Weakness Scoring System

Our Federal government division witin the Department of Commerce, under the National Institute of Standards and Technology, NIST, has a National Vulnerability Databaase designed to help the public, and especially the technical administrators of IT systems to guage potential weaknesses or vulnerabilities in software and hardware systems.  

 

NATIONAL VULNERABILITY DATABASE

NIST has been working with private industry and other public sector organizations to rate and maintain a catalog of IT threats.   Originally started in 1999 under another name, and as an effort between NIST, SANS institute, and othrs, under the name ICAT or Internet Category Attack Toolkit.  It evolved and even faced death by lack of budgets until rebranded as NVD in 2005 and supported more fully.  

example NVD score 7.8

Example: 7.8 Severity Linux Vulnerability

This page is an excellent example of the use, and also of how technical it is.  https://nvd.nist.gov/vuln/detail/CVE-2021-46936