A CVE record is the public entry for one vulnerability, kept by the CVE Program. It is written by the organisation that assigned the identifier, a CVE Numbering Authority (CNA), which is usually the vendor of the product. The record is the primary source; databases such as the NVD copy it and add their own analysis.
The fields that matter when you triage
- Affected products and versions. Structured ranges such as “from 2.0 before 2.17.1”. This is what tells you whether your installed version is in scope.
- Description. One paragraph by the CNA on what goes wrong and what an attacker gains.
- CVSS. The CNA’s own severity assessment, when it provides one. Other organisations, such as CISA’s enrichment programme, can attach theirs to the same record.
- References. Links to the vendor advisory, the patch and technical write-ups.
- State and dates. PUBLISHED or REJECTED, when the record was published and when it last changed.
What the record does not say
Whether the vulnerability is being exploited. That comes from two other sources shown on the sheet: the CISA KEV catalog, which lists confirmed exploitation, and EPSS, which estimates its probability. A record with a critical score and neither signal is usually less urgent than a medium one that is in KEV.