Severity labels are not one scale
A P1, a Medium (5.3), and a critical CVSS 10.0 are three different source labels. This page does not convert them.
Bugcrowd priority
Cards from Bugcrowd use P1 through P5. Those are priority labels from the Vulnerability Rating Taxonomy. They are not CVSS scores. A program can set a different priority than the baseline taxonomy. This catalog does not turn a P label into a number.
P1: 6P2: 4
HackerOne source string
Cards from HackerOne keep the severity words and the score the report showed, such as Medium (5.3). That pair is the source string. It is not a Bugcrowd priority, and it is not rescored here.
Medium (5.3): 2Low (3.1): 1
CVSS word plus score
GitHub advisory cards keep the qualitative word and the score together, such as critical; CVSS 10.0. On CVSS v3.1 the qualitative bands are None 0.0, Low 0.1 to 3.9, Medium 4.0 to 6.9, High 7.0 to 8.9, and Critical 9.0 to 10.0 (FIRST CVSS v3.1). A Critical on that scale is not a Bugcrowd P1.
critical; CVSS 10.0: 4critical; CVSS 9.8: 6
The count next to each label is how many cards in this catalog use that exact source string. Open the disclosures.