CVSS 4.0 calculator

Score a vulnerability with the current CVSS standard. Set the base metrics — plus optional threat and environmental context — for an accurate v4.0 score, its severity, and a shareable vector string. The scoring is a verbatim port of the official FIRST algorithm and runs entirely in your browser.

Need CVSS 3.1 instead? Use the 3.1 calculator →

9.3
CVSS v4.0 score
Critical
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Base Metrics

Intrinsic, unchanging characteristics of the vulnerability. All are required.

Attack VectorAV
Attack ComplexityAC
Attack RequirementsAT
Privileges RequiredPR
User InteractionUI
Confidentiality (Vulnerable System)VC
Integrity (Vulnerable System)VI
Availability (Vulnerable System)VA
Confidentiality (Subsequent System)SC
Integrity (Subsequent System)SI
Availability (Subsequent System)SA

Scoring uses the official FIRST CVSS v4.0 algorithm (MacroVector method) and is verified against the reference implementation. Everything runs in your browser — nothing you enter leaves this page.

CVSS severity ratings

CVSS 4.0 uses the same qualitative severity bands as 3.1, so a numeric score maps to the familiar None-to-Critical scale.

SeverityScore range
None0.0
Low0.1 – 3.9
Medium4.0 – 6.9
High7.0 – 8.9
Critical9.0 – 10.0

CVSS 4.0 questions, answered

What is new in CVSS 4.0?

CVSS 4.0 splits impact into the Vulnerable System and Subsequent Systems (replacing the old Scope metric), adds an Attack Requirements metric, renames Exploit Code Maturity to Exploit Maturity, and folds in supplemental and environmental context. It is scored with a MacroVector method rather than the single formula used in 3.1.

How is a CVSS 4.0 score calculated?

The metrics are grouped into equivalence classes (EQs) that form a MacroVector, which maps to a base score. The final score interpolates between that MacroVector and the next lower one according to how severe the specific vector is within its class. This calculator implements that official algorithm exactly.

Is a 3.1 vector the same as a 4.0 vector?

No. The metric sets and scoring methods differ, so a CVSS 3.1 vector and a CVSS 4.0 vector are not interchangeable and will generally produce different scores. Use the version that matches the record you are working from.

Do the threat and environmental metrics change the score?

Yes. Threat (Exploit Maturity) and environmental metrics adjust the base score to reflect how the threat is evolving and how important confidentiality, integrity, or availability are in your environment. Leaving them as Not Defined uses the worst-case assumption.

How accurate is this calculator?

It is a direct port of the official FIRST CVSS v4.0 reference implementation — the lookup tables and algorithm are reproduced verbatim, and the output was checked against the reference across thousands of vectors. Scoring runs entirely in your browser.

Found something serious?

A score tells you how bad a flaw is in theory. A penetration test tells you what an attacker could actually do with it in your environment. Compare independent, accreditation-verified UK penetration testing companies in our directory.

Browse the directory
CVSS 4.0 Calculator — Score a Vulnerability | PenTesting.Org