CVSS 3.1 Calculator
Score a vulnerability with the CVSS v3.1 base metrics. CVSS is the shared language security teams use to argue about priority with evidence rather than opinion -- this calculator shows the score, the severity band and the vector string you can paste into a ticket or advisory.
How remote can the attacker be?
Are special conditions required?
What access must the attacker already hold?
Must a victim do something?
Can impact cross a security boundary?
Data disclosure impact.
Data modification impact.
Service disruption impact.
Base score
9.8Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The whole calculation runs in your browser using the published CVSS v3.1 formula. Nothing about the vulnerability you are scoring is transmitted or stored.
Reading the score honestly
- The base score describes intrinsic severity only -- it deliberately ignores your environment.
- A 9.8 on an internal test box can matter less than a 6.5 on an internet-facing payment service. Use temporal and environmental context when you prioritise.
- Scope: Changed means the flaw breaks out of its own security boundary, for example a container escape. It raises the score sharply.
- Always publish the vector string, not just the number, so others can check your reasoning.
Related tools
Regex Tester
Test regular expressions against sample text with live match highlighting.
TOTP 2FA Code Generator
Turn a Base32 secret into live six-digit authenticator codes to test MFA enrolment.
Password Policy Tester
Configure a password policy and test candidate passwords against every rule locally.