CVEs are the industry standard for tracking and communicating about known software vulnerabilities. Each CVE entry includes a description of the vulnerability, its severity score, and information about affected systems. SOC teams use CVEs to assess whether systems in their environment are exposed to actively exploited weaknesses and to prioritize patching and response efforts. In connected intelligence contexts, active CVEs on critical assets can directly inform SOC investigation priorities.