Glossary
CVE (Common Vulnerabilities and Exposures)
A unique identifier (e.g. CVE-2021-41773) assigned to a specific, publicly disclosed software vulnerability, used to cross-reference it across vendors, scanners and advisories.
CVE stands for Common Vulnerabilities and Exposures. Each CVE ID (formatted
CVE-<year>-<number>, e.g. CVE-2021-41773) refers to one specific,
publicly disclosed vulnerability in a specific piece of software.
The identifier itself carries no severity information — that comes from a separate score, usually CVSS, published alongside the CVE entry by the National Vulnerability Database (NVD) or the vendor.
Why CVEs matter when reading an Nmap scan
Nmap's service detection (-sV) reports a product and version string for
each open port, e.g. Apache httpd 2.4.49. That string is exactly what you'd
cross-reference against known CVEs for that product: Apache 2.4.49 is
affected by CVE-2021-41773, a path traversal bug that became remote code
execution when mod_cgi was enabled.
Nmap can also go further and tell you directly, via NSE scripts:
--script vulnersor--script vulscanquery a local/online CVE dataset for the detected product/version and list matching CVE IDs with a CVSS score.- The
vulnscript category (e.g.smb-vuln-ms17-010,ssl-heartbleed) actively probes for a specific, named vulnerability and reports whether the target isVULNERABLE.
Both of these are more trustworthy than guessing from a version string alone, since Nmap itself ran a targeted check. This parser surfaces both: it reads any CVEs Nmap's own scripts already found, and separately checks detected product/version strings against a small, curated set of well-known CVEs.