Skip to main content
Severity Levels
  • Critical: High-priority vulnerabilities that pose immediate risk.
  • High: Issues requiring prompt attention but less urgent than critical.
  • Medium: Problems that should be scheduled for resolution.
  • Low: Minor vulnerabilities with minimal impact.
  • Unspecified: The severity of the finding is undetermined.
Severity is one of several prioritisation signals. See reachability analysis (ASAP) for whether vulnerable code is actually reachable, and the Exploitation Maturity Score for real-world exploitation evidence.