It's often confusing !!!
Let's simplify this,
Consider a household with a toddler and a water tumbler on the table-
Vulnerability in this case - Placing an object made of breakable material at a height
Threat in this case - Having a toddler
Risk- Toddler knocking out the tumbler
Vulnerability is a weakness, Threat is a process/element/ event that magnifies the likelihood of negative event . Risk is the outcome of these two factors.
(pic courtesy - Google)
Information system security is dependent on these factors with a consideration of return of investment.