// Vulnerability Analysis AI guide

How to read a CVE

What the parts of a CVE record mean — the identifier, description, affected versions, references, and severity — and how to turn one into a decision about your own systems.

A CVE is a shared reference to one specific, publicly known vulnerability. Learning to read one quickly means you can decide whether it affects you and how urgently to act, without getting lost in the surrounding noise.

The identifier

A CVE ID looks like CVE-2021-44228: the prefix, the year it was assigned, and a sequence number. It is just a stable label — the ID itself carries no severity information, only identity.

Description and affected versions

The description states what the weakness is and, usually, which product and version ranges are affected. The version detail is what tells you whether your deployment is actually exposed — a scary description for a version you do not run is not your problem today.

References

Linked advisories, vendor bulletins, and patches are where the actionable detail lives: the fixed version, the workaround, and often a clearer technical explanation than the CVE summary itself.

Severity

Most CVEs carry a CVSS score. Use it to triage, but read the vector, not just the number — a high base score may matter less if the vulnerable feature is not reachable in your configuration. See the CVSS guide for how to read the vector.

Related guides

CVSS scoring basicsRead a CVSS vector, not just the number — what the base metrics mean, why the same score can matter differently in context, and how to use severity to prioritize.

Terms used here

CVE (Common Vulnerabilities and Exposures)A public catalog that assigns a unique identifier — for example CVE-2021-44228 — to a specific, publicly known vulnerability. A CVE record is the shared reference point defenders, vendors, and researchers use to talk about the same issue.CVSS (Common Vulnerability Scoring System)An open standard for rating the severity of a vulnerability on a scale from 0.0 to 10.0. The score is derived from a vector of metrics describing how the vulnerability can be exploited and what impact it has, producing a comparable severity rating.CWE (Common Weakness Enumeration)A community-maintained list of software and hardware weakness types — such as SQL injection or improper authentication. Where a CVE names one specific vulnerability, a CWE names the underlying category of weakness that caused it.RemediationThe action taken to resolve a vulnerability — such as applying a patch, changing a configuration, or adding a control. A good vulnerability report includes remediation guidance so the owner knows not just what is wrong but how to fix it.