Pith. sign in

REVIEW 4 cited by

A Survey on Vulnerability Prioritization: Taxonomy, Metrics, and Research Challenges

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2502.11070 v1 pith:RMXZMTM2 submitted 2025-02-16 cs.CR cs.AI

classification cs.CRcs.AI
keywords metricsprioritizationresearchvulnerabilitychallengestaxonomyactionableadvance
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

In the highly interconnected digital landscape of today, safeguarding complex infrastructures against cyber threats has become increasingly challenging due to the exponential growth in the number and complexity of vulnerabilities. Resource constraints necessitate effective vulnerability prioritization strategies, focusing efforts on the most critical risks. This paper presents a systematic literature review of 82 studies, introducing a novel taxonomy that categorizes metrics into severity, exploitability, contextual factors, predictive indicators, and aggregation methods. Our analysis reveals significant gaps in existing approaches and challenges with multi-domain applicability. By emphasizing the need for dynamic, context-aware metrics and scalable solutions, we provide actionable insights to bridge the gap between research and real-world applications. This work contributes to the field by offering a comprehensive framework for evaluating vulnerability prioritization methodologies and setting a research agenda to advance the state of practice.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 4 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure

    cs.CR 2026-07 conditional novelty 6.0 of 10

    An MCP-grounded eight-phase agent pipeline converts natural-language critical-infrastructure descriptions into source-verified knowledge graphs and schema-valid OSCAL SSP/SAR artifacts, with 0.90 CVE recall on a synth...

  2. Orchestrated Vulnerability Management for Heterogeneous Networks: Adaptive Two-Stage Vulnerability Assessment, Context-Aware Risk Prioritization, and Automated Mitigation

    cs.NI 2026-08 conditional novelty 4.0 of 10

    An SOAR+SDN framework that combines passive asset discovery, adaptive two-stage scanning, context-aware risk banding, and automatic mitigation, with testbed results claiming large scan-time and prioritization-workload...

  3. PECR: A Reproducible Specification and Synthetic Stress Test of Telemetry-Informed Vulnerability Prioritization for SD-WAN

    cs.CR 2026-08 conditional novelty 4.0 of 10

    PECR is a transparent nine-factor vulnerability prioritization protocol for SD-WAN, with synthetic stress tests showing it ranks differently than CVSS/EPSS/KEV queues, but no real outcome validation.

  4. RiskBridge: Turning CVEs into Business-Aligned Patch Priorities

    cs.SE 2026-01 reject novelty 3.0 of 10

    A weighted sum of CVSS, EPSS, and KEV indicators, marketed as a zero-day exposure model, is combined with compliance deadlines and set-cover optimization; the claimed 88% risk reduction is not backed by released artifacts.

Pith tools