How code actually gets exploited, and what that means for the way you review it.
A list of findings is not a risk assessment. Exploit chain mapping traces how untrusted input actually reaches a dangerous operation — and changes which bugs you fix first.