CVSS Calculator
Build a CVSS vector and get its score instantly — v2.0, v3.0, v3.1 and v4.0, including temporal/threat and environmental metrics. Every score is computed in your browser and matches the official FIRST.org reference. Share any result by its URL, or see how the same vector scores against real CVEs.
How the vulnerability is accessed.
How complex the attack is to execute.
Times an attacker must authenticate.
Impact on confidentiality of information.
Impact on integrity of data.
Impact on availability of the system.
See this score in the wild
A score is more useful next to real vulnerabilities. Search the CVE database for records with a similar profile to this vector.
What is CVSS?
The Common Vulnerability Scoring System (CVSS) is an open, vendor-neutral standard for rating the severity of software vulnerabilities on a 0.0–10.0 scale. A vulnerability is described by a vector of metrics — how it is exploited and what it impacts — which a formula turns into a numeric score and a qualitative rating. It is maintained by FIRST and is the scoring system used by the NVD and most vulnerability databases.
Severity ratings
| Rating | CVSS v3.x / v4.0 | CVSS v2.0 |
|---|---|---|
| Critical | 9.0 – 10.0 | — |
| High | 7.0 – 8.9 | 7.0 – 10.0 |
| Medium | 4.0 – 6.9 | 4.0 – 6.9 |
| Low | 0.1 – 3.9 | 0.0 – 3.9 |
| None | 0.0 | — |
CVSS versions
Three severity bands, no Scope or User Interaction. Still seen on older CVEs.
Adds Scope, Privileges Required, User Interaction and five severity bands.
Clarifies v3.0 — fixes rounding and the environmental impact formula.
Splits vulnerable vs subsequent system impact, adds Attack Requirements and the Threat group.