Common Vulnerabilities and Exposures
Definition
A public identifier for a specific, disclosed cyber-security vulnerability.
Why it matters
Use the identifier to join records across NVD, vendor advisories, CISA KEV, EPSS and internal tools. A CVE identifies the issue; it does not state whether you are affected or how urgently you should act.
Use it in practice
Start with authoritative evidence, record the source and freshness, and be explicit about what this term can and cannot tell you. Connect it to asset context and a named action rather than treating it as an isolated label.