CVSS Calculator — CVSS v3.1 Base Score & Vector
Compute CVSS v3.1 base score, severity, and vector from metric selections in your browser
How to Use This Tool
- Select Attack Vector (AV): Network, Adjacent, Local, or Physical.
- Choose Attack Complexity (AC), Privileges Required (PR), and User Interaction (UI).
- Set Scope (S) unchanged or changed — affects impact calculation path.
- Pick Confidentiality, Integrity, and Availability impact: None, Low, or High.
- Client-side engine computes exploitability and impact subscores.
- Review score, severity label, and generated CVSS:3.1 vector string.
About This Tool
CVSS base scores translate vulnerability metric combinations into comparable severity numbers security teams use for prioritization, SLA assignment, and executive reporting. When advisories publish vector strings like CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, stakeholders need to understand how attack vector, complexity, privileges, user interaction, scope, and CIA impact drive the numeric result. VSPIC CVSS calculator runs entirely client-side — select metric values, instantly receive base score rounded to one decimal, severity label from None through Critical, and complete vector string.
No server submission occurs — metrics and calculations stay in your browser session. Use alongside cve-lookup when validating published CVE scores or training analysts on metric sensitivity. Environmental and temporal scores are out of scope — this implements base score mathematics per CVSS v3.1 specification approximation used in industry tools.
Common use cases
- •Check if a VPN or proxy is detected on your connection
- •Validate SSL certificates before launch
- •Scan for email addresses in known breaches
Why use VSPIC for ?
- Full CVSS v3.1 base metric picker in one interface.
- Instant score, severity, and vector without server round trip.
- Client-side only — metrics never leave your browser.
- Severity bands: None, Low, Medium, High, Critical.
- Educational tool for security training and advisory review.
- Free unlimited calculations — no account required.
CVSS v3.1 base score purpose
Base scores capture intrinsic vulnerability characteristics assuming reasonable exploit conditions. They enable sorting among thousands of findings — patch Critical network-routable vulnerabilities before Medium local issues when resources constrain.
Our calculator implements base metric mathematics client-side for transparency. Adjust one metric and watch score move — building intuition analysts need when vendor vectors look surprising.
Exploitability metrics explained
Attack Vector (AV) scales from Physical — attacker touches device — through Local, Adjacent Network, to Network — remote exploitation. Attack Complexity (AC) Low means repeatable exploitation; High means conditions beyond attacker control. Privileges Required (PR) None means unauthenticated; Low and High require increasing existing access. User Interaction (UI) None means victimless exploitation; Required means a user must click or open something.
These four metrics combine into exploitability subscore weighted against impact. Remote unauthenticated bugs score higher than local authenticated flaws — holding other factors equal.
Scope and impact metrics
Scope Changed (S:C) applies when exploitation impacts components beyond the vulnerable component's security authority — sandbox escapes, VM guest-to-host, etc. Scope Unchanged (S:U) keeps impact within the same authority boundary. Confidentiality, Integrity, and Availability impacts rate None, Low, or High for data disclosure, modification, and service disruption respectively.
High CIA triad with Network AV and Scope Changed often reaches Critical band — nine to ten base score.
Severity label mapping
Score zero maps to None severity. Zero point one through three point nine is Low. Four through six point nine is Medium. Seven through eight point nine is High. Nine through ten is Critical. Labels align with common CVSS v3 reporting bands used in PCI and enterprise SLA frameworks.
Organizations may override labels with risk acceptance policies — calculator output is standardized starting point.
Vector string output format
Generated vectors follow CVSS:3.1/AV:X/AC:X/PR:X/UI:X/S:X/C:X/I:X/A:X canonical ordering. Copy into tickets, advisories, and scanner configuration when documenting assumed metrics for hypothetical scenarios or variant analyses.
Compare calculator vector against cve-lookup results to verify vendor scoring consistency.
Client-side privacy advantage
Vulnerability triage sometimes explores draft or embargoed scenario metrics unsuitable for server logging. Client-side calculation ensures selected metrics never transmit to our infrastructure — only your browser performs arithmetic.
Refresh clears state unless you bookmark or copy results — intentional for sensitive workflows.
Base versus environmental scores
Environmental metrics tailor scores to your asset exposure — internet-facing versus internal, security control mitigations. Temporal metrics incorporate exploit maturity and remediation level. This tool stops at base — add environmental adjustments manually in GRC platforms.
Do not compare base scores across teams applying different environmental profiles without normalization.
Training and advisory review use cases
Security champions learning CVSS use calculator during onboarding exercises — toggling UI:R drops many web XSS findings from Critical to Medium bands. Patch advisory committees reproduce vendor vectors before approving emergency change windows.
Educators demonstrate metric sensitivity without spreadsheet errors.
Relationship to CVE lookup
cve-lookup fetches published scores for real CVE IDs. cvss-calculator explores metric space interactively. Together they connect authoritative records with hands-on metric understanding.
When scores diverge, verify scope and UI selections — vendors occasionally correct vectors post-publication.
Implementation notes and limitations
Rounding to one decimal follows common display conventions. Floating edge cases at band boundaries may differ by zero point one from specific NVD rounding implementations.
Calculator does not validate metric combinations rejected by specification — all UI selections compute mathematically.
Important notes & limitations
- Base score only — not environmental or temporal metrics.
- Approximation aligned with common implementations — edge cases may differ slightly from NVD.
- Does not store calculation history unless you copy results.
- Does not link automatically to CVE records — use cve-lookup separately.
- Training and triage aid — not official CVE scoring authority.
Frequently Asked Questions
Yes. VSPIC offers this CVSS calculator at no cost with no account required. Results load in real time.
We do not permanently store your queries on our servers. Some tools run entirely in your browser; others fetch public data for the request only.
Yes. Open the page in any modern phone or tablet browser. Results work on Wi‑Fi and mobile data.
No. CVSS calculation runs entirely client-side in your browser. Metric selections stay local.
No. Only CVSS v3.1 base score from selected base metrics is calculated.
Rounding and specification edge cases can cause zero point one differences. Verify against official vector strings.
Scores 7.0 through 8.9 map to High severity in standard CVSS v3 banding.
This tool selects metrics manually to generate vectors. Use cve-lookup to fetch published vectors for known CVEs.
Impact crosses security boundaries — for example vulnerability in a sandboxed app affecting the host system.
Next step for your check
Continue with cve lookup on VSPIC.
Related Tools
Explore more free VSPIC tools for IP, DNS, security, and network diagnostics.
CVE Lookup
Fetch CVE summary, CVSS scores, CWE, and references from CIRCL API
Use Free →SSL/TLS Grade Checker
SSL grade, protocol support, cipher analysis, and expiry
Use Free →Security Headers Checker
HSTS, CSP grade A–F, per-header score, full header map
Use Free →JSON Formatter & Validator
Pretty print, minify, fix & validate JSON with tree view
Use Free →SSL Checker
Validate SSL/TLS certificates and expiration dates
Use Free →Blacklist Checker
Check if an IP is listed on spam and abuse blacklists
Use Free →
Trusted by Users Who Value Privacy
Always Free
No premium plan ever
100% Private
Files processed in browser
Instant Results
Convert in seconds
Works Everywhere
Any device, any OS