Glossary
CVSS (Common Vulnerability Scoring System)
An industry-standard 0–10 score describing how severe a vulnerability is, based on factors like attack complexity, privileges required and impact.
CVSS (Common Vulnerability Scoring System) produces a score from 0.0 to 10.0 for a given vulnerability, usually published alongside its CVE entry. Higher is worse.
A common bucketing (CVSS v3.x) is:
| Score | Severity |
|---|---|
| 9.0 – 10.0 | Critical |
| 7.0 – 8.9 | High |
| 4.0 – 6.9 | Medium |
| 0.1 – 3.9 | Low |
The score is derived from metrics like attack vector (network vs. local), attack complexity, privileges required, user interaction, and the impact on confidentiality, integrity and availability — not just "can this crash the service," but how easily and how badly.
When Nmap's vulners/vulscan scripts report a CVE for a detected service,
they usually print the CVSS score next to it. This parser uses that score,
when present, to bucket the finding into the same severity scale shown
throughout the tool.