Build a CVSS 3.1 vector and get the base score, severity rating, and a visual metric breakdown instantly, with results that match the official FIRST.org reference calculator.
Choose a value for each metric. The score updates in real time.
Optional. Leave a metric “Not Defined” to exclude it. When any temporal or environmental metric is set, the score reflects that higher level.
A visual breakdown of the selected base metrics. Drag a point or tap a grey marker to explore how each metric shifts the score.
Every base metric, plus any temporal/threat or environmental metric you set, and how it is contributing to the base score.
Network
This metric reflects the context by which vulnerability exploitation is possible. The Base Score is larger the more remote (logically and physically) an attacker can be in order to exploit the vulnerable component.
Low
This metric describes the conditions beyond the attacker's control that must exist in order to exploit the vulnerability. The Base Score is greatest for the least complex attacks.
None
This metric describes the level of privileges an attacker must possess before successfully exploiting the vulnerability. The Base Score is greatest if no privileges are required.
None
This metric captures the requirement for a human user, other than the attacker, to participate in the successful compromise of the vulnerable component. The Base Score is greatest when no user interaction is required.
Unchanged
This metric captures whether a vulnerability in one vulnerable component impacts resources in components beyond its security scope. A scope change occurs when the impact of a vulnerability breaches a security/trust boundary.
High
This metric measures the impact to the confidentiality of information resources managed by a software component due to a successfully exploited vulnerability. Confidentiality refers to limiting information access and disclosure to only authorized users.
High
This metric measures the impact to integrity of a successfully exploited vulnerability. Integrity refers to the trustworthiness and veracity of information. The Base Score is greatest when the consequence to the impacted component is highest.
High
This metric measures the impact to the availability of the impacted component resulting from a successfully exploited vulnerability. While Confidentiality and Integrity impact metrics apply to data, this metric refers to the loss of availability of the impacted component itself.
How the CVSS 3.1 base score is built from its metrics.
CVSS 3.1 is the most widely published version of the Common Vulnerability Scoring System, used throughout the National Vulnerability Database and vendor advisories. Released by FIRST.org in 2019, it keeps the metrics and qualitative scale of 3.0 while clarifying definitions and refining the scoring formula.
Select a value for each base metric below to build a CVSS 3.1 vector string and compute the base score in real time. The score, severity rating, and canonical vector string update immediately, and the vector can be copied, shared, or pasted back in to reproduce a score exactly.
Common questions about CVSS 3.1 scoring.