We Value Your Privacy

We use cookies to enhance your browsing experience and analyze site traffic. All calculations happen locally in your browser - we never see or store your data. Learn more in our Privacy Policy

/
/
CalculateYogi
  1. Home
  2. Technology
  3. CVSS Score Calculator
Technology

CVSS Score Calculator

Calculate CVSS v3.1 base scores and assess vulnerability severity using standardized metrics for attack vector, complexity, impact, and more.

Exploitability Metrics

Scope

Impact Metrics

Try Example Vulnerabilities

Did this calculator solve your problem today?

Contributor

Reviewed by

Last updated: August 1, 2026
SupportI build these free tools with love, late nights, and way too much coffee. If this calculator helped you, a small donation would mean the world to me and help keep this site running. Thank you for your kindness!

Related Calculators

You might also find these calculators useful

Risk Severity Calculator

Calculate risk severity scores using ISO 27001 and NIST frameworks

Data Breach Cost Calculator

Estimate the financial impact of a data breach

Vendor Risk Calculator

Assess third-party vendor security and compliance risk

Dependency Risk Calculator

Assess software dependency security risks and vulnerabilities

Calculate CVSS v3.1 Vulnerability Scores

The Common Vulnerability Scoring System (CVSS) is the industry standard for assessing computer system security vulnerabilities. Our calculator implements the official CVSS v3.1 specification from FIRST.org to help security professionals accurately score vulnerabilities.

What Is a CVSS Score?

The Common Vulnerability Scoring System (CVSS) is an open industry standard for rating the severity of software security vulnerabilities on a scale from 0.0 to 10.0. The Base score is derived from metrics describing how a vulnerability can be exploited (attack vector, attack complexity, privileges required, user interaction, and scope) and its impact on confidentiality, integrity, and availability. These combine through a defined formula into a numeric score that maps to qualitative ratings: None (0.0), Low (0.1–3.9), Medium (4.0–6.9), High (7.0–8.9), and Critical (9.0–10.0). Optional Temporal and Environmental metrics can adjust the Base score for exploit maturity and an organization's specific context, helping teams prioritize which vulnerabilities to patch first.

How to Calculate a CVSS Score

1

2

3

4

5

6

Common Use Cases

Vulnerability Triage

A security analyst scores a newly discovered flaw to decide how urgently it must be patched relative to other open issues.

Vendor Advisory Review

An IT team recomputes the CVSS score for a reported CVE using their own environmental factors to gauge real exposure.

Compliance Reporting

An auditor documents severity ratings for each finding to meet regulatory or client security requirements.

Bug Bounty Grading

A researcher justifies the severity of a submitted vulnerability to support the payout tier in a disclosure report.

Why Use CVSS Scoring?

Industry Standard

CVSS is used by the National Vulnerability Database (NVD), CVE, and security vendors worldwide for consistent vulnerability assessment.

Prioritize Remediation

CVSS scores help security teams prioritize which vulnerabilities to fix first based on severity and potential impact.

Vendor-Neutral

CVSS provides an open, standardized framework that works across all platforms and vendors.

Communicate Risk

Clear severity ratings (Critical, High, Medium, Low) make it easy to communicate risk to stakeholders.

Frequently Asked Questions

CVSS (Common Vulnerability Scoring System) is a standardized method for rating the severity of security vulnerabilities. Scores range from 0.0 to 10.0, with higher scores indicating more severe vulnerabilities.

None (0.0): No impact. Low (0.1-3.9): Minor vulnerability. Medium (4.0-6.9): Moderate risk. High (7.0-8.9): Serious vulnerability requiring prompt attention. Critical (9.0-10.0): Extremely severe, requiring immediate action.

CVSS v3.1 is a minor update that clarifies scoring guidance and addresses common misconceptions. The formula is the same, but the specification provides better examples and clearer definitions.

Scope indicates whether a vulnerability impacts resources beyond its security scope. 'Changed' scope means the vulnerability can affect other components (e.g., a VM escape affecting the host). 'Unchanged' means impact stays within the vulnerable component.

The vector string (e.g., CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) encodes all metric values. AV=Attack Vector, AC=Attack Complexity, PR=Privileges Required, UI=User Interaction, S=Scope, C/I/A=Confidentiality/Integrity/Availability Impact.

CVSS provides consistency and comparability. Using a standard system means everyone—vendors, researchers, and security teams—can communicate about vulnerability severity in a common language.

CalculateYogi

The most comprehensive calculator web app. Free, fast, and accurate calculators for everyone.

Calculator Categories

  • Math
  • Finance
  • Health
  • Conversion
  • Date & Time
  • Statistics
  • Science
  • Engineering
  • Business
  • Everyday
  • Construction
  • Education
  • Technology
  • Food & Cooking
  • Sports
  • Climate & Environment
  • Agriculture & Ecology
  • Social Media
  • Other

Company

  • About
  • Contact
  • Contributors

Legal

  • Privacy Policy
  • Terms of Service
  • Editorial Policy

© 2026 CalculateYogi. All rights reserved.

Sitemap

Made with by the AppsYogi team