Patch or Wait
Twelve findings and a finite queue. The trap is that the scoring is not the priority: the 9.8 nobody can reach waits behind the 6.1 with a public exploit and no login screen in front of it.
1. CVSS 9.8 remote code execution in a library used by an internal reporting tool. The tool is reachable only from the corporate network, requires an authenticated session, and no public exploit exists.
2. CVSS 6.1 authentication bypass in the customer portal's password-reset flow. Internet-facing, no credentials needed, and a working proof-of-concept was published nine days ago.
3. CVSS 7.5 denial of service in a load balancer, mitigated by rate limiting that has been in place and monitored for two years.
4. A misconfigured storage bucket holding anonymised analytics exports. Public read, no personal data, no credentials, no internal paths.
5. CVSS 5.3 information disclosure: an error page reveals the framework version. Internet-facing.
6. A domain admin account with a password last changed in 2019 and no multi-factor authentication. It is in active use by a scheduled task.
7. CVSS 8.1 in a container image that is present in the registry but not deployed to any running workload.
8. CVSS 9.1 in an edge appliance. Vendor advisory says exploitation observed in the wild; your appliance is internet-facing and the patch requires a maintenance window you do not have until next month.
9. A finding from last quarter's penetration test: session tokens do not rotate on privilege change. No exploit path demonstrated, and the tester rated it medium.
10. CVSS 7.2 privilege escalation requiring local access, on developer laptops that already grant their users local administrator rights.
11. An unauthenticated API endpoint returning full customer records. Found by a developer this morning, not present in any scan, no CVE.
12. CVSS 6.5 cross-site scripting in an admin console reachable only over VPN, with a content security policy that blocks inline script.
Ratings here follow CVSS v3.1 base scores, which is the point — a base score deliberately says nothing about your environment. Educational, and not a substitute for your own asset inventory: reachability, exposure and compensating controls are facts about your estate, and every acceptance should be recorded with an owner and a review date.