โ† All tools

CVSS Calculator

Score a vulnerability with the official CVSS v4.0 and v3.1 metrics. The maths are the FIRST reference implementation; the score, severity and vector string update as you choose. Everything runs in your browser.

A severity score is not a risk assessment. CVSS rates the technical severity of a vulnerability, not the risk to your organisation.
  • Base metrics describe the flaw itself; add Threat and Environmental metrics to reflect your context.
  • Combine the score with exploitability, exposure and asset value before you prioritise.
  • Nothing is uploaded โ€” the calculation happens entirely on this page.

Load a vector string

โ€”
โ€”
MacroVector โ€”

About these scores

CVSS v4.0 uses the official FIRST MacroVector lookup tables and interpolation algorithm, ported verbatim from the FIRST reference calculator. It separates impact on the vulnerable system (VC/VI/VA) from impact on subsequent systems (SC/SI/SA), and the Threat (Exploit Maturity) and Environmental (Security Requirements, Modified Base) metrics refine the score. Supplemental metrics are recorded in the vector but do not change the score, by design.

CVSS v3.1 implements the base-score equations from the FIRST v3.1 specification, including the specified Roundup function. This tool computes the Base score.

Qualitative severity bands (both versions): None 0.0 ยท Low 0.1โ€“3.9 ยท Medium 4.0โ€“6.9 ยท High 7.0โ€“8.9 ยท Critical 9.0โ€“10.0.