Build a CVSS 4.0 vector and get the base score, severity rating, and a visual metric breakdown instantly, with results that match the official FIRST.org reference calculator.
Choose a value for each metric. The score updates in real time.
Optional. Leave a metric “Not Defined” to exclude it. When any temporal or environmental metric is set, the score reflects that higher level.
A visual breakdown of the selected base metrics. Drag a point or tap a grey marker to explore how each metric shifts the score.
Every base metric, plus any temporal/threat or environmental metric you set, and how it is contributing to the base score.
Network
This metric reflects the context by which vulnerability exploitation is possible. The more remote (logically and physically) an attacker can be, the greater the severity.
Low
This metric captures measurable actions that must be taken by the attacker to actively evade or circumvent existing built-in security-enhancing conditions in order to obtain a working exploit.
None
This metric captures the prerequisite deployment and execution conditions or variables of the vulnerable system that enable the attack. These differ from security-enhancing techniques as their primary purpose is not to explicitly mitigate attacks.
None
This metric describes the level of privileges an attacker must possess prior to successfully exploiting the vulnerability. The method by which the attacker obtains privileged credentials prior to the attack is outside the scope of this metric.
None
This metric captures the requirement for a human user, other than the attacker, to participate in the successful compromise of the vulnerable system. This metric determines whether the vulnerability can be exploited solely at the will of the attacker, or whether a separate user must participate in some manner.
High
This metric measures the impact to the confidentiality of information managed by the vulnerable system. Confidentiality refers to limiting information access and disclosure to only authorized users.
High
This metric measures the impact to the integrity of the vulnerable system. Integrity refers to the trustworthiness and veracity of information.
High
This metric measures the impact to the availability of the vulnerable system. Availability refers to the accessibility of information resources.
None
This metric measures the impact to the confidentiality of information managed by systems beyond the vulnerable system. This captures impacts that occur outside the vulnerable system's security scope.
None
This metric measures the impact to the integrity of systems beyond the vulnerable system. This captures impacts that breach the vulnerable system's security boundary.
None
This metric measures the impact to the availability of systems beyond the vulnerable system. This captures availability impacts that extend beyond the vulnerable component itself.
How the CVSS 4.0 base score is built from its metrics.
CVSS 4.0 is the latest version of the Common Vulnerability Scoring System, released by FIRST.org in 2023. It refines the model from 3.1 with separate impact metrics for the vulnerable system (VC, VI, VA) and any subsequent system (SC, SI, SA), an Attack Requirements (AT) metric, and an expanded User Interaction metric (None, Passive, Active).
Select a value for each base metric below to build a CVSS 4.0 vector string and compute the base score in real time. The score, severity rating, and canonical vector string update immediately, and the vector can be copied, shared, or pasted back in to reproduce a score exactly.
Common questions about CVSS 4.0 scoring.