CalculatorsRuns in your browser

CVSS Calculator

Free CVSS 4.0 and CVSS 3.1 calculator. Pick metrics, get the score and severity instantly, copy the vector string, and share a permalink.

Score
Base score
All 8 Base metrics are set. Temporal and Environmental metrics are optional and live below the score.
7.8
High
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 3.1 base score
All 8 Base metrics are set.
7.8
High

The vector updates as you answer. Paste a CVSS 3.0, 3.1, or 4.0 vector, or enter a CVE ID to load its NVD vector from the Strix CVE Database.

Impact
5.9
Exploitability
1.8
What moves the score
The single metric changes with the largest effect on this vector. Select one to apply it.

What the Base metrics measure

Each Base metric answers one question about the vulnerability itself, independent of who runs the software. The Base score is the number that NVD and vendors publish.

GroupMetricsQuestion it answers
ExploitabilityAV, AC, AT (4.0), PR, UIHow easy is it to trigger the vulnerability? Remote, reliable, unauthenticated, and no victim action scores highest.
Impact on the vulnerable systemC, I, A (3.x) or VC, VI, VA (4.0)What can the attacker read, change, or take offline on the system that has the bug?
Reach beyond the componentS (3.x) or SC, SI, SA (4.0)In 3.x, does the impact cross a security authority boundary, for example a sandbox escape or a guest that affects the hypervisor? In 4.0, what can the attacker read, change, or take offline on a subsequent system?

How to use the CVSS calculator

  1. Select CVSS 4.0 or CVSS 3.1. New advisories should use 4.0. Many vendors and NVD still publish 3.1 vectors.
  2. Paste a vector string or enter a CVE ID in the field at the top. The calculator loads the NVD vector from the Strix CVE Database.
  3. Or set each Base metric in the cards below. Every metric shows the question it answers. The score appears when all Base metrics are set.
  4. Open the Threat, Environmental, or Supplemental groups to score the vulnerability for your own environment.
  5. Use the list of changes that move the score most to settle a disagreement about one metric. Then copy the vector, the Markdown summary, or the link to this exact configuration.

Worked examples

Real vulnerabilities with the NVD CVSS 3.1 vector and our CVSS 4.0 mapping of the same facts. Open one to see every metric filled in.

VulnerabilityWhy it scores this wayCVSS 3.1CVSS 4.0
XZ Utils backdoorCVE-2024-3094Supply-chain backdoor in liblzma. It gives an unauthenticated remote attacker code execution inside sshd, so the impact reaches beyond the library.10.010.0
regreSSHionCVE-2024-6387Signal handler race condition in OpenSSH. Remote root without credentials, but the attacker must win a race that takes hours, so Attack Complexity is High.8.19.2
Dirty PipeCVE-2022-0847Linux kernel page cache bug. Any local user can overwrite read-only files and become root, but the attacker needs a shell first.7.88.5
Reflected XSSScript injected through a URL parameter and executed in the victim's browser. The victim must open the link, and the impact lands in the browser, not the server.6.15.1

CVSS 4.0 metric groups

CVSS 4.0 has four metric groups. Base metrics describe the vulnerability itself and do not change over time. Threat metrics adjust the score for the current exploit maturity. Environmental metrics adjust the score for one deployment. Supplemental metrics add context such as Safety and Automatable, and they do not change the numeric score.

The nomenclature next to the score shows which groups you used. CVSS-B is Base only. CVSS-BT adds Threat. CVSS-BE adds Environmental. CVSS-BTE uses all three.

Severity bands

SeverityScore range
None0.0
Low0.1 – 3.9
Medium4.0 – 6.9
High7.0 – 8.9
Critical9.0 – 10.0

Score a real CVE

Every page in the Strix CVE Database has a link that opens its NVD vector in this calculator. Use it to adjust the Environmental metrics for your own deployment, or to compare the CVSS 3.1 and CVSS 4.0 views of the same vulnerability.

Scoring follows the FIRST CVSS v3.1 and v4.0 specifications. The CVSS 4.0 implementation is a port of the FIRST.Org reference calculator (BSD-2-Clause). CVSS is owned by FIRST.Org, Inc.

Frequently asked questions

Start testing in minutes

Connect your GitHub repos and domains, and get fully set up in a few clicks.