Read a CVSS vector, not just the number — what the base metrics mean, why the same score can matter differently in context, and how to use severity to prioritize.
CVSS turns a vulnerability into a 0.0–10.0 severity score. The number is convenient for sorting, but the value is in the vector behind it, which describes how the vulnerability behaves. Reading the vector is what separates useful triage from cargo-culting a number.
The base score is built from how the vulnerability is exploited and what it affects:
The base score assumes a reachable, default deployment. A 9.8 for a feature you have disabled may be a non-issue, while a 6.5 on your internet-facing authentication path may be your top priority. CVSS ranks the vulnerability in the abstract; you rank the risk to your system.
Treat CVSS as a first-pass sort, then adjust for exposure, exploit availability, and the sensitivity of what the affected component touches. The score starts the conversation; it does not end it.