CVSS (Common Vulnerability Scoring System)
CVSS is the open standard that assigns a 0–10 severity score to a vulnerability based on its intrinsic characteristics.
CVSSvulnerability scoringseverityriskprioritization
CVSS is the open standard that assigns a 0–10 severity score to a vulnerability based on its intrinsic characteristics.
What is CVSS?
It's useful as a baseline, but it gives every organization the same score for the same CVE — it doesn't know which of your assets are internet-facing, hold CUI, or are isolated.
Why It Matters
Triaging by CVSS alone floods teams with "criticals" that may not be critical in their environment, and buries ones that are.
How Advisedly Helps
Advisedly's TRACE Score factors in your real environment to prioritize what matters to you — explainable and reproducible (we don't publish the formula). Learn about TRACE.