CVSS 3.1 / 4.0 Calculator Pick the base metrics that describe a vulnerability to get an instant base score, severity rating, and copy-ready vector string for both CVSS 3.1 and 4.0.
Finding Description Metrics Score Templates & Export Platform
Web API Mobile Desktop (Windows) Desktop (macOS) Desktop (Linux) LLM / AI Application
Vulnerability type Any / Custom Broken Access Control / Privilege Escalation Broken Authentication / Session Management Cross-Site Request Forgery (CSRF) Insecure Direct Object Reference (IDOR) Race Condition (TOCTOU) Open Redirect Parameter Tampering Path Traversal / Local File Inclusion Security Misconfiguration Sensitive Data Exposure / Cryptographic Failures Using Components with Known Vulnerabilities Cross-Site Scripting (XSS) Insecure Deserialization OS Command Injection Server-Side Request Forgery (SSRF) SQL Injection XML External Entity (XXE) Injection
Scenario template Custom
Vulnerability Description & Impact▾ Description (editable) Copy
Auto-filled starting draft. Edit to fit your specific finding before using.
Impact (editable) Copy
Auto-filled starting draft. Edit to fit your specific finding before using.
Attack Vector (AV)
Network Adjacent Local Physical
Attack Complexity (AC)
Low High
Privileges Required (PR)
None Low High
User Interaction (UI)
None Required
Scope (S)
Unchanged Changed
Confidentiality (C)
None Low High
Availability (A)
None Low High
0.0 None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:NCopy Vector
Additional Info ▾ Rationale / notes (optional)
OWASP Category
Web edition: 2021 2025
None ▾
References
+ Add Reference Combined Copy Format
Unselect all Reset positions
Additional Settings ▸
No bullets Bullet points Numbered Custom
Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
Copy All