CVSS Score Calculator

Measure vulnerability severity with transparent CVSS math. See vectors, subscores, charts, and exports in one place. Use it confidently for faster cleaner security prioritization workflows.

CVSS Metric Inputs

Base Metrics
Temporal Metrics
Environmental Metrics
Reset

Result appears above this form after submission.

Example Data Table

Reference Vector String Base Score Severity Scenario
CVE-2026-1001 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 9.8 Critical Remote unauthenticated RCE
CVE-2026-1002 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N 3.9 Low Authenticated phishing chain
CVE-2026-1003 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H 7.2 High Privilege escalation on host
CVE-2026-1004 CVSS:3.1/AV:P/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L 1.8 Low Local maintenance abuse case

Formula Used

This calculator evaluates CVSS v3.1 using base, temporal, and environmental metrics. It computes exploitability, impact, and modified environmental values, then rounds upward to one decimal place.

How to Use This Calculator

  1. Select the base metrics that best describe the vulnerability.
  2. Add temporal values when exploit maturity or remediation status matters.
  3. Adjust environmental settings for the affected organization or asset.
  4. Click the calculation button to generate scores and vector output.
  5. Review the chart, severity ratings, and subscores for context.
  6. Export the result as CSV or PDF for reporting workflows.

FAQs

1. What does CVSS measure?

CVSS measures technical severity, not full business risk. It standardizes how exploitability and impact are described so teams can compare vulnerabilities consistently.

2. Why are there three scores here?

Base reflects intrinsic severity. Temporal adjusts for exploit maturity and remediation. Environmental tailors scoring to your environment, requirements, and deployed conditions.

3. What is the vector string used for?

The vector string compresses all selected metric values into one standardized format. It makes sharing, reproducing, and validating a score much easier.

4. Why can scope change increase the score?

Changed scope means compromise crosses a security boundary. That can raise impact because the vulnerable component affects resources beyond its original authority.

5. Should I always fill environmental metrics?

No. Use them when local deployment conditions matter. If not defined, the calculator falls back to the base values for a more general score.

6. Why does roundup matter in CVSS?

CVSS uses a strict upward rounding rule to one decimal place. Standard decimal rounding can produce different scores and inconsistent reporting.

7. Can this replace vulnerability prioritization?

No. Prioritization should also include asset value, exploit activity, exposure, detections, compensating controls, and business impact alongside CVSS.

8. Is a high base score always critical for my organization?

Not always. A high base score can become less urgent if the asset is isolated, protected, or low value. Environmental context is important.

Related Calculators

owasp risk rating calculator

Important Note: All the Calculators listed in this site are for educational purpose only and we do not guarentee the accuracy of results. Please do consult with other sources as well.