It does not take time to do CVSS scoring, and the CVSS scoring system is known to have issues many issues anyway. 1. Scores are often much lower or higher than they should be. 2. It is possible to easily over- or understate the impact of a vulnerability, intentionally or not. 3. Whether the vulnerability is actively exploitable is another question. After NIST had slowed down enrichment of CVEs, and many other safeguards broke, anyone can now go and issue a CVE for a project without any verification.

Replies (1)

1000% also NIST funding not being renewed did cause chaos in the ecosystem, I agree it is not perfect