Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Vulnerabilities

A Vulnerability is a weakness or defect in a software or hardware component that attackers exploit. Vulnerabilities apply for STIX 2.x.

The weakness or defect is in the requirements, designs, or implementations of the code found in a software or hardware component. This weakness is directly exploited to negatively impact the confidentiality, integrity, or availability of that system.

CVE is a list of information security vulnerabilities and exposures that provides common names for publicly known problems [CVE].

For example, if a piece of malware exploits CVE-2015-12345, a Malware object could be linked to a Vulnerability object that references CVE-2015-12345.

  • Define vulnerabilities
    Define vulnerability as a weakness or defect in a software or hardware component that attackers exploit.

Parent Topic:IoC Repository

Related topics

Attack modes and methods

Indicators of compromise

Observables

Attack patterns

Campaigns

Course of actions

Identities

Infrastructure

Intrusion set

Locations

Malware

Malware analysis

Observed data

Threat actors

Threat groupings

Marking definitions

Threat notes

Threat opinions

Threat reports

Sightings

Tools

Relationships

STIX Visualizer