ISTQB Mock App

Common Vulnerabilities And Exposures

Common Vulnerabilities and Exposures (CVE) is a standardized catalog of publicly disclosed software and hardware vulnerabilities.

Official definition
ISTQB Official Glossary Definition
A catalog of publicly disclosed vulnerabilities in released software packages.

(Definition reproduced from the ISTQB Glossary. Copyright belongs to ISTQB.)

View the complete ISTQB Glossary

What is Common Vulnerabilities And Exposures?

Each CVE entry provides a unique identifier for a known vulnerability, making it easier for organizations to track, discuss, and remediate security issues.

Standard identifiers: Every vulnerability receives a unique CVE ID.

Industry adoption: Used by security vendors and organizations worldwide.

Testing relevance: Security testing verifies whether known CVEs affect a system.

Real World Example

A regulated product team is preparing a release where Common vulnerabilities and exposures appears in reviews, test design conversations, or defect triage rather than as an isolated glossary word.

The risk is that the team treats Common vulnerabilities and exposures as interchangeable with nearby ISTQB terms. That makes test scope blurry and can lead to weak evidence for the release decision.

The tester anchors the discussion in the official definition, asks where the concept appears in the product, and designs examples that show the difference between Common vulnerabilities and exposures and similar ideas.

The page becomes useful in practice because Common vulnerabilities and exposures is connected to a specific testing decision, not memorized as a detached definition.

Practice Questions

Question 1

Which practice uses CVE correctly?

Question 2

A library has a CVE but your app doesn’t use the affected feature. What is BEST?

Test your knowledge with real ISTQB-style questions

You’ve learned Common Vulnerabilities And Exposures. Test your understanding with topic-specific questions in our Mock Exams.

Go to Mock Exams