← All Tools

CVSS Calculator (v4.0 and v3.1)

Score vulnerabilities with the official FIRST methodology: CVSS v4.0 (Base, Threat, Environmental and Supplemental) or CVSS v3.1 (Base, Temporal and Environmental). Paste a vector of either version and the matching calculator opens.

All processing happens locally in your browser. No data is sent to any server. Studying for the CISSP? CVSS lives in Domain 3 — try the Security Architecture and Engineering practice questions.
CVSS-B
--
Select all base metrics
CVSS:4.0

Exploitability Metrics (Required)

Reflect the characteristics of the vulnerable system that influence how the vulnerability can be reached and triggered by an attacker.

Attack Vector (AV) ?
Attack Complexity (AC) ?
Attack Requirements (AT) ?
Privileges Required (PR) ?
User Interaction (UI) ?

Vulnerable System Impact (Required)

Capture the effects of a successfully exploited vulnerability on the vulnerable system itself.

Confidentiality (VC) ?
Integrity (VI) ?
Availability (VA) ?

Subsequent System Impact (Required)

Capture the effects of a successfully exploited vulnerability on systems other than the vulnerable system. Replaces the v3.1 "Scope" concept.

Confidentiality (SC) ?
Integrity (SI) ?
Availability (SA) ?

Threat Metrics (Optional)

Reflect the characteristics of a vulnerability related to threat that may change over time but not necessarily across user environments.

Exploit Maturity (E) ?

Security Requirements (Optional)

Enable customization of the score depending on the importance of the affected IT asset to the organization.

Confidentiality Requirement (CR)
Integrity Requirement (IR)
Availability Requirement (AR)

Modified Base Metrics (Optional)

Override individual base metrics based on specific characteristics of a user's environment. "Not Defined (X)" inherits the corresponding base metric value.

Modified Exploitability

Modified Attack Vector (MAV)
Modified Attack Complexity (MAC)
Modified Attack Requirements (MAT)
Modified Privileges Required (MPR)
Modified User Interaction (MUI)

Modified Vulnerable System Impact

Modified Confidentiality (MVC)
Modified Integrity (MVI)
Modified Availability (MVA)

Modified Subsequent System Impact

Modified Confidentiality (MSC)
Modified Integrity (MSI)
Modified Availability (MSA)

Supplemental Metrics (Optional)

Provide additional, contextual information that does not modify the final CVSS-BTE score, but communicates extra characteristics of the vulnerability to consumers.

Safety (S) ?
Automatable (AU) ?
Recovery (R) ?
Value Density (V) ?
Vulnerability Response Effort (RE) ?
Provider Urgency (U) ?

About CVSS v4.0

CVSS v4.0 is the latest version of the Common Vulnerability Scoring System, published by FIRST in November 2023. It introduces several significant changes over CVSS v3.1.

Key changes from CVSS v3.1

  • New base metric — Attack Requirements (AT): distinct from Attack Complexity, captures prerequisite deployment / execution conditions.
  • User Interaction (UI) expanded into three values: None, Passive, Active.
  • Scope removed and replaced by separate impact metrics for the Vulnerable System (VC/VI/VA) and Subsequent System(s) (SC/SI/SA).
  • Temporal renamed to Threat with a single simplified metric: Exploit Maturity (E). RL and RC have been removed.
  • Environmental Modified base covers all new base metrics. MSI/MSA add a "Safety (S)" value.
  • New Supplemental metric group: Safety (S), Automatable (AU), Recovery (R), Value Density (V), Response Effort (RE), Provider Urgency (U). These do not change the numeric score.
  • Nomenclature: scores are now labelled CVSS-B, CVSS-BT, CVSS-BE or CVSS-BTE depending on which metric groups are present.
  • New scoring algorithm based on macrovectors and interpolation, rather than the v3.1 closed-form formula.

References

The scoring engine on this page is a direct port of the official FIRST CVSS v4.0 JavaScript reference implementation. The lookup tables, max-severity tables and macrovector logic are embedded verbatim and the math has been validated against published reference vectors.

Import Vector String

CVSS v4.0 Severity Ratings

None

Score: 0.0

Low

Score: 0.1 - 3.9

Medium

Score: 4.0 - 6.9

High

Score: 7.0 - 8.9

Critical

Score: 9.0 - 10.0

How to use the CVSS calculator

Pick the version your source uses: CVSS v4.0 for new advisories, v3.1 for most NVD and vendor records published before 2024. Pasting a vector, or opening a link with ?vector=, selects the right tab by its CVSS:4.0 or CVSS:3.1 prefix. The steps below describe v4.0; the v3.1 tab works the same way with Base, Temporal and Environmental groups.

  1. On the Base tab, pick a value for all eleven required metrics: the exploitability metrics (AV, AC, AT, PR, UI) and the impact on the vulnerable system (VC, VI, VA) and on subsequent systems (SC, SI, SA). The score appears once every Base metric is set.
  2. Or paste an existing vector into Import Vector String, for example CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N, and press Import.
  3. Optionally set Exploit Maturity on the Threat tab, and your Security Requirements (CR, IR, AR) or Modified Base metrics on the Environmental tab.
  4. Add Supplemental metrics if you want to pass on context such as Safety or Automatable.
  5. Copy the vector string, or use Share to copy a link that reopens the calculator with the same vector.

Reading the result

The score box shows the number, its severity band and the nomenclature. CVSS-B is what vendors and NVD usually publish: it describes the flaw itself. Once you set Exploit Maturity the label becomes CVSS-BT; environmental metrics give CVSS-BE; both give CVSS-BTE, the score that reflects your own situation and is the best input for patch priority.

The example vector above, a network-reachable flaw with no privileges or user interaction and high impact on the vulnerable system only, scores 9.3 (Critical). If the flaw also fully compromises downstream systems (SC:H/SI:H/SA:H), it reaches 10.0. Keep the full vector with the score in tickets and reports: the number alone hides which assumptions produced it.

Frequently asked questions

What is the difference between CVSS-B, CVSS-BT, CVSS-BE and CVSS-BTE?

The suffix says which metric groups went into the score. CVSS-B uses only Base metrics, CVSS-BT adds Threat (Exploit Maturity), CVSS-BE adds Environmental metrics, and CVSS-BTE uses all three. The calculator switches the label automatically as soon as you set a Threat or Environmental metric.

Is a CVSS 4.0 score comparable to a CVSS 3.1 score?

Not directly. v4.0 drops Scope, adds Attack Requirements (AT), splits impact into vulnerable and subsequent systems and uses a different scoring algorithm, so the same flaw can score differently. Always quote the version with the score. For v3.1 vectors use the CVSS v3.1 calculator.

Do Supplemental metrics change the CVSS 4.0 score?

No. Safety, Automatable, Recovery, Value Density, Vulnerability Response Effort and Provider Urgency are added to the vector string as extra context, but the numeric score stays the same.

Why does the score not drop when I leave Exploit Maturity as Not Defined?

CVSS 4.0 treats Not Defined (E:X) as Attacked, the worst case, and missing Security Requirements as High. Setting E:P or E:U, or lowering CR/IR/AR, can only keep the score the same or lower it. To weigh exploitation likelihood with data, check the CVE in the EPSS lookup.

Is my vector sent anywhere?

No. Scoring runs in JavaScript in your browser using the FIRST reference lookup tables. The Share button only builds a link with ?vector= in the URL, so anyone you send it to sees the same vector.