CVSS 3.1 calculator

Score a vulnerability the way the standard intends. Choose the metrics below and get an accurate CVSS v3.1 base, temporal, and environmental score, its severity rating, and a shareable vector string. Everything runs in your browser — nothing you enter leaves this page.

Base metrics

The intrinsic, unchanging qualities of the vulnerability. These are required and produce the headline score.

Attack VectorAV
Attack ComplexityAC
Privileges RequiredPR
User InteractionUI
ScopeS
ConfidentialityC
IntegrityI
AvailabilityA

How CVSS severity ratings work

A CVSS number maps to a qualitative severity band. Most teams use these bands to decide what to fix first — Critical and High vulnerabilities are the ones that typically demand immediate attention.

SeverityScore range
None0.0
Low0.1 – 3.9
Medium4.0 – 6.9
High7.0 – 8.9
Critical9.0 – 10.0

CVSS questions, answered

What is a CVSS score?

CVSS (the Common Vulnerability Scoring System) is an open standard for rating the severity of a security vulnerability on a 0 to 10 scale. A higher number means a more serious flaw. The score is derived from a set of metrics describing how the vulnerability is exploited and what happens if it is.

What counts as a high CVSS score?

Scores of 9.0 to 10.0 are rated Critical and 7.0 to 8.9 are High — these are the ones most teams prioritise fixing first. 4.0 to 6.9 is Medium, 0.1 to 3.9 is Low, and 0.0 is None.

What is the difference between base, temporal, and environmental scores?

The base score reflects the intrinsic, unchanging traits of the vulnerability and is the number usually quoted (for example on a CVE record). The temporal score adjusts it for how the threat is evolving, such as whether working exploit code exists. The environmental score tailors it to your own systems and how important confidentiality, integrity, or availability are to you.

Is this the same as CVSS 4.0?

No. This calculator implements CVSS v3.1, which remains the most widely used version and the one behind most current CVE records. CVSS 4.0 uses a different metric set and scoring method; a 3.1 vector and a 4.0 vector are not interchangeable.

Does a high CVSS score mean I am definitely at risk?

Not on its own. CVSS measures the severity of a flaw, not your specific risk. Real risk also depends on whether the affected system is exposed, whether it holds sensitive data, and what compensating controls you have. The environmental metrics let you fold some of that context in, but a penetration test is how you find out what is actually exploitable in your environment.

Found something serious?

A score tells you how bad a flaw is in theory. A penetration test tells you what an attacker could actually do with it in your environment. Compare independent, accreditation-verified UK penetration testing companies in our directory.

Browse the directory
CVSS 3.1 Calculator — Score a Vulnerability | PenTesting.Org