Glossary Security

CVSS

CVSS (Common Vulnerability Scoring System) is the standard way to rate how severe a vulnerability is, on a scale from 0.0 to 10.0.

Last reviewed:

AdSense Placeholder
Slot: header_reference_page

In more detail

A score is calculated from metrics such as attack vector, complexity, privileges required, user interaction and the impact on confidentiality, integrity and availability. Ratings run from Low (0.1-3.9) to Critical (9.0-10.0). The base score describes the flaw itself, not your own risk.

Try these tools

See also

  • Glossary CVE
    A CVE (Common Vulnerabilities and Exposures) is a unique identifier, such as CVE-2021-44228.
  • Glossary Vulnerability
    A vulnerability is a weakness in software, hardware or a process that an attacker could exploit to do something unintended.
  • Cheat sheet CVSS Metrics Cheat Sheet
    The eight CVSS v3.1 base metrics with their weights, the severity bands.
AdSense Placeholder
Slot: footer_leaderboard