Prioritise: one Priority Score sorts every CVE into an action bucket with its own SLA — so teams triage by workflow, not by scrolling a list.
Priority Score = 35% Severity (CVSS) + 25% Exploitability (EPSS/KEV) + 20% CIA impact + 20% Operational reachability (network vector, no auth, no UI).