Severity Tiers

CVE Explained sorts every post into one of four severity tiers, following the same CVSS v3.x bands NVD uses to rate vulnerabilities.

01/01/0001

Critical

Critical-severity CVEs (CVSS 9.0-10.0): the vulnerabilities that warrant an emergency, out-of-cycle patch.

Read More »

01/01/0001

High

High-severity CVEs (CVSS 7.0-8.9): patch on an accelerated timeline, typically within days, not the next regular cycle.

Read More »

01/01/0001

Medium

Medium-severity CVEs (CVSS 4.0-6.9): worth tracking and patching on your normal maintenance cadence.

Read More »

01/01/0001

Low

Low-severity CVEs (CVSS 0.1-3.9): track them, but they rarely justify an unscheduled change.

Read More »