Tools / CVSS Calculator
CVSS Calculator
CVSS v3.1 base score calculator. Select each metric to compute the score, severity rating, and vector string — entirely in your browser.
0.0
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
// About this tool
CVSS v3.1 Calculator
This calculator computes the CVSS v3.1 base score for a vulnerability from its base metrics: attack vector, attack complexity, privileges required, user interaction, and the confidentiality, integrity, and availability impact values.
You get the numeric score, the severity rating, and the full vector string (for example, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) that you can paste into an advisory, a ticket, or a CVE entry.
Everything is calculated locally in your browser — nothing is uploaded, and the calculator works fully offline. The math follows the FIRST CVSS v3.1 specification.
How this differs from the FIRST and NVD calculators: those are the reference implementations, and for a score you put in an advisory, use them. This one exists for the moment-to-moment work around the score — triaging a queue of findings, checking what a vector string you found in someone else's advisory actually encodes, and comparing severity consistently across a program instead of a single CVE. It runs client-side, so it works on an air-gapped machine, on a pentest laptop without network, and with vulnerability details you wouldn't paste into a third-party site.
A note on how scoring gets misused: a base score is a property of the vulnerability, not of your environment. A 9.8 in a vacuum tells you nothing about your exposure — the same critical CVE matters differently on an internet-facing edge service and on an unreachable internal host. Pair the score with exposure context (that is the core argument of continuous threat exposure management), and let the vector string, not the number, carry the detail.
CVSS — the Common Vulnerability Scoring System, maintained by FIRST — is one lens among several. Where it fits alongside its neighbours: a CWE (Common Weakness Enumeration) ID classifies what kind of flaw a finding is, the CVSS base score grades how severe it would be in isolation, and SSVC (Stakeholder-Specific Vulnerability Categorization) decides whether your organization should act on it now. There is no such thing as a 'CWE calculator' or an 'SSVC calculator' — CWE is a lookup, and SSVC needs your exposure and mission context — but this calculator gives you the scoring half of that pipeline, and the vector string feeds directly into a triage decision.
// When to use it
Score a finding for a vulnerability report
Select the base metrics for a vulnerability and get the score, severity, and vector string for your advisory or disclosure.
Triage findings consistently
Use the same calculator for every finding so severity ratings stay consistent across your team or program.
Understand an existing CVSS vector
Work backwards from a vector string you found in an advisory and see which metric values produced the score.
// Questions
Which CVSS version does this use?
CVSS v3.1, following the FIRST.org specification. The calculator covers the base metrics that produce the score and vector string.
Does it calculate temporal or environmental scores?
Not yet. The current tool computes the base score only. Temporal and environmental modifiers are on the roadmap.
Is my data uploaded?
No. All scoring math runs locally in your browser — nothing is sent to a server.
Why does the score differ from another calculator?
Scores differ when metric values are entered differently — for example, whether scope is changed, or how privileges required is interpreted. The vector string is the exact record of the values used.
How does CVSS relate to CWE?
They classify different things. A CWE ID (Common Weakness Enumeration) names the kind of flaw — SQL injection is CWE-89, an out-of-bounds write is CWE-787 — while the CVSS base score grades how severe that flaw would be in isolation. A CWE entry is a lookup in a classification catalogue, not something you compute, so a 'CWE calculator' isn't a thing: you look up the weakness, then score it. NVD pairs every CVE with both — a CWE ID for the weakness type and a CVSS base score for severity — and a finding's CWE can nudge the CVSS metrics (a weakness with no user interaction pushes attack complexity and UI values one way). This calculator is the scoring half of that pairing.
What is SSVC vs CVSS?
CVSS grades the vulnerability; SSVC (Stakeholder-Specific Vulnerability Categorization, also from Carnegie Mellon SEI) grades the decision. SSVC asks whether your organization should act now: is the vulnerability automated-exploitable, is the affected system in your production or decision-making chain, how exposed is it — and outputs Act / Attend / Track. So a CVE with a 9.8 CVSS score can legitimately land in 'Attend' if it's not exploitable in your environment, while a 7.5 that's exploited in the wild and sits on your edge gets 'Act'. SSVC isn't a calculator you feed a vector into — it needs your exposure and mission context — but the CVSS vector string you compute here is exactly the technical input its decision tree starts from.
What is a CVE score?
A 'CVE score' usually means the CVSS base score attached to a CVE entry (CVE IDs are the identifiers for publicly known vulnerabilities; the score grades their severity). NVD assigns a CVSS v3.1 base score to most CVEs — 9.8 for a textbook network-exploitable critical — and publishes the vector string next to it, so you can see exactly which metric values produced the number. Scores can differ between the vendor's advisory and NVD because they're scored by different analysts; the vector string tells you which one you're looking at. Enter that vector here to re-derive the score and severity rating.
What CVSS score is considered critical?
Under the v3.1 qualitative severity rating scale: 0.1–3.9 is Low, 4.0–6.9 is Medium, 7.0–8.9 is High, and 9.0–10.0 is Critical. The rating band matters less than the vector behind it — two 8.8s with different vectors are different problems.
What is a CVSS vector string?
The compact record of every metric value you selected, for example CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. It reads as: attack vector Network, attack complexity Low, privileges required None, user interaction None, scope Unchanged, and High impact on confidentiality, integrity, and availability. Anyone can re-derive your score from it, which is why advisories publish the vector alongside the number.
Should I use the FIRST calculator or this one?
Both compute the same v3.1 math. Use the FIRST reference calculator when you need the authoritative score for a published advisory or CVE entry. Use this one for private triage work — client-side means nothing about your finding, your queue, or an undisclosed vulnerability leaves your machine, and it keeps working offline.
// Related tools