Notes:



Vulnerabilities or exposures can be bugs in code, misconfigurations, weak or default passwords. Anything that allows an intruder to access the system in a way not intended.

Exploits are how the vulnerabilities are used, leading to a compromise.