CVSS Calculator (v4.0 and v3.1)
Score vulnerabilities with the official FIRST methodology: CVSS v4.0 (Base, Threat, Environmental and Supplemental) or CVSS v3.1 (Base, Temporal and Environmental). Paste a vector of either version and the matching calculator opens.
CVSS:4.0
Exploitability Metrics (Required)
Reflect the characteristics of the vulnerable system that influence how the vulnerability can be reached and triggered by an attacker.
Vulnerable System Impact (Required)
Capture the effects of a successfully exploited vulnerability on the vulnerable system itself.
Subsequent System Impact (Required)
Capture the effects of a successfully exploited vulnerability on systems other than the vulnerable system. Replaces the v3.1 "Scope" concept.
Threat Metrics (Optional)
Reflect the characteristics of a vulnerability related to threat that may change over time but not necessarily across user environments.
Security Requirements (Optional)
Enable customization of the score depending on the importance of the affected IT asset to the organization.
Modified Base Metrics (Optional)
Override individual base metrics based on specific characteristics of a user's environment. "Not Defined (X)" inherits the corresponding base metric value.
Modified Exploitability
Modified Vulnerable System Impact
Modified Subsequent System Impact
Supplemental Metrics (Optional)
Provide additional, contextual information that does not modify the final CVSS-BTE score, but communicates extra characteristics of the vulnerability to consumers.
About CVSS v4.0
CVSS v4.0 is the latest version of the Common Vulnerability Scoring System, published by FIRST in November 2023. It introduces several significant changes over CVSS v3.1.
Key changes from CVSS v3.1
- New base metric — Attack Requirements (AT): distinct from Attack Complexity, captures prerequisite deployment / execution conditions.
- User Interaction (UI) expanded into three values: None, Passive, Active.
- Scope removed and replaced by separate impact metrics for the Vulnerable System (VC/VI/VA) and Subsequent System(s) (SC/SI/SA).
- Temporal renamed to Threat with a single simplified metric: Exploit Maturity (E). RL and RC have been removed.
- Environmental Modified base covers all new base metrics. MSI/MSA add a "Safety (S)" value.
- New Supplemental metric group: Safety (S), Automatable (AU), Recovery (R), Value Density (V), Response Effort (RE), Provider Urgency (U). These do not change the numeric score.
- Nomenclature: scores are now labelled CVSS-B, CVSS-BT, CVSS-BE or CVSS-BTE depending on which metric groups are present.
- New scoring algorithm based on macrovectors and interpolation, rather than the v3.1 closed-form formula.
References
- Official CVSS v4.0 Specification (FIRST)
- CVSS v4.0 User Guide
- CVSS v4.0 Examples
- Official FIRST CVSS v4.0 Calculator
- Reference implementation source (BSD-2-Clause)
The scoring engine on this page is a direct port of the official FIRST CVSS v4.0 JavaScript reference implementation. The lookup tables, max-severity tables and macrovector logic are embedded verbatim and the math has been validated against published reference vectors.
Import Vector String
CVSS v4.0 Severity Ratings
None
Score: 0.0
Low
Score: 0.1 - 3.9
Medium
Score: 4.0 - 6.9
High
Score: 7.0 - 8.9
Critical
Score: 9.0 - 10.0
CVSS:3.1/AV:_/AC:_/PR:_/UI:_/S:_/C:_/I:_/A:_
Base Metrics (Required)
The base metric group represents the intrinsic characteristics of a vulnerability that are constant over time and across user environments.
Temporal Metrics (Optional)
Environmental Metrics (Optional)
Example Vectors
Import Vector String
CVSS v3.1 Severity Ratings
None
Score: 0.0
Low
Score: 0.1 - 3.9
Medium
Score: 4.0 - 6.9
High
Score: 7.0 - 8.9
Critical
Score: 9.0 - 10.0
How to use the CVSS calculator
Pick the version your source uses: CVSS v4.0 for new advisories, v3.1 for most NVD and vendor records published before 2024. Pasting a vector, or opening a link with ?vector=, selects the right tab by its CVSS:4.0 or CVSS:3.1 prefix. The steps below describe v4.0; the v3.1 tab works the same way with Base, Temporal and Environmental groups.
- On the Base tab, pick a value for all eleven required metrics: the exploitability metrics (AV, AC, AT, PR, UI) and the impact on the vulnerable system (VC, VI, VA) and on subsequent systems (SC, SI, SA). The score appears once every Base metric is set.
- Or paste an existing vector into Import Vector String, for example
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N, and press Import. - Optionally set Exploit Maturity on the Threat tab, and your Security Requirements (CR, IR, AR) or Modified Base metrics on the Environmental tab.
- Add Supplemental metrics if you want to pass on context such as Safety or Automatable.
- Copy the vector string, or use Share to copy a link that reopens the calculator with the same vector.
Reading the result
The score box shows the number, its severity band and the nomenclature. CVSS-B is what vendors and NVD usually publish: it describes the flaw itself. Once you set Exploit Maturity the label becomes CVSS-BT; environmental metrics give CVSS-BE; both give CVSS-BTE, the score that reflects your own situation and is the best input for patch priority.
The example vector above, a network-reachable flaw with no privileges or user interaction and high impact on the vulnerable system only, scores 9.3 (Critical). If the flaw also fully compromises downstream systems (SC:H/SI:H/SA:H), it reaches 10.0. Keep the full vector with the score in tickets and reports: the number alone hides which assumptions produced it.
Frequently asked questions
What is the difference between CVSS-B, CVSS-BT, CVSS-BE and CVSS-BTE?
The suffix says which metric groups went into the score. CVSS-B uses only Base metrics, CVSS-BT adds Threat (Exploit Maturity), CVSS-BE adds Environmental metrics, and CVSS-BTE uses all three. The calculator switches the label automatically as soon as you set a Threat or Environmental metric.
Is a CVSS 4.0 score comparable to a CVSS 3.1 score?
Not directly. v4.0 drops Scope, adds Attack Requirements (AT), splits impact into vulnerable and subsequent systems and uses a different scoring algorithm, so the same flaw can score differently. Always quote the version with the score. For v3.1 vectors use the CVSS v3.1 calculator.
Do Supplemental metrics change the CVSS 4.0 score?
No. Safety, Automatable, Recovery, Value Density, Vulnerability Response Effort and Provider Urgency are added to the vector string as extra context, but the numeric score stays the same.
Why does the score not drop when I leave Exploit Maturity as Not Defined?
CVSS 4.0 treats Not Defined (E:X) as Attacked, the worst case, and missing Security Requirements as High. Setting E:P or E:U, or lowering CR/IR/AR, can only keep the score the same or lower it. To weigh exploitation likelihood with data, check the CVE in the EPSS lookup.
Is my vector sent anywhere?
No. Scoring runs in JavaScript in your browser using the FIRST reference lookup tables. The Share button only builds a link with ?vector= in the URL, so anyone you send it to sees the same vector.