A program through which an organization invites security researchers to find and report vulnerabilities in its systems, usually in exchange for recognition or a monetary reward. Testing is authorized only within the program's published scope and rules.
The practice of reporting a discovered vulnerability privately to the affected organization and giving it reasonable time to fix the issue before any public discussion. Also called coordinated disclosure; it prioritizes protecting users over publicity.
A public catalog that assigns a unique identifier — for example CVE-2021-44228 — to a specific, publicly known vulnerability. A CVE record is the shared reference point defenders, vendors, and researchers use to talk about the same issue.
An open standard for rating the severity of a vulnerability on a scale from 0.0 to 10.0. The score is derived from a vector of metrics describing how the vulnerability can be exploited and what impact it has, producing a comparable severity rating.
A community-maintained list of software and hardware weakness types — such as SQL injection or improper authentication. Where a CVE names one specific vulnerability, a CWE names the underlying category of weakness that caused it.
The information-gathering phase of a security assessment, in which a tester builds a picture of an authorized target — its domains, hosts, services, and technologies — before testing anything. Often shortened to recon.
The full set of points where an attacker could attempt to interact with a system — every exposed domain, endpoint, service, and input. Mapping the attack surface is a core goal of reconnaissance because you can only assess what you know exists.
An authorized, scoped assessment that simulates real attacks against a system so its owner can find and fix weaknesses first. A legitimate penetration test always has defined scope, rules of engagement, and written permission before any testing begins.
A flaw or weakness in a system that could be exploited to compromise its confidentiality, integrity, or availability. Not every vulnerability is equally serious; severity depends on how easily it can be exploited and what the impact would be.
The action taken to resolve a vulnerability — such as applying a patch, changing a configuration, or adding a control. A good vulnerability report includes remediation guidance so the owner knows not just what is wrong but how to fix it.