Glossary
CVSS
CVSS gives each vulnerability a danger score from 0 to 10. A 9.8 is 'drop everything and patch now.' A 3.1 is 'add it to the list.' It helps you prioritize what to fix first.
What is CVSS?
Common Vulnerability Scoring System - a standardized framework for rating the severity of security vulnerabilities on a 0-10 scale.
Why Should You Care?
CVSS scores drive resource allocation across security teams by translating vulnerability assessments into actionable priority levels. Without standardized scoring, organizations waste time debating severity instead of patching—CVSS lets teams map scores directly to SLAs (e.g., "patch all 9.0+ vulns within 24 hours"). Vendors, vulnerability databases, and compliance frameworks all use CVSS, so your team can align patch schedules and remediation budgets based on metrics that stakeholders across your supply chain already understand.
Is your business exposed?
Real-World Example
When the Log4j remote code execution vulnerability (CVE-2021-44228) was disclosed, it received a CVSS score of 10.0—the highest possible—prompting emergency patching across thousands of organizations within days. Organizations tracking vulnerabilities by CVSS score could immediately identify Log4j as a drop-everything priority rather than triaging it against dozens of lower-rated CVEs, helping limit widespread exploitation.
How to Protect Against CVSS
- 1.
Patch critical CVSS 9+ vulnerabilities within 24 hours
- 2.
Establish SLAs for patching by CVSS score
Related Terms
Is your business exposed?
Check if your company data is circulating on the dark web
Free scan • No credit card required