Findings and risk
CVE
Also called: Common Vulnerabilities and Exposures, CVE identifier
A CVE is a unique public identifier assigned to a specific known vulnerability in a specific product, in the form CVE-YYYY-NNNNN. It names a vulnerability so that different tools and vendors can refer to the same thing.
A CVE identifies a vulnerability in released software. Most of the serious findings in a penetration test of a bespoke product have no CVE, because the flaw is in code only you run.
Sources
See also
Testing, with the report an auditor can actually use
A fixed price, a date, and a report that states scope, method and closure. No discovery call required to get a number.