Glossary term

CWE

Common Weakness Enumeration. A catalogue of the underlying defect class, for example CWE-89 for SQL injection, independent of any particular product or version.

Browse Vulnerabilities →

More glossary terms

CVE
Common Vulnerabilities and Exposures. A public identifier such as CVE-2021-44228 assigned to a specific vulnerability, giving everyone one unambiguous...
CVSS
Common Vulnerability Scoring System. A 0 to 10 severity score built from exploitability and impact metrics, used to prioritise patching alongside cont...
Indicator of Compromise (IoC)
A forensic artefact that suggests a system was breached: a file hash, a suspicious domain, an unusual registry key or a known-bad IP address.
Cross-Site Scripting (XSS)
Injecting script into a page so it runs in another user's browser session, enabling cookie theft, page rewriting and credential capture.
Server-Side Request Forgery (SSRF)
Coercing the server into making a request to a destination of the attacker's choosing, typically to reach internal services or cloud metadata endpoint...
← Back to glossary

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used