Join Nostr
2026-08-07 09:02:24 UTC
in reply to

npub1jj…snhpx on Nostr: A researcher can describe it as critical in text But CVE scoring has a real ...

A researcher can describe it as critical in text

But CVE scoring has a real methodology with various frameworks and takes time to do properly, just have a look at the NIST CVSS calculator

https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator

A valid critical 9+ cve score is more science than propaganda

can it be that some of the redteam's critical vulnerabilities found are actually 7 or 8 cve? yes possible, but those are sill valid vulns to patch