Every vulnerability report leans on CVSS, and almost nobody reads the vector behind the number. Two findings can both say 9.8 and mean very different things in practice.
Here is what the score actually tells you, and where it quietly misleads.
The number is a summary of a vector
A CVSS base score is computed from a string like AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Those letters are the real information; the 0 to 10 is a lossy summary of them. Attack Vector, Attack Complexity, Privileges Required, User Interaction, Scope and the three impact metrics each feed the maths.
If you only ever read the number, you throw away the part that tells you how the thing is actually attacked. Learn to skim the vector and the score stops being a mystery.
Network, no privileges, no interaction is the combination that matters
The profile that should worry you is AV:N / PR:N / UI:N: reachable over the network, needs no credentials, needs no one to click anything. That is an internet-facing flaw an attacker can hit directly.
Two 9.8s are not equal if one needs local access and the other is remotely exploitable without authentication. The score hides that; the vector shows it.
Base score is severity, not your risk
The CVSS base score is intrinsic severity. It says nothing about whether the affected asset is exposed, whether an exploit exists, or whether it is internet-facing. Temporal and Environmental metrics exist to adjust for exactly that, and almost nobody fills them in.
That is why a raw list sorted by base score both overstates and understates real risk. It is a starting point, not a verdict.
Use it as a floor, then adjust
Treat the base score as a defensible floor for severity, then layer context on top: is the service reachable, is the flaw in CISA's KEV catalogue, does it have a high EPSS probability.
That is how a wall of thirty criticals becomes the three that will actually get this client hit. The number starts the conversation; it should not end it.