Risk rating
The severity assigned to a finding, ideally accounting for your environment rather than the raw score alone.
A useful rating combines how easily the issue can be exploited, what it would give an attacker, and what the affected system is worth to the business. That is why the same technical issue can be critical in one report and low in another.
A report where every finding is high is not a prioritized plan. The rating exists to tell you what to fix on Monday.
Where this comes up
Risk rating sits inside our penetration testing work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.