Skip to content
CVSS v3.1 Calculator

CVSS Score Calculator

Common Vulnerability Scoring System v3.1 — set each metric to compute the base score, severity rating and vector string.

Exploitability Metrics

AVAttack Vector
ACAttack Complexity
PRPrivileges Required
UIUser Interaction

Scope

SScope

Impact Metrics

CConfidentiality Impact
IIntegrity Impact
AAvailability Impact

BASE SCORE

9.8

Critical
0 None4 Medium7 High10 Critical

Sub-scores

Impact5.9
Exploitability3.9

Vector String

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity Ranges

Critical9.0 – 10.0
High7.0 – 8.9
Medium4.0 – 6.9
Low0.1 – 3.9
None0.0

AV: Attack Vector

N Network — 0.85

A Adjacent — 0.62

L Local — 0.55

P Physical — 0.20

AC: Attack Complexity

L Low — 0.77

H High — 0.44

PR: Privileges Required

N None — 0.85/0.85

L Low — 0.62/0.68

H High — 0.27/0.50

UI: User Interaction

N None — 0.85

R Required — 0.62

C/I/A: Impact

N None — 0.00

L Low — 0.22

H High — 0.56

S: Scope

U Unchanged — standard PR

C Changed — elevated PR (×1.08)

Frequently Asked Questions

What is CVSS v3.1?

The Common Vulnerability Scoring System version 3.1, an open industry standard for rating the severity of security vulnerabilities on a 0-10 scale using a defined set of exploitability and impact metrics.

What do Attack Vector and Attack Complexity mean?

Attack Vector describes how the vulnerability is reached (Network, Adjacent, Local, Physical); Attack Complexity describes whether exploitation requires special conditions beyond the attacker's control.

What does "Scope Changed" mean in CVSS?

Scope Changed indicates the vulnerability in one component can impact resources beyond its own security scope — for example, a container escape that affects the host.

Is CVSS 3.1 the latest version?

CVSS v4.0 was published in November 2023, but v3.1 (2019) remains the version most widely reported by NVD and vendor advisories today.