---
title: "CWEs vs CVEs, and How to Use Them"
url: "https://www.armorcode.com/podcast/cwes-vs-cves-and-how-to-use-them"
markdown_url: "https://www.armorcode.com/podcast/cwes-vs-cves-and-how-to-use-them.md"
llm_canonical: "https://www.armorcode.com/podcast/cwes-vs-cves-and-how-to-use-them.md"
canonical_for_llm: true
entity_type: "Article"
primary_entity: "CWEs vs CVEs, and How to Use Them"
citation_value: "Published on ArmorCode; canonical URL https://www.armorcode.com/podcast/cwes-vs-cves-and-how-to-use-them."
last_updated: "2025-02-21T08:01:09-08:00"
---

<h1>CWEs vs CVEs, and How to Use Them</h1>

CWE: a common software weakness with standardized descriptors that could catalyze a vulnerability. CVE: a known public vulnerability associated with 3rd party software. Mark flies solo to explain the difference and how CVEs can help us at the prioritization stage, and how CWEs come into play further on the left as we correlate data across tools.

More tactics for AppSec Success are coming at [AppSecCon 2023](https://www.thepurplebook.club/appseccon-2023?utm_campaign=AppSecCon%202023&utm_source=Let%27s%20Talk%20AppSecOps%20Podcast&utm_medium=Episode%20Home%20Resources%20link%2FDescriptions%2FSocial%20posts)
