CVSS Calculator
How it works
Base metrics describe the vulnerability itself and give the score that NVD and vendors publish. Threat and Environmental metrics adjust it for exploit maturity and for one deployment. Supplemental metrics add context and do not change the number. Every CVE page in the Strix CVE Database opens its NVD vector here.
Worked examples
| Vulnerability | Why it scores this way | 3.1 | 4.0 |
|---|---|---|---|
| XZ Utils backdoorCVE-2024-3094 | Supply-chain backdoor in liblzma. It gives an unauthenticated remote attacker code execution inside sshd, so the impact reaches beyond the library. | 10.0 | 10.0 |
| regreSSHionCVE-2024-6387 | Signal handler race condition in OpenSSH. Remote root without credentials, but the attacker must win a race that takes hours, so Attack Complexity is High. | 8.1 | 9.2 |
| Dirty PipeCVE-2022-0847 | Linux kernel page cache bug. Any local user can overwrite read-only files and become root, but the attacker needs a shell first. | 7.8 | 8.5 |
| Reflected XSS | Script injected through a URL parameter and executed in the victim's browser. The victim must open the link, and the impact lands in the browser, not the server. | 6.1 | 5.1 |
Frequently asked questions
Keep exploring
Start testing in minutes
Connect your GitHub repos and domains, and get fully set up in a few clicks.
