Computers can have tiny mistakes. These mistakes are like small holes. Bad people can find these holes. They use them to get inside. We can fix them with updates. This keeps our tools safe. Do you use a computer?
Computers have tiny mistakes. These mistakes are called bugs. 

Computers use hardware and software to work. Most systems have tiny mistakes called bugs. A bug becomes a vulnerability when it creates a security risk. This means a bad actor could use the bug to get into a system. 
Some things make these risks more likely. Large and complex systems can have more flaws. Being connected to the internet also makes a system easier to reach. Even old systems, called legacy systems, are at higher risk. 
People use a set of steps called vulnerability management to stay safe. First, they find the systems that are most important. Then, they scan the systems to find any bugs. They can fix a bug with a software patch. A patch is a small update that closes the hole. 
Sometimes, people cannot fix every bug right away. They might use mitigation. Mitigation means they take steps to make the bug harder to use. They can also use a defense in depth strategy. This means they use many different barriers to stop an attack. As of November 2024, there are over 240,000 known vulnerabilities in the CVE database.
Computers and other machines have tiny mistakes called bugs. Most hardware and software contain these bugs even when people try their best to be perfect. A bug becomes a vulnerability when it creates a security risk. This happens if a bad actor can use the bug to steal data or stop a system from working. 
Managing these risks is a step-by-step process called vulnerability management. First, people identify which systems are the most important to protect. Next, they use tools to scan for any known weaknesses. Once a flaw is found, they must decide how to handle it. They might use remediation, which means fixing the problem with a software patch. They might use mitigation, which makes the flaw harder to use. Sometimes, they must use acceptance, which means they know the risk is there but choose to keep going. 
Many people have worked to track these digital weaknesses over time. Experts use special systems to name and score how dangerous a bug is. One system is called the Common Vulnerability Scoring System, or CVSS. Another important tool is the Common Vulnerabilities and Exposures database, known as the CVE. This database keeps a list of known flaws so people can stay informed. As of November 2024, there were more than 240,000 vulnerabilities listed in the CVE database. 
There are many reasons why vulnerabilities appear in our technology. Large and complex systems are harder to build without making mistakes. Being connected to the internet also makes it easier for attackers to reach a system. Older parts, called legacy systems, are often at a higher risk of being attacked. Poor habits during software development can also cause problems. For example, if a company is in a rush, they might miss a bug. 
You can think of computer security like protecting a house. A vulnerability is like a window that does not lock properly. A patch is like a repairman coming to fix that lock. Mitigation is like adding a loud alarm to the window instead of fixing the lock. Using a defense in depth strategy is like having a fence, a locked door, and an alarm all at once. 
In the field of computer security, a vulnerability is a flaw or weakness. These flaws appear in a system's design, implementation, or management. A malicious actor can exploit these weaknesses to compromise security. This compromise usually affects confidentiality, integrity, or availability. Confidentiality ensures only authorized people see data. Integrity ensures data remains accurate and unchanged. Availability ensures systems work when they are needed. Virtually all hardware and software contain bugs. A bug becomes a vulnerability only when it creates a specific security risk. 
Understanding how a vulnerability functions requires looking at its lifecycle. A vulnerability is initiated when it is first introduced into hardware or software. At this stage, it is often called a carrier. It becomes an active vulnerability when the software or hardware is actually running. An attacker needs an active vulnerability to perform an exploit. An exploit is the method used to take advantage of the flaw. Once a vulnerability is discovered, it might be publicly disclosed. This disclosure can increase risk because attackers can then target systems before patches arrive. Vulnerabilities eventually end when the system is patched or removed from use.
There are several distinct types of vulnerabilities categorized by their impact. Some allow for denial-of-service attacks, which stop a system from working. Others allow for code injection, where an attacker runs their own programs. A more severe type is privilege escalation. This allows an attacker to gain higher levels of access than they should have. Vulnerabilities also exist in different components. Hardware vulnerabilities can be introduced during manufacturing. Operating system vulnerabilities often involve privilege escalation. Client-server applications can suffer from process hijacking. Web applications are a major source of security incidents. They may face cross-site scripting (XSS) or SQL injection attacks. 
Many factors contribute to the creation of these digital weaknesses. Complexity is a major design factor. Large, complex systems increase the chance of unintended access points. Connectivity also plays a role. Any system connected to the internet can be accessed by attackers. Legacy systems, which are older hardware or software, are at higher risk. Development practices also matter significantly. A lack of training or excessive pressure to deliver can lead to bugs. Inadequate code reviews can also allow vulnerabilities to go unnoticed. Even modern workflows like DevOps can introduce risks if many developers have access to change configurations.
Organizations use vulnerability management to handle these risks. This process involves identifying important systems and scanning them for flaws. Management typically uses a combination of three strategies. The first is remediation, which means fixing the flaw, often with a software patch. The second is mitigation, which makes the flaw harder to exploit. This might involve reducing the attack surface. The third is acceptance, where a company chooses to live with a residual risk. Many organizations use a defense in depth strategy. This means they use multiple layers of security to protect a system.
To organize this information, experts use standardized systems. The Common Vulnerability Scoring System, or CVSS, scores vulnerabilities by severity. The Common Vulnerabilities and Exposures (CVE) database catalogs known flaws. As of November 2024, the CVE database contained more than 240,000 vulnerabilities. The National Vulnerability Database also classifies vulnerabilities into eight root causes. These include input validation errors and access control failures. Configuration vulnerabilities occur when settings create security risks. Race conditions happen when timing changes the outcome of a process in an unpredictable way.
Managing these risks is a constant challenge for administrators. Achieving perfect security is considered impossible for complex systems. Many security measures can also be expensive or difficult to use. For example, reducing a system's complexity can help, but it might make the system less useful. Organizations must prioritize their efforts because they lack the resources to fix everything. They often focus on the highest-risk vulnerabilities first. This helps them manage the cost and the time needed for repairs. 
🖼️ Images & Media (1)
More to explore
✨ What else?
Related topics you might enjoy
🔬 Go deeper
More advanced topics to explore
🪜 Step back
Simpler topics to build understanding
What is Nepedia?
A free, ad-free encyclopedia for children. Every article is written at five reading levels, so the same page works for a five-year-old and a fifteen-year-old — use the level switcher above to see this one change. No account needed to read.