CVE — Common Vulnerabilities and Exposures

A CVE (Common Vulnerabilities and Exposures) is a unique, standardized identifier for a publicly known cybersecurity vulnerability. In SEPSES-KG each CVE entity stores its description, CVSS v3 score and severity, publication date, assigner, references, and links to affected products (CPE) and root weaknesses (CWE).

TOTAL CVE ENTITIES
402,865
AVG CVSS
6.8
CRITICAL COUNT
14,291

Latest CVEs

CVE-1999-0001UNKNOWN

ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets.

Published: Recent
CVE-1999-0002UNKNOWN

Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.

Published: Recent
CVE-1999-0003UNKNOWN

Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).

Published: Recent
CVE-1999-0004UNKNOWN

MIME buffer overflow in email clients, e.g. Solaris mailtool and Outlook.

Published: Recent

Filter CVE Data

Showing 30 of 12,482 CVEs

CVEs per Year

CVSS Average Trend per Year

Severity Distribution

TOTAL223.8K
Critical
14,2916.4%
High
68,14230.4%
Medium
112,84050.4%
Low
28,57412.8%

Top 10 CWEs linked to CVEs

CWE-79
Improper Neutralization (XSS)
18,204
CWE-89
SQL Injection
14,103
CWE-20
Improper Input Validation
11,642
CWE-787
Out-of-bounds Write
9,401
CWE-125
Out-of-bounds Read
8,231

Understanding CVE Fields

dcterms:identifier

The unique, standardized identifier code associated with this vulnerability (e.g., CVE-2025-9231).

dcterms:description

A detailed textual explanation of the cybersecurity weakness, vulnerability mechanism, and attack vectors.

hasCVSS3BaseMetric

Linked node storing the CVSS v3 details including Base Score, Severity, Exploitability, and Impact Metrics.

hasCPE

Identifies the affected software/hardware products, versions, and vendors mapped via Common Platform Enumeration.

hasCWE

Points to the root Common Weakness Enumeration system design flaw causing this vulnerability instance.

published

The official timestamp marking when the cybersecurity community was publicly informed about the vulnerability.