Don’t judge a vulnerability by its CVSS score

Stefan Lambregts

Video Player
Playlists: 'hackerhotel2025' videos starting here / audio

The total number of vulnerabilities continues to rise. If we had to rely on just CVSS for prioritizing those vulnerabilities, we have an enormous hard time to remediate all of them. In this talk, we’ll explore the critical gaps in CVSS-based prioritization and discuss why factors like exploitability, asset criticality, and real-time threat intelligence are way more important. Expect real-world examples, a touch of humor, and actionable insights to help you move beyond the CVSS score and toward a smarter, risk-based approach to vulnerability management.

Because let’s face it: a CVSS 7 can be way more critical to your organization then a CVSS 9!

Licensed to the public under



