The document criticizes the Common Vulnerability Scoring System (CVSS) for prioritizing vulnerabilities based on theoretical models rather than empirical data. It argues that CVSS suffers from analytical and empirical failures, and proposes using a large dataset of vulnerabilities, exploits, and breaches to establish a more accurate prioritization framework. The framework would calculate the probability that an open vulnerability will be exploited based on observed breach data, in order to focus remediation on the vulnerabilities that pose the greatest actual risk.