Due Diligence & Software

CVE

Common Vulnerabilities and Exposures

A standardized identifier for publicly known cybersecurity vulnerabilities (e.g., CVE-2024-3094 for the xz-utils backdoor). CVEs are assigned by MITRE and listed in the National Vulnerability Database (NVD). In due diligence, CVE counts in a codebase and the speed at which they are patched are key indicators of a development team's security posture.