CVSS Calculator - CVSS v3.1 Base, Temporal & Environmental Scores

AdSense Placeholder
Slot: header_tool

CVSS Calculator

Score a vulnerability and get its CVSS vector string

Base metrics
Temporal
Environmental
--
Base
--
Temporal
--
Environmental
--
Impact / Exploitability
-- / --

AdSense Placeholder
Slot: tool_mid_article

Live Scores

Change any metric and the base score, severity and vector string update at once.

Base, Temporal, Environmental

Add the temporal metrics for exploit maturity and fixes, and the environmental ones to fit the score to your systems.

Read Any Vector

Paste a vector from an advisory or the NVD to see its score and to adjust its metrics.

Full Privacy

Everything is calculated in your browser.

How CVSS Scores a Vulnerability

The Common Vulnerability Scoring System rates how severe a security flaw is on a scale of 0 to 10. The base score depends on how the flaw is exploited (attack vector, complexity, privileges and user interaction), whether it crosses a security boundary (scope) and how badly it hurts confidentiality, integrity and availability. A network-reachable flaw needing no privileges or interaction that fully compromises all three scores 9.8.

Scores map to ratings: 0.1 to 3.9 is Low, 4.0 to 6.9 Medium, 7.0 to 8.9 High and 9.0 to 10.0 Critical. The temporal score lowers the base score when exploits are unproven or a fix exists, and the environmental score adjusts it for how much the affected system matters to you and for controls you have in place. CVSS measures severity, not risk, so use it together with how exposed and valuable your systems are.

Key Takeaways

  • FIRST specification: Uses the official v3.1 formulas, including the exact Roundup function, and the older v3.0 ones on request.
  • Vectors: Copy the vector string for reports and tickets, or load one to inspect it.
  • Not CVSS v4.0: This tool covers v3.1 and v3.0 only; v4.0 uses a different model.
AdSense Placeholder
Slot: footer_leaderboard