
This is our present model.
Some things to consider:
- CVSS should be in
Vulnerability Reference and not in Vulnerability, since, CVSS scores are assigned to particular CVE-IDs
- There should be some distinction in b/w a vulnerable package version and fixed version. Atm, we store just the fixed version.