CVSS Score Calculator
Common Vulnerability Scoring System v3.1 — set each metric to compute the base score, severity rating and vector string.
Exploitability Metrics
Scope
Impact Metrics
BASE SCORE
9.8
CriticalSub-scores
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSeverity Ranges
AV: Attack Vector
N Network — 0.85
A Adjacent — 0.62
L Local — 0.55
P Physical — 0.20
AC: Attack Complexity
L Low — 0.77
H High — 0.44
PR: Privileges Required
N None — 0.85/0.85
L Low — 0.62/0.68
H High — 0.27/0.50
UI: User Interaction
N None — 0.85
R Required — 0.62
C/I/A: Impact
N None — 0.00
L Low — 0.22
H High — 0.56
S: Scope
U Unchanged — standard PR
C Changed — elevated PR (×1.08)
Related Vulnerability Research
Search 250,000+ CVEs from the NIST National Vulnerability Database. Live CVSS scores, CWE mappings and vendor references.
Security advisory schedules and patch cadence for Cisco, Fortinet, Microsoft, Palo Alto, Juniper and 20+ vendors.
Exploit methodology reference: vulnerability classes, weaponisation lifecycle, PoC-to-exploit pipeline and detection opportunities.
Layered mitigation playbooks for RCE, SQLi, SSRF, Deserialization, Auth Bypass and XXE. WAF rules and compensating controls when patches can't deploy immediately.
Patch prioritisation framework: CVSS score, CISA KEV status, exploit availability and environmental context scoring.
Frequently Asked Questions
What is CVSS v3.1?
The Common Vulnerability Scoring System version 3.1, an open industry standard for rating the severity of security vulnerabilities on a 0-10 scale using a defined set of exploitability and impact metrics.
What do Attack Vector and Attack Complexity mean?
Attack Vector describes how the vulnerability is reached (Network, Adjacent, Local, Physical); Attack Complexity describes whether exploitation requires special conditions beyond the attacker's control.
What does "Scope Changed" mean in CVSS?
Scope Changed indicates the vulnerability in one component can impact resources beyond its own security scope — for example, a container escape that affects the host.
Is CVSS 3.1 the latest version?
CVSS v4.0 was published in November 2023, but v3.1 (2019) remains the version most widely reported by NVD and vendor advisories today.