http://blog.risk.io/2013/08/stop-fixing-all-the-things-bsideslv/

Recent parer shows that it make sense to focus only on vulns that have ready exploits in metasploit and exploitdb