> I can look at a CVE and determine for myself and my organization whether it something we need to care about.
Except it doesn't work like this.
A security scanner will include a CVE. People want no red flags on the security scanner. They don't care what the CVE is, they just want red mark go away.
The attitude to accepting useless crap as a CVE is diluting what an important CVE actually is.