False positive
-a vulnerability is identified that doesn’t exist
False negative
A vulnerability exists, but not detected
CVSS (common vulnerability scoring system)
is a standardized framework used to assess the severity of security vulnerabilities in software and hardware. It provides a way to quantify the characteristics and impact of vulnerabilities, allowing organizations to prioritize their responses based on risk
CVE (common vulnerabilities and exposures)
is a standardized system for identifying and cataloging publicly known cybersecurity vulnerabilities. It serves as a reference method for publicly known information security vulnerabilities and exposures