World’s largest virtual agentic engineering & quality conference
Compute CVSS v3.1 Base, Temporal, and Environmental scores for any vulnerability by selecting Attack Vector, Attack Complexity, Privileges Required, Scope, and CIA impact values. Get the numerical score, severity rating, and a copyable CVSS vector string — ready to drop into your CVE entry, advisory, or risk register.
CVSS stands for the Common Vulnerability Scoring System. It is an open industry standard maintained by FIRST.org for rating the severity of software security vulnerabilities, producing a numerical score from 0.0 to 10.0 that captures how exploitable a vulnerability is and how much impact it has on confidentiality, integrity, and availability.
The CVSS calculator is a free online tool that computes CVSS v3.1 base, temporal, and environmental scores from a set of input metrics — attack vector, attack complexity, privileges required, user interaction, scope, and the confidentiality, integrity, and availability impacts. Security teams use the resulting score and vector string to triage vulnerabilities, write advisories, and meet compliance requirements.
The base score is built from eight metrics that describe how a vulnerability is exploited and what it affects. Choosing accurate values is the key to a meaningful score:
CVSS v3.1 maps every numeric score to a qualitative severity band, which most teams use to drive remediation SLAs:
The score is a prioritisation aid, not the whole picture — combine it with exploit availability, asset value, and exposure when deciding what to fix first.
The calculator implements the official CVSS v3.1 specification maintained by FIRST.org, covering base, temporal, and environmental metric groups.
A vector string is the canonical text encoding of all the metric values you selected — for example, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — used in advisories, CVE records, and security tooling.
CVSS v3.1 maps numeric scores to qualitative ratings: 0.0 = None, 0.1–3.9 = Low, 4.0–6.9 = Medium, 7.0–8.9 = High, and 9.0–10.0 = Critical.
Temporal metrics adjust the base score for real-world exploit and patch availability over time, while environmental metrics tune the score to the specific deployment context of an organisation.
Yes, the CVSS calculator is completely free with no signup or hidden charges, and the calculation runs entirely in your browser.
CVSS v4.0 is the newer revision, adding finer-grained metrics such as Attack Requirements and supplemental metrics. CVSS v3.1 remains the most widely adopted version across CVEs, scanners, and compliance frameworks, which is why this calculator implements it.
Not always. A high base score signals potential severity, but real-world priority also depends on whether a working exploit exists, how exposed the asset is, and how valuable the affected data is. Use the temporal and environmental metrics to tailor the score to your context before setting a deadline.
Did you find this page helpful?
TestMu AI forEnterprise
Get access to solutions built on Enterprise
grade security, privacy, & compliance