CVSS, EPSS, the KEV catalog, MTTR: the vocabulary for turning a long vulnerability list into an actually prioritized — and measurable — remediation plan.
The continuous cycle of detecting, assessing, prioritizing, and fixing security flaws in an information system. Unlike a one-off audit, it's an ongoing process: new vulnerabilities are discovered every day in software already in production.
The reference score (0 to 10) measuring a flaw's intrinsic technical severity — independent of whether it's actually being exploited. Version 3.1 remains the most widely used today; version 4.0 (published late 2023) fixes a known flaw of 3.x: too many vulnerabilities ended up scored 9.8, making the score less useful for prioritization. The two versions aren't directly comparable for the same CVE.
Check a specific CVE's CVSS scoreUnlike CVSS, which measures theoretical severity, EPSS estimates the real-world probability (0 to 100%) that a flaw will be exploited within the next 30 days, based on threat intelligence signals and CVE characteristics. A CVSS 9.8 flaw with an EPSS near 0% is, in practice, often less urgent than a CVSS 7.0 flaw with an 80% EPSS.
Our built-in EPSS scoring on every scanA list maintained by the US CISA agency recording flaws whose active exploitation has been confirmed in the wild — not a prediction like EPSS, a fact. A CVE listed here deserves immediate priority, regardless of its CVSS score.
CVSS describes technical severity. EPSS estimates what's likely to be exploited next. KEV records what already has been. None of the three alone is enough to prioritize well — combining them gives a far more reliable picture than severity alone for deciding what to fix first.
MTTD (Mean Time to Detect) measures the time between a flaw appearing and it being discovered. MTTR (Mean Time to Remediate) measures the time between discovery and it actually being fixed. In practice, MTTR remains the most telling measure of an organization's real risk: a known flaw left unpatched for months is still an open door, no matter how early it was detected.
The operational process that actually applies the security fixes vendors publish — testing, scheduling, deploying, verifying. This is often where the real risk lives, not in detection: the gap between a patch being released and it actually being installed is almost always longer than the gap between a flaw's disclosure and its first exploitation.
Rather than handling every flaw at the same pace, a remediation SLA sets differentiated deadlines — for example 48 hours for a critical, actively exploited flaw (KEV), 7 days for a high-severity flaw with a high EPSS score, 30 days for the rest. This is what turns a list of vulnerabilities into an actual, measurable action plan.
See your real vulnerabilities, already scored and prioritizedA free scan, in a few minutes, no credit card required.
Free scan