CVE 101: Demystifying the Three-Letter Acronym

Episode 22   Published October 7, 2025 9 minute watch

Summary

A CVE is a globally unique ID for a single vulnerability, like a license plate, while CVSS supplies the zero-to-10 technical severity score and CNAs are the trusted organizations that assign CVE IDs. Landon Miles ties the vocabulary together around one point: a high CVSS score reflects technical severity, not business risk. Before you decide what to patch first, you layer in context. Is it internet exposed, is there a public proof of concept, is it being actively exploited, and what is the blast radius if it is.