Compute a Common Vulnerability Scoring System v3.1 base score from the eight base metrics. The score, severity rating, and standard vector string update live as you select each metric — implemented with the official FIRST equations.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HThe base score reflects the intrinsic severity of a vulnerability, independent of your environment or the passage of time. It runs from 0.0 to 10.0 and maps to qualitative ratings: None, Low (0.1–3.9), Medium (4.0–6.9), High (7.0–8.9), and Critical (9.0–10.0). Exploitability metrics describe how easy the flaw is to reach and abuse, while impact metrics describe the damage to confidentiality, integrity, and availability. When Scope changes, a vulnerability in one component affects resources beyond its security authority, which raises the score. For help operationalizing vulnerability scoring across your estate, talk to our team.
The Common Vulnerability Scoring System is an open standard maintained by FIRST for rating the severity of software vulnerabilities. The base score captures the inherent characteristics of a vulnerability and is the figure most commonly cited in CVE records.
Yes. It implements the official CVSS v3.1 base metric equations, including the correct roundup behavior and the scope-changed adjustments, so the score matches the FIRST reference calculator.
The vector string is a compact, machine-readable encoding of every metric selection, for example CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Copy it into tickets, reports, or vulnerability trackers so others can reproduce the exact score.
This calculator covers the base metric group, which is the most widely used. Temporal and environmental metrics refine the base score for exploit maturity and your specific environment; contact our team if you need help applying them.