This paper proposed a hierarchical evaluation method to quantitative evaluate vulnerability attributes to improve vulnerability risk evaluation process. It developed a evaluation system based on the analytic hierarchy process to obtain the factor weights. And it quantified the vulnerability severity based on the fuzzy comprehensive evaluation to give the severity rank, evaluated vulnerability by the combining of exploitability attributes and safety influence attributes. Experimental results show that this method can evaluate the vulnerability severity more accurately.