None
EN
The perverse incentive of vulnerability counting
[]
Open Source Security
A goal of zero vulnerabilities will result in zero vulnerabilities, but not in the way you want. If all you focus on is vulnerability counting, there’s a very good chance you would lower your vulnerability count and accidentally increase risk elsewhere. If you can’t or don’t want to hire a security team to go over every vulnerability report and identify which vulnerabilities matter, you’re going to use CVSS.