The Common Vulnerability Scoring System (CVSS) is the industry standard for rating vulnerability severity on a 0–10 scale, mapped to labels: low, medium, high, critical. The score combines exploitability metrics (attack vector, complexity, privileges required) with impact metrics (confidentiality, integrity, availability).

What CVSS does and does not tell you

  • It rates the vulnerability in the abstract — not the risk to your specific deployment.
  • It ignores reachability: a critical CVE in a function you never call is scored the same.
  • Vendors layer their own adjustments, so 'high' rarely means the same thing across tools.

Why normalization matters

When each scanner applies its own scale and adjustments, cross-tool questions — how many high-severity issues does this repository carry? — become unanswerable without a normalization layer that maps every provider's ratings onto one explicit scale.

Severity as policy input

Severity's operational purpose is triggering decisions: which level blocks a build, which merely records. That threshold belongs in one central, versioned policy — not in each tool's console.

RELATED CONCEPTS