Navigation

CVSS Calculator v3.1 & v4.0

Select the base metrics to compute the CVSS base score, severity and vector string. Everything runs in your browser.

Version
Base metrics
0.0
None
Vector string
-
CVE Search
Related tools
How to use
1
Pick a version

v3.1 for most published CVEs, v4.0 for the newest standard.

2
Set the metrics

Click an option for each base metric. The score updates live.

3
Copy the vector

Share the standardized vector string or look up the CVE on mlab.

Frequently Asked Questions

An open FIRST.org standard rating vulnerability severity on a 0–10 scale. The base score reflects intrinsic exploitability and impact, independent of environment.

v4.0 (2023) splits impact into Vulnerable and Subsequent system metrics, adds Attack Requirements, replaces Scope and adds threat/supplemental metrics. v3.1 is still the most common in published CVE data.

v3.1 combines Exploitability (AV, AC, PR, UI) and Impact (C, I, A) sub-scores, adjusted by Scope, then rounds up. v4.0 uses a lookup-table model from expert scoring.

No. The v3.1 score is computed locally with the official formula.

A free tool from mlab, the intelligence platform for IOC, domain and file analysis. Rolling this out across a team? Talk to us.

Go deeper

All articles →