Skip to content

standard

CVE

CVE (Common Vulnerabilities and Exposures) is a standardized system that assigns unique identifiers to publicly disclosed cybersecurity vulnerabilities.

Known aliases

  • Common Vulnerabilities and Exposures
  • CVE
  • CVE database
  • CVE ID
  • CVE identifiers
  • CVE IDs
  • CVE Record Format

Relationships

No evidence-backed relationships are recorded.

Current stories

security3 publishers

NIST concedes manual NVD enrichment no longer scales, and gives 62 days to argue about the fix

A Federal Register RFI calls periodic scanning, static prioritization and manual remediation increasingly inadequate. Comments on redesigning the feed close October 13.

Perspective Coverage

3 publishers
Builder
Builder 35%
Operator
Operator 55%
Investor
Investor 10%

Reality

Evidence72
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence70
product9 publishers

A forum image upload carried Hacktron's researchers into OpenAI's internal GitHub

The image parsing bug had been fixed upstream about a year earlier, and the decision not to ship that fix belonged to Discourse. OpenAI's forum shared single sign-on with internal systems, so a forum account became GitHub access.

Perspective Coverage

9 publishers
Builder
Builder 35%
Operator
Operator 39%
Investor
Investor 26%

Reality

Evidence70
Adoption63
Hype gap+28
Incentives60
Confidence62

Earlier coverage

  1. Automox drafts endpoint mitigations with AI for the flaws that have no patch yet

    Security · September 11, 2026 · 1 publisher

  2. Exploitation of software flaws tops Verizon's 2026 intrusion list, up 31% year over year

    Security · September 10, 2026 · 1 publisher

  3. WordPress disclosures with no patch on day one nearly doubled in 2025

    Build · September 8, 2026 · 1 publisher

  4. Maintainers shipped 97 fixes against the 23,019 bugs Claude Mythos flagged

    Security · September 3, 2026 · 1 publisher

  5. Pooling three passes turns DeepSeek Pro's 17 findings into 28 of 32

    Build · August 29, 2026 · 1 publisher

  6. NVD stops scheduling enrichment for roughly 30,000 pre-March-2026 CVEs

    Security · August 28, 2026 · 1 publisher

  7. Twistlock's founders raised $51M for Minimus, then handed the leftovers back

    Invest · August 26, 2026 · 1 publisher

  8. Silent patches ship the details anyway. Only the defenders miss them

    Security · August 25, 2026 · 1 publisher

  9. The disclosure pipeline is triaging itself: 20,700 new CVEs, 10% more exploitation

    Security · August 19, 2026 · 1 publisher

  10. Mythos's method, not its zero-day count, is what breaks CVE-keyed vuln management

    Security · August 18, 2026 · 1 publisher

  11. CISA's KEV triage guidance tells agencies to collect RAM before they patch

    Security · August 17, 2026 · 1 publisher

  12. The AI hacking disclosures were all instructed attacks. The change is tempo, not autonomy

    Science · August 17, 2026 · 1 publisher

  13. One unsigned parent, dozens of children: why image signing keeps losing to scanning

    Build · August 14, 2026 · 1 publisher