World’s largest virtual agentic engineering & quality conference

WHENAUG 19-21
WHEREVirtual · Global
Register Now

CVSS Calculator - TestMu AI (Formerly LambdaTest)

Compute CVSS v3.1 Base, Temporal, and Environmental scores for any vulnerability by selecting Attack Vector, Attack Complexity, Privileges Required, Scope, and CIA impact values. Get the numerical score, severity rating, and a copyable CVSS vector string — ready to drop into your CVE entry, advisory, or risk register.

Categories

...

3000+ Browsers. One Platform.

See exactly how your site performs everywhere.

Try it free
...

Write Tests in Plain English with KaneAI

Create, debug, and evolve tests using natural language.

Try for free
...
TestMu Conf 2026

World's largest virtual agentic engineering & quality conference

...

AUG 19-21, 2026

REGISTER NOW

Output

Base Score Metrics
Exploitability Metrics
Attack Vector (AV)*
Privileges Required (PR)*
Attack Complexity (AC)*
User Interaction (UI)*
Scope (S)*
Impact Metrics
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
* - All base metrics are required to generate a base score.
Temporal Score Metrics
Exploit Code Maturity (E)
Remediation Level (RL)
Report Confidence (RC)
Environmental Score Metrics
Exploitability Metrics
Attack Vector (MAV)
Attack Complexity (MAC)
Privileges Required (MPR)
User Interaction (MUI)
Scope (MS)
Impact Metrics
Confidentiality Impact (MC)
Integrity Impact (MI)
Availability Impact (MA)
Impact Subscore Modifiers
Confidentiality Requirement (CR)
Integrity Requirement (IR)
Availability Requirement (AR)

What is CVSS?

CVSS stands for the Common Vulnerability Scoring System. It is an open industry standard maintained by FIRST.org for rating the severity of software security vulnerabilities, producing a numerical score from 0.0 to 10.0 that captures how exploitable a vulnerability is and how much impact it has on confidentiality, integrity, and availability.

What is the CVSS calculator?

The CVSS calculator is a free online tool that computes CVSS v3.1 base, temporal, and environmental scores from a set of input metrics — attack vector, attack complexity, privileges required, user interaction, scope, and the confidentiality, integrity, and availability impacts. Security teams use the resulting score and vector string to triage vulnerabilities, write advisories, and meet compliance requirements.

Understanding the CVSS base metrics

The base score is built from eight metrics that describe how a vulnerability is exploited and what it affects. Choosing accurate values is the key to a meaningful score:

  • Attack Vector (AV): How remote the attacker can be — Network, Adjacent, Local, or Physical. Network-exploitable issues score highest.
  • Attack Complexity (AC): Whether exploitation needs special conditions outside the attacker's control — Low or High.
  • Privileges Required (PR): The access level the attacker must already hold — None, Low, or High.
  • User Interaction (UI): Whether a victim must take an action for the attack to work — None or Required.
  • Scope (S): Whether the impact stays within the vulnerable component or spreads to others — Unchanged or Changed.
  • Confidentiality (C): Impact on data disclosure — None, Low, or High.
  • Integrity (I): Impact on the trustworthiness of data — None, Low, or High.
  • Availability (A): Impact on access to the system or service — None, Low, or High.

How to use this CVSS calculator?

  • Pick Base Metrics: Select values for attack vector, attack complexity, privileges required, user interaction, scope, and the confidentiality, integrity, and availability impacts that describe the vulnerability.
  • Add Temporal & Environmental Metrics (optional): Refine the score with exploit code maturity, remediation level, report confidence, and environment-specific modifiers for your deployment.
  • Read the Score: The calculator updates the base, temporal, and environmental scores in real time and emits the canonical CVSS v3.1 vector string for use in advisories and ticketing systems.

What are the features of this tool?

  • Free and Convenient Access: No signup or installation required to compute CVSS scores.
  • CVSS v3.1 Compliant: Implements the official FIRST.org v3.1 specification for base, temporal, and environmental scoring.
  • Vector String Output: Produces the canonical CVSS:3.1 vector string for copy-paste into advisories, CVEs, and ticketing systems.
  • Real-Time Calculation: Scores recalculate instantly as you change metrics, so you can compare attack scenarios side-by-side.

CVSS severity rating scale

CVSS v3.1 maps every numeric score to a qualitative severity band, which most teams use to drive remediation SLAs:

  • 0.0 — None: No measurable impact.
  • 0.1–3.9 — Low: Limited impact or hard-to-exploit issues.
  • 4.0–6.9 — Medium: Moderate risk that should be scheduled for remediation.
  • 7.0–8.9 — High: Serious issues that usually warrant prompt patching.
  • 9.0–10.0 — Critical: Severe, easily exploited vulnerabilities that demand immediate action.

The score is a prioritisation aid, not the whole picture — combine it with exploit availability, asset value, and exposure when deciding what to fix first.

Frequently Asked Questions

Which version of CVSS does this calculator support?

The calculator implements the official CVSS v3.1 specification maintained by FIRST.org, covering base, temporal, and environmental metric groups.

What is a CVSS vector string?

A vector string is the canonical text encoding of all the metric values you selected — for example, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — used in advisories, CVE records, and security tooling.

How are CVSS severity ratings categorised?

CVSS v3.1 maps numeric scores to qualitative ratings: 0.0 = None, 0.1–3.9 = Low, 4.0–6.9 = Medium, 7.0–8.9 = High, and 9.0–10.0 = Critical.

Why use temporal and environmental scores?

Temporal metrics adjust the base score for real-world exploit and patch availability over time, while environmental metrics tune the score to the specific deployment context of an organisation.

Is the CVSS calculator free to use?

Yes, the CVSS calculator is completely free with no signup or hidden charges, and the calculation runs entirely in your browser.

What is the difference between CVSS v3.1 and v4.0?

CVSS v4.0 is the newer revision, adding finer-grained metrics such as Attack Requirements and supplemental metrics. CVSS v3.1 remains the most widely adopted version across CVEs, scanners, and compliance frameworks, which is why this calculator implements it.

Does a high CVSS score mean I must patch immediately?

Not always. A high base score signals potential severity, but real-world priority also depends on whether a working exploit exists, how exposed the asset is, and how valuable the affected data is. Use the temporal and environmental metrics to tailor the score to your context before setting a deadline.

Did you find this page helpful?

TestMu AI forEnterprise

Get access to solutions built on Enterprise
grade security, privacy, & compliance

  • Advanced access controls
  • Advanced data retention rules
  • Advanced Local Testing
  • Premium Support options
  • Early access to beta features
  • Private Slack Channel
  • Unlimited Manual Accessibility DevTools Tests