CVSS 3.1 vector scoring
Score complete local CVSS 3.1 vectors, inspect every metric and inheritance source, and retain all scores, intermediate values and original bytes.
Complete CVSS 3.1 input
Joint limits: 4 MiB input; 10,000 vectors; 22 metrics; 512 ASCII bytes/vector; 128 UTF-8 bytes/ID; 2 million work units.
CVSS 3.1 results
CVSS v3.1 is a standard of FIRST.ORG, Inc. Scores are shown with their scoring vectors.
Ready to run
Before you start
Score complete local CVSS 3.1 vectors, inspect every metric and inheritance source, and retain all scores, intermediate values and original bytes.
How to use this tool
- Choose one source and vector or CSV mode; supply complete records and stable IDs.
- Run locally, then inspect all three scores, scoring vectors, all 22 metric states and intermediate fields.
- Copy all scores and settings, or download the complete audit and unchanged original.
Supported inputs and limits
Fixed CVSS 3.1: all eight base metrics required; up to 22 distinct metrics in any order. Explicit X and omitted optional metrics are retained separately.
One complete UTF-8 vector or CSV with exact id,vector header; unique nonempty IDs. Source order and duplicate vector values are preserved.
Simultaneous limits: 4 MiB input, 10,000 vectors, 512 ASCII bytes/vector, 128 UTF-8 bytes/ID, 2 million total work units; 64 MiB files plus text/copy, 8 MiB typed data, 72 MiB aggregate, 96 MiB wire, 256 MiB owned reservation and one absolute 30-second period. Limits are gates, not a claim that every isolated maximum can be reached together.
All inputs are local. No CVE lookup, vulnerability scan, metric inference or other CVSS version. Severity does not establish exploitability in a particular deployment.
Seven complete downloads: JSON audit, scores CSV, metric states CSV, intermediate formulas CSV, settings JSON, original bytes and full FIRST notice. Copy contains all scores and settings. Metric CSV joins to complete IDs through sourceRecord.
Worked example
Example input
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Example options
CVSS 3.1; single ID original38
Example output
Base 9.0; temporal 9.0; environmental 9.1; 22 metric states.
When something does not work
Correct the complete input or choices and run again. The same File can be reused after cancellation; every run creates a fresh worker.
Frequently asked questions
Why can 9.0 base produce 9.1 environmental without overrides?
Environmental scoring uses a distinct modified-impact formula. With scope changed, an environmental score of 9.1 may accompany a base score of 9.0 even without overrides.
Is an omitted optional value the same source state as explicit X?
They can have the same effective weight, but the audit retains their distinct source states. Modified metrics inherit from the base metric when omitted or X; MPR weight uses effective modified scope.
Documentation & further reading
Related tools
JSON formatting workspace
Format or minify strict JSON, sort object keys, and encode or decode strings while preserving raw number tokens.
Regex tester
Try a pattern and see what it matches in your text.
Compare text
See what changed, side by side.
HTML formatter
Format HTML indentation so its structure is easier to read.