Home/Tools/Security/CVSS Calculator

CVSS Calculator

Calculate CVSS v3.1 vulnerability severity scores with Base, Temporal, and Environmental metrics. Generate vector strings and severity ratings.

100% Private - Runs Entirely in Your Browser
No data is sent to any server. All processing happens locally on your device.
Loading CVSS Calculator...

Vector String

Base Score - Exploitability Metrics

+1 more options

Base Score - Impact Metrics

+14 more fields loading...
Loading interactive tool...

Need Professional Security Testing?

Our penetration testers find vulnerabilities before attackers do. Get a comprehensive security assessment.

What Is CVSS

The Common Vulnerability Scoring System (CVSS) is an open framework for communicating the severity of software vulnerabilities. Maintained by the Forum of Incident Response and Security Teams (FIRST), CVSS provides a standardized numerical score from 0.0 to 10.0 that reflects the technical severity of a vulnerability, helping organizations prioritize remediation efforts.

CVSS is the de facto standard used by the National Vulnerability Database (NVD), vulnerability scanners like Nessus and Qualys, and compliance frameworks including PCI DSS and FedRAMP. Understanding how CVSS scores are calculated enables security teams to make informed patching decisions rather than treating every vulnerability as equally urgent.

How CVSS Scoring Works

CVSS 3.1 (the current widely-deployed version) calculates scores using three metric groups:

Base Score Metrics

MetricOptionsMeasures
Attack Vector (AV)Network, Adjacent, Local, PhysicalHow the attacker reaches the vulnerability
Attack Complexity (AC)Low, HighConditions beyond attacker control required for exploitation
Privileges Required (PR)None, Low, HighAuthentication level needed
User Interaction (UI)None, RequiredWhether a victim must take action
Scope (S)Unchanged, ChangedWhether exploitation impacts resources beyond the vulnerable component
Confidentiality (C)None, Low, HighImpact on information disclosure
Integrity (I)None, Low, HighImpact on data modification
Availability (A)None, Low, HighImpact on system accessibility

Severity Ratings

Score RangeSeverityTypical Response
0.0NoneNo action needed
0.1 - 3.9LowPatch in next maintenance window
4.0 - 6.9MediumPatch within 30 days
7.0 - 8.9HighPatch within 1-2 weeks
9.0 - 10.0CriticalImmediate patching or mitigation

Common Use Cases

  • Vulnerability prioritization: Rank hundreds of scanner findings by CVSS score to focus remediation on the most severe issues first
  • SLA definition: Establish patching timelines tied to CVSS severity levels in your vulnerability management policy
  • Risk communication: Translate technical vulnerability details into a standardized score that non-technical stakeholders can understand
  • Compliance evidence: PCI DSS Requirement 6.1 requires ranking vulnerabilities by risk — CVSS provides the recognized methodology
  • Vendor comparisons: Evaluate the security track record of third-party software by analyzing historical CVSS distributions

Best Practices

  1. Use Environmental metrics for context — The Base Score reflects generic severity. Use the Environmental metric group to adjust scores based on your specific deployment: a network-accessible vulnerability in an air-gapped system is less critical than the base score suggests.
  2. Don't ignore Medium-severity findings — Organizations that only patch Critical and High CVEs accumulate a growing attack surface of exploitable Medium vulnerabilities. Address these within defined SLAs.
  3. Combine CVSS with exploit intelligence — A CVSS 7.5 vulnerability with a public Metasploit module poses more immediate risk than a CVSS 9.0 with no known exploit. Cross-reference with CISA KEV, Exploit-DB, and threat intelligence feeds.
  4. Understand CVSS 4.0 changes — CVSS 4.0 introduces granular attack requirements, updated environmental metrics, and supplemental metrics for automatable attacks and recovery. Plan your transition from 3.1 to 4.0.
  5. Document your scoring rationale — When you adjust scores using Temporal or Environmental metrics, record why. Auditors and future analysts need to understand your risk acceptance decisions.

Frequently Asked Questions

Common questions about the CVSS Calculator

CVSS (Common Vulnerability Scoring System) is an industry-standard framework for rating the severity of security vulnerabilities. It is important because it provides a consistent way for organizations to prioritize vulnerability remediation efforts based on the potential impact to confidentiality, integrity, and availability of systems.

ℹ️ Disclaimer

This tool is provided for informational and educational purposes only. All processing happens entirely in your browser - no data is sent to or stored on our servers. While we strive for accuracy, we make no warranties about the completeness or reliability of results. Use at your own discretion.