Security

CVSS Calculator

Calculate CVSS v3.1 base, temporal and environmental scores from the metric vector, with the severity rating and the vector string for a ticket or advisory.

Last reviewed by the Radiatus Cloud team

Base metrics

Temporal metrics (optional)

Environmental metrics (optional)

Scores appear here.

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

A shared scale for vulnerability severity

The Common Vulnerability Scoring System exists so that a vulnerability described by one organisation means the same thing to another. Its base metrics describe intrinsic characteristics that do not change: how the vulnerability is reached, how difficult exploitation is, what privileges and user interaction are required, and what it does to confidentiality, integrity and availability. Those eight metrics produce a number from 0 to 10 and a severity band, and that number appears in the National Vulnerability Database entry for every published CVE.

The base score is not a risk score

This is the most consequential misunderstanding in vulnerability management. The base score measures severity in the abstract, assuming a worst case deployment. It knows nothing about whether the affected component is internet facing, whether the data it touches matters, or whether an exploit exists. A critical rated vulnerability in a service you do not run is not a risk, and a medium rated one on an unauthenticated internet facing endpoint may be the most urgent item on the list.

Temporal and environmental metrics close the gap

Temporal metrics adjust for exploit maturity and the availability of a fix, and they only ever lower the score. Environmental metrics let you re-weight confidentiality, integrity and availability for your own deployment and modify the base metrics to reflect compensating controls. Almost nobody uses them, which is why so many organisations patch by base score and spend their time on the wrong things. The environmental score is the one that should drive the queue.

Related tools

  • Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
  • Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
  • Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
  • Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.

Frequently Asked Questions

What is the difference between CVSS 3.1 and 4.0?

CVSS 4.0, published in 2023, adds supplemental metrics, splits the impact metrics between the vulnerable and subsequent systems, and removes the temporal score in favour of a threat metric group. Adoption is still partial, and 3.1 remains what most databases and tools report.

Should I patch by CVSS score alone?

No. The base score assumes a worst case deployment and ignores exploit availability and asset value. Combining it with exploit intelligence such as EPSS or the known exploited vulnerabilities catalogue, and with your own asset context, produces a far better queue.

What does scope changed mean?

That exploiting the vulnerability in one component affects resources beyond its security authority, such as a container escape or a hypervisor breakout. It raises the score substantially and is one of the metrics most often assessed inconsistently.

Why do vendors sometimes score the same CVE differently?

Because several metrics involve judgement, particularly attack complexity, privileges required and scope. Vendors also score against their own default configuration while the database scores a worst case. Where they differ, read both vectors rather than comparing numbers.

What are the severity bands?

0.0 is none, 0.1 to 3.9 low, 4.0 to 6.9 medium, 7.0 to 8.9 high and 9.0 to 10.0 critical. The bands are a convenience for reporting; the underlying number and the vector carry the information.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Select each metric value to build the CVSS vector and see the resulting scores.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.