A weakness in a system, application, or process that could be exploited to cause harm. Like an unlocked door in an otherwise secure building.
An unpatched web server running outdated software may have a known vulnerability that attackers can exploit to gain unauthorized access.