Skip to content

Glossary

CVE (Common Vulnerabilities and Exposures)

A unique identifier (e.g. CVE-2021-41773) assigned to a specific, publicly disclosed software vulnerability, used to cross-reference it across vendors, scanners and advisories.

CVE stands for Common Vulnerabilities and Exposures. Each CVE ID (formatted CVE-<year>-<number>, e.g. CVE-2021-41773) refers to one specific, publicly disclosed vulnerability in a specific piece of software.

The identifier itself carries no severity information — that comes from a separate score, usually CVSS, published alongside the CVE entry by the National Vulnerability Database (NVD) or the vendor.

Why CVEs matter when reading an Nmap scan

Nmap's service detection (-sV) reports a product and version string for each open port, e.g. Apache httpd 2.4.49. That string is exactly what you'd cross-reference against known CVEs for that product: Apache 2.4.49 is affected by CVE-2021-41773, a path traversal bug that became remote code execution when mod_cgi was enabled.

Nmap can also go further and tell you directly, via NSE scripts:

  • --script vulners or --script vulscan query a local/online CVE dataset for the detected product/version and list matching CVE IDs with a CVSS score.
  • The vuln script category (e.g. smb-vuln-ms17-010, ssl-heartbleed) actively probes for a specific, named vulnerability and reports whether the target is VULNERABLE.

Both of these are more trustworthy than guessing from a version string alone, since Nmap itself ran a targeted check. This parser surfaces both: it reads any CVEs Nmap's own scripts already found, and separately checks detected product/version strings against a small, curated set of well-known CVEs.