CVSS

CVSS is the scoring system that produces those numbers out of ten, and almost everybody uses only a fraction of it.

It has several groups of metrics. The one that gets published is the base score, describing the flaw in the abstract, identically for everybody. The other groups exist precisely to adjust for whether anybody is exploiting it and what the affected system actually does in your organisation. Consuming only the base score and treating it as a priority is the most common misuse of the framework, and it is a misuse its own documentation warns about.

Checked against the primary source.

More on Vulnerability management