CVSS
A standardized scoring framework for describing the technical severity characteristics of software vulnerabilities.
Boundaries
CVSS describes vulnerability severity characteristics, not an organization's actual business risk or patch priority by itself.
Related Concepts
- CVE
- CWE
- Vulnerability Management
- Risk Assessment
Source
- https://csrc.nist.gov/glossary/term/common_vulnerability_scoring_system