You can use Microsoft's DREAD risk assessment model or OWASP`s risk rating methodology to prioritize security bugs based on damage and exploitability and other factors, but in the end you need to align your priorities with the same scheme that the development team uses for managing all of their other bugs.