CVSS v4.0 & v3.1 Vulnerability Severity Score & Vector Calculator (2026)

Compute official FIRST.org CVSS v3.1 Base/Temporal scores and CVSS v4.0 Vulnerable vs Subsequent System (VC/VI/VA & SC/SI/SA) severity vectors with bi-directional vector string parsing.

CVSS v4.0 & v3.1 Vulnerability Severity Score Calculator — Interactive Console
Runs locally in your browser • Instant output
Attack Vector (AV)
Attack Complexity (AC)
Attack Requirements (AT - v4.0)
Privileges Required (PR)
User Interaction (UI)
Scope / Subsequent System (S)
Confidentiality Impact (VC/C)
Integrity Impact (VI/I)
Availability Impact (VA/A)
CVSS v4.0 Base Score9.8
CVSS v3.1 Base Score9.8
CRITICAL SEVERITY
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Ready
Embed / Cite This Tool (Markdown & HTML)
GitHub / Reddit Markdown Badge[![CVSS v4.0 & v3.1 Vulnerability Severity Score Calculator](https://img.shields.io/badge/ZerosUniverse-Free_Tool-ff6a00)](https://www.zerosuniverse.com/tools/cvss-v4-vulnerability-score-calculator/)
Blog / Documentation HTML Citation<a href="https://www.zerosuniverse.com/tools/cvss-v4-vulnerability-score-calculator/">CVSS v4.0 & v3.1 Vulnerability Severity Score Calculator — ZerosUniverse</a>

2026 CVSS v4.0 Severity Scoring, Vector Metrics & Patch SLA Reference Table

2026 Verified Reference
Quick Answer & 2026 Technical Summary (cvss score calculator)Updated 2026 Standard

CVSS v4.0 (FIRST.org standard) replaces CVSS v3.1's ambiguous `Scope (S:U/C)` metric with explicit Vulnerable System (`VC/VI/VA`) and Subsequent System (`SC/SI/SA`) impact metrics, introduces `Attack Requirements (AT:N/P)` to replace `User Interaction` nuance, and encourages reporting combined Base + Threat (`CVSS-BT`) scores.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N → Score: 9.3 (Critical)
Critical SLA: 9.0–10.0 (Remediate within 24–72 hours if E:A exploited)
Scope Replacement: Vulnerable (VC/VI/VA) vs Subsequent (SC/SI/SA) impact
Threat Metric Impact: E:U (Unreported) can reduce High vectors by 1.5+ points
CVSS v4.0 Rating / MetricScore Range / Vector Valuesv4.0 Architectural Change vs v3.1Enterprise Remediation SLA
Critical Severity9.0 – 10.0 (e.g., AV:N/AC:L/AT:N/PR:N)Unauthenticated network RCE or auth bypassEmergency Patch: 24 – 72 Hours
High Severity7.0 – 8.9 (e.g., AV:N/AC:L/AT:P/PR:L)Privilege escalation or high-impact data leakPriority Patch: 7 – 14 Days
Medium Severity4.0 – 6.9 (e.g., AV:N/AC:L/AT:N/UI:A)Reflected XSS, CSRF, or limited info disclosureScheduled Release: 30 – 60 Days
Attack Requirements (AT)AT:N (None) vs AT:P (Present)Separates race conditions/MITM prereqs from ACAT:P lowers score when exploit depends on timing
Subsequent System CIA (SC/SI/SA)SC:H / SI:H / SA:H (Downstream Impact)Replaces binary Scope:Changed (S:C) from v3.1Models lateral movement to hypervisor or DB
Exploit Maturity (Threat E)E:A (Attacked) | E:P (PoC) | E:U (Unreported)Produces official CVSS-BT nomenclature scorePrioritize E:A (CISA KEV) over theoretical E:U
In-Depth ZerosUniverse Tutorial

CEH Module 05: Vulnerability Analysis & CVSS Scoring Guide

Read our complete step-by-step editorial guide, architecture breakdown, and defensive best practices on ZerosUniverse.

Read Full Guide

How to Use CVSS v4.0 & v3.1 Vulnerability Severity Score Calculator

01

Choose CVSS v4.0 or CVSS v3.1 Mode (or Paste a Vector)

Select your scoring standard or paste an existing vector string (e.g., CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N).

02

Configure Exploitability Metrics

Set Attack Vector (AV), Attack Complexity (AC), Attack Requirements (AT in v4.0), Privileges Required (PR), and User Interaction (UI).

03

Set Impact Metrics for Target & Downstream Systems

Select High, Low, or None for Confidentiality, Integrity, and Availability across the Vulnerable System and (in v4.0) Subsequent Systems.

04

Copy the Calculated Score, Severity Rating & Vector

Export the numeric score (0.0–10.0), qualitative rating (None, Low, Medium, High, Critical), and Markdown snippet for your advisory.

Key Capabilities & Technical Architecture

Dual CVSS v4.0 & CVSS v3.1 Scoring Engines

Switch between the modern CVSS v4.0 standard (introducing Attack Requirements AT and Vulnerable/Subsequent System impact separation) and the industry-wide CVSS v3.1 formula.

Bi-Directional Vector String Parser

Paste any `CVSS:4.0/...` or `CVSS:3.1/...` vector string from NVD or a security advisory to immediately populate every metric button and explain the score breakdown.

Vulnerable vs Subsequent System Impact Modeling

Replace CVSS v3's ambiguous Scope (S:U/S:C) toggle with CVSS v4.0's explicit Confidentiality, Integrity, and Availability metrics for both the Vulnerable System (VC/VI/VA) and Subsequent Systems (SC/SI/SA).

Pentest Report Markdown & JSON Exporter

Copy standardized Markdown severity badges, NVD vector strings, and executive remediation SLA timelines (Critical <24h, High <7d, Medium <30d) for vulnerability reports.

Practical Use Cases

Bug Bounty & Penetration Testing Report Triage

Justify exact severity ratings for HackerOne, Bugcrowd, or client pentest deliverables with reproducible vector strings and sub-score explanations.

CVSS v3.1 to v4.0 Advisory Migration

Evaluate how vulnerabilities involving race conditions (AT:P) or downstream lateral impact (SC/SI/SA) shift in score between CVSS v3.1 and v4.0.

CEH Module 05 & Vulnerability Management SLA Planning

Combine Base severity metrics with Threat/Exploit Maturity indicators to prioritize patching queues.

Frequently Asked Questions (FAQs)

What are the biggest changes between CVSS v3.1 and CVSS v4.0?+

CVSS v4.0 eliminates the confusing single 'Scope (Unchanged/Changed)' toggle and replaces it with distinct Impact metrics for the Vulnerable System (VC/VI/VA) and Subsequent Systems (SC/SI/SA). It also splits Attack Complexity into Attack Complexity (AC) and Attack Requirements (AT), replaces User Interaction's binary None/Required with None/Passive/Active, and renames Temporal metrics to Threat metrics.

What does Attack Requirements (AT:P vs AT:N) measure in CVSS v4.0?+

Attack Requirements (AT) captures deployment or execution prerequisites of the vulnerable component—such as winning a race condition, bypassing ASLR on a non-deterministic heap, or requiring an active Man-in-the-Middle position—separating those preconditions from the attacker's own engineering effort (Attack Complexity).

How do Qualitative Severity Ratings map to numeric CVSS scores?+

Both CVSS v3.1 and v4.0 map numeric scores to five qualitative severity bands: None (0.0), Low (0.1 – 3.9), Medium (4.0 – 6.9), High (7.0 – 8.9), and Critical (9.0 – 10.0).

Why does FIRST recommend CVSS-BTE nomenclature instead of using Base scores alone?+

A CVSS Base score (CVSS-B) reflects intrinsic technical severity assuming worst-case exploitability, which often inflates remediation queues. Combining Base with Threat (Exploit Maturity) and Environmental metrics (CVSS-BTE) reflects whether a public PoC or active in-the-wild exploitation actually exists.

How is a Cross-Site Scripting (XSS) vulnerability scored in CVSS v4.0?+

In a typical Reflected or Stored XSS where the web server hosts the flaw but the victim's browser DOM/session is compromised, the Vulnerable System (the web server itself) often has VC:N/VI:N/VA:N, while the Subsequent System (the user's browser context) receives SC:L/SI:L/SA:N with UI:P (Passive) or UI:A (Active).