CVSS Threat metrics

The threat metrics adjust a score for what is actually known about exploitation in the wild.

This is the group almost nobody uses, and it is the one that most changes the answer. A flaw with published, working exploit code being used today is a different proposition from one where exploitation is theoretical, even at the same base severity. Ignoring it means prioritising by how bad something could be rather than by what is happening.

Checked against the primary source.

More on Vulnerability management