Evidence
Active exploitation, reachability, privilege, business impact, and verified controls are observable inputs.
CODE OVER CHAOS / FIELD LAB 01
A transparent, defensive worksheet for deciding what deserves attention first—without confusing a severity score for the whole truth.
DEFENSIVE DECISION LAB
Severity describes a vulnerability. Risk emerges from repetition: exposure, identity, operational consequence, and controls compound around it.
METHOD & LIMITS
Active exploitation, reachability, privilege, business impact, and verified controls are observable inputs.
The score combines those inputs to create a consistent conversation starter. It is not a probability model.
Small repeated weaknesses can scale into systemic failure. Search for the copied condition, not only the first broken instance.
PRIMARY-SOURCE LEDGER
CISA calls the catalog an authoritative source of vulnerabilities exploited in the wild and urges organizations to prioritize timely remediation.
NIST explicitly distinguishes CVSS severity from risk, which depends on context beyond a base score.
Business impact analysis can inform consistent prioritization and response decisions.
NIST describes work to estimate exploitation likelihood as another input for prioritization.