CVE

Informational

Common Vulnerabilities and Exposures

Definition

CVE (Common Vulnerabilities and Exposures) is a unique, standardized identification system for publicly known security vulnerabilities. Each vulnerability receives a CVE-YEAR-NUMBER identifier (for example, CVE-2021-44228 for Log4Shell). It is maintained by MITRE Corporation and is the global standard for referencing vulnerabilities.

Impact

Unambiguous identification of vulnerabilities globallyCoordination between security teams and vendorsBasis for patches and security updatesRemediation prioritization with the associated CVSSReference in bug bounty reports and audits

Examples

Famous CVEs in security history

Some historic CVEs: CVE-2021-44228 (Log4Shell) enabled RCE on millions of Java servers. CVE-2017-5638 (Apache Struts) caused the Equifax breach. CVE-2014-0160 (Heartbleed) exposed the memory of OpenSSL servers. Each one changed the security industry.

Practice CVE with real labs

Apply what you've learned in safe environments based on real bug bounty reports.

See practice labs
2,482

hunters training

62

labs from real hacks

1,630

completions

$14,790

paid out for these bugs

11 flags captured this week·Real hacks from HackerOne · YesWeHack · Bugcrowd·No commitment·Free Academy
Free · no account

The checklist I run on every new target

47 checks ordered by cost: first what can get you in trouble, then the cheap stuff, and finally the expensive stuff — which is where the big bounties are. I'll send it to your inbox right now.

Unsubscribe in one click, from any email.

BBLabs · bug bounty training

Stop reading about bugs and start hunting them

Create your free account and practice on labs based on real hacks that paid out thousands of euros. The Academy is free forever.

No card · free Academy · cancel anytime