I've only seen CVSS used by vendors to declare a lower severity rating than is warranted by an earnest understanding of a bug, and bug bounty hunters to do the opposite.
For example, what does Network vs Local vs Physical mean if it's an exploit in a cloud microservice?
Ooh let me consult the tea leaves. What's that? They consider it "Network" even though it's S3 mounted locally as a filesystem? Now that sev:med looks like a sev:crit.
The known alternative to CVSS is to rate severity levels entirely on vibes, and I find vibes to be more accurate.