With every year that goes by, vulnerability management—the decades-old task of locating, ranking, and fixing software vulnerabilities—faces more difficulties. With MITRE reporting 25,068 new vulnerabilities in 2022 alone—a 24.3% increase from 2021—practitioners find the task even more difficult as they struggle with the complexity of remediation in addition to the sheer volume of vulnerabilities. While the Common Vulnerability Scoring System (CVSS) has long been an industry standard for vulnerability prioritization, it has many limitations, the most notable of which is the inability of its Base metric group to dynamically include post-disclosure updates, such as the introduction of new exploits. Here are some instances of how CVSS constraints can affect vulnerability prioritization: