dashboard radar bug_report school newspaper sensors

Learning Hub › Foundational Security › Understanding Vulnerabilities

Foundations 03 · Interactive guide

Understanding Vulnerabilities

About 40,000 new CVEs were published in 2024, far more than any team can patch at once, and only a small fraction are ever exploited. This guide explains how vulnerabilities are named, classified and scored, then has you score real CVEs and triage a backlog the way modern teams do: severity plus exploit likelihood plus business context.

01

Vulnerabilities, CVEs and their life story

A vulnerability is a weakness that can be exploited. A threat is someone or something that might exploit it. Risk is the likelihood and impact of that happening to you. A CVE (Common Vulnerabilities and Exposures) is simply a unique ID for one publicly known vulnerability, so everyone means the same bug. Click the fields of a real CVE record.

From discovery to patch

    02

    CWE: the type of mistake

    If a CVE is one specific bug in one product, a CWE (Common Weakness Enumeration) is the kind of mistake behind it, such as SQL injection. Fixing weakness types, not just individual bugs, is how developers stop whole classes of CVEs. Below are the top 10 of the 2025 CWE Top 25 (MITRE, December 2025). Click one.

    03

    CVSS: scoring severity

    The Common Vulnerability Scoring System (FIRST) rates how bad a vulnerability is on a 0–10 scale from its technical traits: how it is reached, how hard it is, and what it breaks. This calculator implements the official CVSS v3.1 base score formula exactly. Load a famous CVE or build your own.

    Presets Exact v3.1 formula

    What changed in CVSS v4.0 (Nov 2023)

    • New Attack Requirements (AT) metric, separate from Attack Complexity.
    • Scope is gone. Impact is split into the vulnerable system (VC/VI/VA) and subsequent systems (SC/SI/SA).
    • User Interaction becomes None, Passive or Active.
    • Threat metrics (Exploit Maturity) and Environmental metrics are emphasised, with labels like CVSS-B (base only) and CVSS-BTE (base + threat + environmental).
    • Optional Supplemental metrics such as Automatable and Recovery, which don't change the score.

    v4.0 scores come from lookup tables of "macro vectors" rather than one formula, so this page computes v3.1, which most vulnerability databases still show alongside v4.0.

    CVSS measures severity, not risk

    A 9.8 on a server that's switched off is less urgent than a 7.5 being exploited on your website today. CVSS base scores know nothing about whether attackers are using the bug or how important the affected system is to you. FIRST itself says the base score should be supplemented with threat and environmental context. That is what the next section is about.

    04

    Beyond CVSS: EPSS, KEV and SSVC

    Three free tools answer the question CVSS can't: is this actually likely to be used against me?

    EPSSprobability

    The Exploit Prediction Scoring System (FIRST) estimates the chance a CVE will be exploited in the next 30 days, from 0 to 100%, updated daily from real attack data. Version 4 launched on 17 March 2025.

    CISA KEVevidence

    The Known Exploited Vulnerabilities catalogue lists CVEs with confirmed exploitation in the wild. Under Binding Operational Directive 22-01 (Nov 2021), US federal agencies must fix them by set deadlines. Everyone else can use it as a "patch first" list.

    SSVCdecision

    Stakeholder-Specific Vulnerability Categorization (CISA, with Carnegie Mellon SEI) is a decision tree that ends in an action: Track, Track*, Attend or Act. Try a simplified version below.

    Simplified teaching model The official CISA SSVC tree has more branches; use CISA's calculator for real decisions.

    05

    Triage exercise: Monday morning's scan

    Your scanner found six vulnerabilities. You can't patch everything today. Put each one in a bucket using CVSS, EPSS, KEV and what you know about the asset, then check your answers.

    FictionalThese findings and IDs are invented for the exercise; the scores are realistic but not real CVEs.

    06

    Patch management: a cycle, not a project

    NIST SP 800-40 Rev. 4 describes patching as routine preventive maintenance. The steps repeat every week. Click each step.

    Example remediation SLAs

    FindingFix within
    In CISA KEV, or internet-facing and critical48 h – 7 days
    Critical / high, internal14–30 days
    Medium60–90 days
    LowNext maintenance cycle

    Illustrative values; each organisation sets its own. BOD 22-01 typically gives agencies two weeks for newly added KEV entries.

    When you can't patch yet

    • Mitigate: apply the vendor's workaround, such as disabling the vulnerable feature.
    • Virtual patch: a WAF or IPS rule that blocks the exploit pattern.
    • Isolate: remove internet exposure, restrict to a management network.
    • Monitor: add detections for exploitation attempts.
    • Accept formally: a documented, time-limited risk acceptance signed by the system owner. Never silently ignore it.
    07

    Myth or fact?

    Five beliefs that lead to wasted patching effort.

    08

    Sources & further reading

    Next: catch weaknesses before they become CVEs with the SAST in CI/CD lab, or see how attackers chain exploits in the Threat Intelligence & MITRE ATT&CK deep dive.