What the parts of a CVE record mean — the identifier, description, affected versions, references, and severity — and how to turn one into a decision about your own systems.
A CVE is a shared reference to one specific, publicly known vulnerability. Learning to read one quickly means you can decide whether it affects you and how urgently to act, without getting lost in the surrounding noise.
A CVE ID looks like CVE-2021-44228: the prefix, the year it was assigned, and a sequence number. It is just a stable label — the ID itself carries no severity information, only identity.
The description states what the weakness is and, usually, which product and version ranges are affected. The version detail is what tells you whether your deployment is actually exposed — a scary description for a version you do not run is not your problem today.
Linked advisories, vendor bulletins, and patches are where the actionable detail lives: the fixed version, the workaround, and often a clearer technical explanation than the CVE summary itself.
Most CVEs carry a CVSS score. Use it to triage, but read the vector, not just the number — a high base score may matter less if the vulnerable feature is not reachable in your configuration. See the CVSS guide for how to read the vector.