Skip to content
Zyberum Cyber Security Firm
Menu
Free toolVulnerabilities

CVSS 3.1 Calculator

Free CVSS 3.1 calculator: pick the eight base metrics, get score, severity and vector string instantly. Paste an existing vector to decode it. Runs in your browser.

Updated This page as Markdown

In short

This calculator computes the CVSS v3.1 base score from the eight base metrics (attack vector, attack complexity, privileges required, user interaction, scope, confidentiality, integrity, availability) exactly as the FIRST specification defines it, including the rounding rule. It shows the score, the severity rating, the impact and exploitability sub-scores and the vector string, and it decodes a pasted vector.

Attack Vector (AV)

From where can the vulnerability be exploited?

Attack Complexity (AC)

Are there conditions beyond the attacker’s control that must exist?

Privileges Required (PR)

Which privileges does the attacker need before exploiting?

User Interaction (UI)

Does a user other than the attacker have to do something?

Scope (S)

Can the exploited vulnerability affect components beyond its own security authority?

Confidentiality (C)

Impact on confidentiality of the affected component.

Integrity (I)

Impact on integrity of the affected component.

Availability (A)

Impact on availability of the affected component.

How it works

The calculator implements section 7 of the CVSS v3.1 specification. Each metric value maps to a weight. The impact sub-score is derived from the three impact metrics, the exploitability sub-score from the four exploitability metrics, and the base score combines both, with a different formula when the scope is changed. The result is rounded up to one decimal with the specification’s Roundup function, which avoids the floating-point artefacts that made some early calculators disagree by 0.1.

The qualitative severity follows the FIRST rating scale: None (0.0), Low (0.1 to 3.9), Medium (4.0 to 6.9), High (7.0 to 8.9) and Critical (9.0 to 10.0).

How to read the result

The score describes the vulnerability, not your risk. Before you prioritise, ask three questions the base metrics cannot answer: Who can actually reach the affected component in your deployment? What does an attacker get in business terms? Is the vulnerability being exploited in the wild? A short risk statement next to the score answers them better than the environmental metrics most teams never fill in.

The vector string belongs in every report and ticket. It lets a second person check the reasoning, and it is what vulnerability databases and customers compare.

Limits

The tool computes the base score only. Temporal and environmental metrics are not included, and CVSS 4.0 is not supported yet. Choosing the metrics still needs judgement, in particular Privileges Required, User Interaction and Scope; the FIRST user guide has worked examples for the common cases, and our pentest reports state the reasoning for every finding.

FAQ

Frequently asked questions

Does the calculator send my data anywhere?

No. It is static JavaScript running in your browser. Your metric choices are not transmitted, stored or logged. If you have consented to analytics, we only record that the tool was used and the severity category of the result.

Why does my score differ from the NVD by 0.1?

Usually because one metric was chosen differently, most often Privileges Required or Scope. Compare the vector strings, not the numbers. The arithmetic itself follows the specification including its Roundup function, so two identical vectors always give the same score.

Does it support CVSS 4.0?

Not yet. Version 4.0 uses a different metric set and a lookup-table based calculation. We will add it once most of the advisories and scanners our customers use have switched. Until then the 3.1 base score is the number everybody compares.

Sources

Related pages

Get started

The tool gave you a result. Now what?

Discuss your result with a security engineer in 15 minutes and find out what the practical next step is.

  • Your result, interpreted for your situation
  • What to do first
  • Free and without obligation
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usTalk to an expert

Pick a time that suits you

Open in a new tab