Free Tool

CVSS v4.0 Calculator

The Common Vulnerability Scoring System v4.0 is the industry standard for assessing vulnerability severity. Select the Base metrics below to instantly compute a score and severity rating. All calculations run client-side with no data sent to any server.

10.0
Critical

A CVSS score of 10.0 indicates a critical vulnerability. These flaws are typically remotely exploitable with no authentication required and lead to full system compromise. Patch immediately and treat as a P0 incident.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Severity Scale
None (0.0)Low (0.1)Medium (4.0)High (7.0)Critical (9.0)

Exploitability

AVAttack Vector

Network path used to exploit the vulnerability.

ACAttack Complexity

Conditions beyond attacker control that must exist.

ATAttack Requirements

Prerequisites on the target system for the attack.

PRPrivileges Required

Level of privileges the attacker must have before exploitation.

UIUser Interaction

Whether exploitation requires action from a human user.

Vulnerable System Impact

VCConfidentiality

Impact on confidentiality of data within the vulnerable component.

VIIntegrity

Impact on integrity of data within the vulnerable component.

VAAvailability

Impact on availability of the vulnerable component.

Subsequent System Impact

SCConfidentiality

Impact on confidentiality of systems beyond the vulnerable component.

SIIntegrity

Impact on integrity of systems beyond the vulnerable component.

SAAvailability

Impact on availability of systems beyond the vulnerable component.

Equivalency Class Breakdown

EQ1
0
AV+PR+UI
EQ2
0
AC+AT
EQ3
0
VC+VI+VA
EQ4
0
SC+SI+SA
EQ5
0
Exploit (base)
EQ6
0
CR+IR+AR (base)

Lookup key: 000000. Lower values indicate higher severity within each equivalency class.

What is CVSS v4.0?

The Common Vulnerability Scoring System (CVSS) v4.0 was published by FIRST in November 2023. It replaces CVSS v3.1 with a more granular Base metric set, introducing Attack Requirements (AT) and separating Vulnerable System Impact from Subsequent System Impact. Scores range from 0.0 to 10.0 and map to five severity ratings: None, Low, Medium, High, and Critical.

How to use this calculator

Select the value that best describes the vulnerability for each Base metric. The score updates instantly. Copy the CVSS vector string to include in vulnerability reports, CVE submissions, or security advisories. This calculator implements the official CVSS v4.0 lookup table scoring algorithm as defined by the FIRST CVSS SIG.

Severity Reference

RatingScore Range
CRITICAL9.0 - 10.0
HIGH7.0 - 8.9
MEDIUM4.0 - 6.9
LOW0.1 - 3.9
NONE0.0