CVSS Calculator
Build or decode a CVSS v3.1 vector and see which metric drives the score.
Choose metrics, or paste a vector string.
How it works
CVSS v3.1 turns eight judgements about a vulnerability into one number between 0.0 and 10.0. The judgements are the interesting part; the number is a summary of them. This page works in both directions — pick the metrics and watch the vector build, or paste a vector out of an advisory and see what it decodes to and which term is driving the result.
The score is two sub-scores, not one calculation
Impact comes from the Confidentiality, Integrity and Availability metrics: how bad it is when the flaw is used. Exploitability comes from Attack Vector, Attack Complexity, Privileges Required and User Interaction: how much has to go right for an attacker to use it. Both are shown here, because a 7.5 built from total impact behind a hard precondition and a 7.5 built from partial impact reachable by anyone are different problems with the same label.
Scope changes two things at once
Scope asks whether the flaw reaches past the component it lives in — a hypervisor escape, a sandbox break, a library flaw that compromises the host. Setting it to Changed switches Impact to a different equation and raises the weight of Privileges Required, because privilege spent to escape a boundary is worth more than privilege spent inside one. It is the part of the specification most commonly implemented wrongly, and the part most likely to make two calculators disagree.
What a base score does not tell you
Nothing about your environment. A base score describes the vulnerability in the abstract: not whether the affected component is internet-facing, not whether a compensating control exists, and not whether anyone is exploiting it. Those belong to the Environmental and Temporal metric groups, which this page reads from a pasted vector and reports but does not score. For exploitation status, see Quietlytic’s vulnerability intelligence.
Example
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H is 9.8 Critical — unauthenticated, over the network,
total loss of all three. Change nothing but Scope to S:C and it reaches 10.0. Change the impacts to
C:L/I:L/A:N and add UI:R, the shape of a reflected cross-site scripting flaw, and the
same otherwise-identical vector scores 6.1 Medium.
Frequently asked questions
Why does the same vector score differently when Scope changes?
Because two things change at once. Scope Changed switches Impact to a different equation, and it also raises the weight of Privileges Required — Low goes from 0.62 to 0.68 and High from 0.27 to 0.50. Privilege is worth more to an attacker when it is being spent to reach past the component it applies to. It is the most commonly mis-implemented part of the equation.
What is the difference between the base score and the severity rating?
The rating is just a band the number falls in: 0.1-3.9 Low, 4.0-6.9 Medium, 7.0-8.9 High, 9.0-10.0 Critical. Two vulnerabilities rated Critical can sit at 9.0 and 10.0 and mean quite different things, which is why the vector matters more than the label.
Why does this not do CVSS v4.0?
v4.0 replaced the closed-form equation with a lookup table of 270 fitted values indexed by MacroVector. Those values cannot be derived — only transcribed from the published data — and this tool does not carry them. Producing a plausible v4.0 number without them would be inventing a score, so a v4.0 vector is refused and says so.
Should I use the CVSS score to decide what to patch first?
Not on its own. A base score says how bad a flaw is if you have it, not how likely you are to be hit. Exploitation status, whether the component is internet-facing, and what the asset does all move the answer, and none of them are inputs to the base equation.
Is my vector sent anywhere?
No. The whole calculation is arithmetic over eight values and it runs in your own tab. There is no network request on this page at all.
Related tools
Hash Identifier
Narrow an unlabelled hash down to the algorithms that could have produced it.
LocalATT&CK Technique Lookup
Find a MITRE ATT&CK technique by ID or name from a bundled dataset.
LocalSecurity Headers Analyzer
Review a set of pasted HTTP response headers against current guidance.
LocalUser-Agent Parser
Read a User-Agent string, with the token behind every claim and the spoofing tells named.
LocalSRI Hash Generator
Paste a script or stylesheet, get its sha256/sha384/sha512 integrity attribute.
LocalCSP Generator
Build a Content-Security-Policy header directive by directive, not by editing a string.
LocalFrom the intelligence desk
- Vulnerability Arista VeloCloud OrchestratorOn-Prem Input Validation Flaw (CVE-2026-93952)
- Vulnerability 2 CVEs: Check Point Quantum Security Gateway & Check Point Quantum Security Management (CVE-2026-85102)
- Vulnerability F5 BIG-IP APM Vulnerability (CVE-2026-94127)
- Vulnerability ACPT- Custom Post Types Plugin for WordPress Privilege Escalation (CVE-2026-32566)