XEIZE assigns each security issue a priority score from 0 to 100. This score is distinct from severity, which describes the issue's technical risk, and helps you decide which issues to address first.
- Severity describes the potential technical impact of exploiting a vulnerability.
- Priority scores combine severity with information that affects the order of remediation, such as exploitability, detection confidence, evidence of exploitation, code reachability, and the scope of credential permissions.
Priority levels
| Level | Score range | Recommended action |
|---|---|---|
| Immediate | 90–100 |
Investigate and address first because of actual exploitation or a very high potential impact. |
| Urgent | 80–89 |
Treat as an important security issue and prepare a remediation plan promptly. |
| Soon | 70–79 |
Manage as a priority issue and include it in planned remediation. |
| Review needed | 0–69 |
Below the Top Priorities threshold, but still review according to the environment and the importance of the asset. |
Criteria by scan type
| Scan type | Main criteria | Effect on priority |
|---|---|---|
| SAST | Impact, exploitability, detection confidence, and exposure scope | Uses the score defined in each SAST rule first. When no rule score exists, calculates a base score from likelihood, impact, and precision. Vulnerabilities with greater impact and a higher likelihood of being true positives receive higher priority; code-quality and basic hardening items receive lower scores. |
| SCA | CVSS, EPSS probability and percentile, code reachability, malicious packages, known exploitation, public exploits, ransomware, and potential for automation | Uses CVSS as the base risk and incorporates attack likelihood and reachability in the current project. A high CVSS score alone does not immediately promote an issue to priority response without additional threat or reachability signals. Malicious packages or known exploitation substantially increase priority. |
| Secrets | Credential type, permission scope, and potential impact of exposure | Groups detection rules by the potential impact of the credentials. Cloud and infrastructure credentials are in the higher tier, followed by tokens for source control, artifacts, and secret-management services. Items with unclear permissions or usage, such as generic API keys, receive lower default scores. |
| IaC | Potential for compromise caused by infrastructure configuration | Scores whether an infrastructure configuration issue can lead to compromise. Docker-related IaC issues are currently capped below the Top Priorities threshold. |
Order of precedence for the final score
If multiple scoring criteria apply to the same issue, the final score uses this order:
- A score manually set by a user
- A score configured in a Custom Rule
- The base score calculated for the scan type
An issue with a manually adjusted score or a Custom Rule score can therefore display a score different from the scan type's default calculation.