To cope with various standard of vulnerability classification, this paper proposed simple criterion for evaluating the network risk from several vulnerability detection called as “Network Risk Metric”. Two major ideas, “Weighted Cutoff Severity Normalization” and “Probability of Trust”, will be introduced in each phase of the proposed risk evaluation metric. The overall procedure is separated into two phases: 1) Differentiate server and client risk and 2) Risk evaluation.