CVE severity is a terrible way to do this. If you follow the cybersecurity space you should know why.