Learning Hub › Foundational Security › Understanding Vulnerabilities
Foundations 03 · Interactive guide
Understanding Vulnerabilities
About 40,000 new CVEs were published in 2024, far more than any team can patch at once, and only a small fraction are ever exploited. This guide explains how vulnerabilities are named, classified and scored, then has you score real CVEs and triage a backlog the way modern teams do: severity plus exploit likelihood plus business context.
Vulnerabilities, CVEs and their life story
A vulnerability is a weakness that can be exploited. A threat is someone or something that might exploit it. Risk is the likelihood and impact of that happening to you. A CVE (Common Vulnerabilities and Exposures) is simply a unique ID for one publicly known vulnerability, so everyone means the same bug. Click the fields of a real CVE record.
From discovery to patch
CWE: the type of mistake
If a CVE is one specific bug in one product, a CWE (Common Weakness Enumeration) is the kind of mistake behind it, such as SQL injection. Fixing weakness types, not just individual bugs, is how developers stop whole classes of CVEs. Below are the top 10 of the 2025 CWE Top 25 (MITRE, December 2025). Click one.
CVSS: scoring severity
The Common Vulnerability Scoring System (FIRST) rates how bad a vulnerability is on a 0–10 scale from its technical traits: how it is reached, how hard it is, and what it breaks. This calculator implements the official CVSS v3.1 base score formula exactly. Load a famous CVE or build your own.
What changed in CVSS v4.0 (Nov 2023)
- New Attack Requirements (AT) metric, separate from Attack Complexity.
- Scope is gone. Impact is split into the vulnerable system (VC/VI/VA) and subsequent systems (SC/SI/SA).
- User Interaction becomes None, Passive or Active.
- Threat metrics (Exploit Maturity) and Environmental metrics are emphasised, with labels like CVSS-B (base only) and CVSS-BTE (base + threat + environmental).
- Optional Supplemental metrics such as Automatable and Recovery, which don't change the score.
v4.0 scores come from lookup tables of "macro vectors" rather than one formula, so this page computes v3.1, which most vulnerability databases still show alongside v4.0.
CVSS measures severity, not risk
A 9.8 on a server that's switched off is less urgent than a 7.5 being exploited on your website today. CVSS base scores know nothing about whether attackers are using the bug or how important the affected system is to you. FIRST itself says the base score should be supplemented with threat and environmental context. That is what the next section is about.
Beyond CVSS: EPSS, KEV and SSVC
Three free tools answer the question CVSS can't: is this actually likely to be used against me?
The Exploit Prediction Scoring System (FIRST) estimates the chance a CVE will be exploited in the next 30 days, from 0 to 100%, updated daily from real attack data. Version 4 launched on 17 March 2025.
The Known Exploited Vulnerabilities catalogue lists CVEs with confirmed exploitation in the wild. Under Binding Operational Directive 22-01 (Nov 2021), US federal agencies must fix them by set deadlines. Everyone else can use it as a "patch first" list.
Stakeholder-Specific Vulnerability Categorization (CISA, with Carnegie Mellon SEI) is a decision tree that ends in an action: Track, Track*, Attend or Act. Try a simplified version below.
Simplified teaching model The official CISA SSVC tree has more branches; use CISA's calculator for real decisions.
Triage exercise: Monday morning's scan
Your scanner found six vulnerabilities. You can't patch everything today. Put each one in a bucket using CVSS, EPSS, KEV and what you know about the asset, then check your answers.
FictionalThese findings and IDs are invented for the exercise; the scores are realistic but not real CVEs.
Patch management: a cycle, not a project
NIST SP 800-40 Rev. 4 describes patching as routine preventive maintenance. The steps repeat every week. Click each step.
Example remediation SLAs
| Finding | Fix within |
|---|---|
| In CISA KEV, or internet-facing and critical | 48 h – 7 days |
| Critical / high, internal | 14–30 days |
| Medium | 60–90 days |
| Low | Next maintenance cycle |
Illustrative values; each organisation sets its own. BOD 22-01 typically gives agencies two weeks for newly added KEV entries.
When you can't patch yet
- Mitigate: apply the vendor's workaround, such as disabling the vulnerable feature.
- Virtual patch: a WAF or IPS rule that blocks the exploit pattern.
- Isolate: remove internet exposure, restrict to a management network.
- Monitor: add detections for exploitation attempts.
- Accept formally: a documented, time-limited risk acceptance signed by the system owner. Never silently ignore it.
Myth or fact?
Five beliefs that lead to wasted patching effort.
Sources & further reading
- CVE Program: process and CNAs
How CVE IDs are assigned and published. Log4Shell's record: CVE-2021-44228.
- MITRE CWE Top 25 Most Dangerous Software Weaknesses
The 2025 list, ranked from CVE data.
- FIRST: CVSS v3.1 specification
The formula used by the calculator. See also the v4.0 specification.
- FIRST: Exploit Prediction Scoring System
Daily exploitation probabilities for every published CVE.
- CISA Known Exploited Vulnerabilities catalogue
And the directive behind it, BOD 22-01.
- CISA: SSVC
The full decision tree and calculator.
- NIST SP 800-40 Rev. 4: Enterprise Patch Management Planning
Patching as preventive maintenance, with risk-response options.
- CISA: Apache Log4j vulnerability guidance
A real-world case study of emergency vulnerability response.
Next: catch weaknesses before they become CVEs with the SAST in CI/CD lab, or see how attackers chain exploits in the Threat Intelligence & MITRE ATT&CK deep dive.