scoring frameworks, and curated knowledge bases to triage, measure, and learn from AI security events.