Security Analysis

CVSS 3.1 Calculator

Score a vulnerability with the CVSS v3.1 base metrics. CVSS is the shared language security teams use to argue about priority with evidence rather than opinion -- this calculator shows the score, the severity band and the vector string you can paste into a ticket or advisory.

How remote can the attacker be?

Are special conditions required?

What access must the attacker already hold?

Must a victim do something?

Can impact cross a security boundary?

Data disclosure impact.

Data modification impact.

Service disruption impact.

Base score

9.8Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

The whole calculation runs in your browser using the published CVSS v3.1 formula. Nothing about the vulnerability you are scoring is transmitted or stored.

Reading the score honestly

  • The base score describes intrinsic severity only -- it deliberately ignores your environment.
  • A 9.8 on an internal test box can matter less than a 6.5 on an internet-facing payment service. Use temporal and environmental context when you prioritise.
  • Scope: Changed means the flaw breaks out of its own security boundary, for example a container escape. It raises the score sharply.
  • Always publish the vector string, not just the number, so others can check your reasoning.