A deterministic rule set, not a model: every row prints its inputs, weights and arithmetic so an auditor can reproduce the number.
Public CVE records only. Nothing here is evidence that the vulnerability exists on your assets.
Powered by: public.cves via fetchCves (CVSS vector, EPSS, KEV, CWE) · public.canonical_findings for verification completeness in environment mode
Rule: Priority = 0.35 × (CVSS ÷ 10) + 0.25 × exploitability + 0.20 × CIA impact + 0.20 × operational reach. exploitability = max(EPSS, mean(AC, PR, UI)); CIA impact = mean(C, I, A) with High = 1, Low = 0.4, None/absent = 0; operational reach = mean(AV, PR, UI). Buckets: ≥ 0.72 Patch now, ≥ 0.52 Investigate, ≥ 0.32 Monitor, else Low.
Score = 0.35 × severity + 0.25 × exploitability + 0.20 × CIA impact + 0.20 × operational reach, each factor normalised to 0–1.
Inputs used: CVSS base vector (AV, AC, PR, UI, C, I, A), CVSS base score, EPSS probability, CISA KEV membership, CWE identifiers.
Bands: ≥ 0.72 urgent · 0.52–0.71 important · below 0.52 watch. Labels change with the score only — there is no learning, no weighting drift, and no hidden adjustment.
Excluded from the score: asset criticality (Unknown — not collected), compensating controls, network segmentation, patch availability, owner workload.
Freshness: EPSS and KEV values are as fresh as the catalogue sync timestamp shown in the coverage line above.