Home› Cybersecurity›CVSS Score Calculator
Cybersecurity tool

CVSS Score Calculator

Choose the eight CVSS v3.1 base metrics to calculate the base score, severity and vector string locally.

Calculate a CVSS v3.1 base score

Choose the eight CVSS v3.1 base metrics to calculate the base score, severity and vector string locally.

CVSS v3.1 base score—
Severity—
Impact sub-score—
Exploitability—
—

What this CVSS score calculator covers

This implementation calculates the CVSS v3.1 Base score from Attack Vector, Attack Complexity, Privileges Required, User Interaction, Scope, Confidentiality, Integrity and Availability. It also produces the complete v3.1 vector string so the selected metrics can be reviewed and reproduced.

CVSS version matters

CVSS v4.0 is the newer standard and changes both the metric model and scoring approach. This page intentionally labels its calculation as v3.1 because silently mixing v3.1 inputs with v4.0 scoring would be misleading. Use the version required by your vulnerability-management process and keep the vector with the numerical score.

How to interpret the result

CVSS communicates technical severity; it is not a complete business-risk score. Asset importance, exploit activity, exposure, compensating controls and environmental context can change remediation priority even when two vulnerabilities have the same Base score.

Scoring discipline

Choose metric values from the vulnerability's actual characteristics rather than from the desired severity outcome. When publishing or sharing a score, include the vector string and the CVSS version so others can reproduce the assessment.

Frequently asked questions

Does this calculate CVSS v4.0?
No. This tool calculates the CVSS v3.1 Base score and labels that version explicitly. CVSS v4.0 uses a different scoring model.
What is a CVSS vector string?
It is a compact representation of the metric values used to derive the score, making the assessment reproducible.
Is CVSS the same as business risk?
No. CVSS describes vulnerability severity; business risk also depends on asset value, exposure, threat activity and controls.
Why keep the CVSS version with the score?
Scores from different CVSS versions are not interchangeable, so the version is necessary context.