Jump to content

User:Guninvalid/Notability of vulnerabilities

From Wikipedia, the free encyclopedia
This is the current revision of this page, as edited by Guninvalid (talk | contribs) at 22:25, 22 September 2025 (Created page with '{{notability essay|category=User essays on notability}} Vulnerabilities are extremely common in any substantial system or application. Some are catastrophic, potentially allowing complete system compromise and potentially even human death. Some are better described as typos. Not every vulnerability is notable. This essay provides a brief description of factors which can make a vulnerability notable for either...'). The present address (URL) is a permanent link to this version.
(diff) ← Previous revision | Latest revision (diff) | Newer revision → (diff)

Vulnerabilities are extremely common in any substantial system or application. Some are catastrophic, potentially allowing complete system compromise and potentially even human death. Some are better described as typos. Not every vulnerability is notable. This essay provides a brief description of factors which can make a vulnerability notable for either an article or for inclusion on a broader page.

Standalone notability

[edit]

For any topic to meet notability for a standalone article, it must meet Wikipedia's policies on notability. For vulnerabilities, the gold standard is that they should have been described in detail in papers published in journals, preferably more than one.

CVEs rarely meet this line without being given a proper name. As a general rule, if a CVE is only known by its number, it is not notable enough for an article. On the other hand, if there is an established common name that is different from the CVE, it is likely that the name was given in published journal papers, and thus it is likely to be notable. Notable CVEs include Heartbleed (CVE-2014-0160).

Application notability

[edit]

Many CVEs do receive significant coverage, but much of it is considered run-of-the-mil. In these cases, if a significant number of articles is discussing these vulnerabilities in-depth, it may be considered notable enough for an article on the application itself, such as CVE-2025-22230 currently listed under VMware#Incidents.