Vulnerability
A weakness in software, configuration, or process that an attacker could use to do something they should not be able to do.
Not every vulnerability is a real risk to you. A critical flaw in a component you do not expose, or that requires access an attacker does not have, may sit far below a moderate flaw on the system facing the internet with no MFA in front of it.
That is why raw scanner output is a starting point rather than a plan. Prioritization needs exploitability, exposure, and business impact considered together, which is the work that turns a list into a remediation order.
Where this comes up
Vulnerability sits inside our cybersecurity and threats work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.