> For the complete documentation index, see [llms.txt](https://pentesting.mrw0l05zyn.cl/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://pentesting.mrw0l05zyn.cl/general/vulnerabilidades.md).

# Vulnerabilidades

## Identificación

### Common Vulnerabilities and Exposures (CVE) <a href="#identificacioncommon-vulnerabilities-and-exposures-cve" id="identificacioncommon-vulnerabilities-and-exposures-cve"></a>

* <https://cve.mitre.org/>

El CVE-ID ofrece una nomenclatura estándar para identificar las vulnerabilidades de forma inequívoca:

* El formato para CVE-ID es: CVE-YYYY-NNNN (YYYY indica el año y NNNN el número de vulnerabilidad). Desde enero de 2014 este identificador puede contener, si es necesario, más de cuatro dígitos.
* El formato para vulnerabilidades candidatas es: CAN-YYYY-NNNN (YYYY indica el año y NNNN el número de vulnerabilidad)

## Impacto

### Common Vulnerability Score System (CVSS)

* <https://www.first.org/cvss/>

## Clasificación

### Common Weakness Enumeration (CWE)

* <https://cwe.mitre.org/>

### OWASP Web Top 10

* <https://owasp.org/www-project-top-ten/>

### OWASP Mobile Top 10

* <https://owasp.org/www-project-mobile-top-10/>

### OWASP API Security Top 10

* <https://owasp.org/www-project-api-security/>

### Common Attack Pattern Enumeration and Classification (CAPEC)

* <https://capec.mitre.org/>

### The WASC Threat Classification

* <http://projects.webappsec.org/Threat-Classification>
