In plain English
A vulnerability is any flaw that an attacker could use to their advantage. This ranges from unpatched software with a published exploit, to a misconfigured firewall rule, to a process that relies on users never making a mistake. Not all vulnerabilities are equally exploitable — risk ratings account for the likelihood of exploitation and the potential impact.
