Score CVSS 3.1 without losing input states
Declare the exact version, inspect metric inheritance and save all scores with their scoring vectors.
Start with the complete input
Paste the original CVSS:3.1 vector or select one local UTF-8 CSV with id,vector header. A single vector needs a stable ID; CSV needs unique IDs. Arbitrary metric order is accepted, but duplicate metrics, wrong versions, PR:U/MPR:U and missing base metrics refuse the whole batch. Source order and repeated vector values remain intact.
Separate source state from effective weight
Every record retains all 22 states: original token, omitted flag, explicit X, effective value, weight, inheritance source and vector offset. Optional temporal/requirement defaults use weight 1; modified metrics inherit their base values, and modified privilege weights use modified scope.
| Result | Score | Read alongside |
|---|---|---|
| Base | 9.0 | ISS, impact, exploitability |
| Temporal | 9.0 | E, RL, RC and Roundup |
| Environmental | 9.1 | MISS, modified scope/impact and two Roundup stages |
The original discrepancy was resolved
The author of Red Hat cvss issue #38 reported base 9.0 and environmental 9.1 with no environmental entries, and argued that NVD 9.0 was correct. The maintainer explained that FIRST and Decimal follow the specification and closed it as a duplicate/not-a-bug. This tool preserves 9.0 / 9.0 / 9.1; it does not force environmental to equal base.
Read the whole result and retain its source
JSON contains every record, all 22 metric states and 14 intermediate values. The scores, metrics and formula CSVs retain complete source-record keys; settings and the original bytes identify the exact run. Copy contains all scores and settings, while the interface pages 25 records at a time. Derived CSV protects formula-leading cells; original bytes and JSON preserve exact source content.
Simultaneous limits: 4 MiB input, 10,000 vectors, 512 ASCII bytes/vector, 128 UTF-8 bytes/ID, 2 million total work units; 64 MiB files plus text/copy, 8 MiB typed data, 72 MiB aggregate, 96 MiB wire, 256 MiB owned reservation and one absolute 30-second period. Limits are gates, not a claim that every isolated maximum can be reached together.
- Read the scoring vector next to each score; do not compare scores from different versions.
- Inspect explicit X separately from omitted input, especially MPR and modified scope.
- After any error or cancellation, correct the full input and rerun with the same File if needed.
- Retain all seven downloads; CVSS severity alone is not a vulnerability scan or deployment decision.
References
- Resolved original user question and maintainer correction
Historical first-person task evidence; region and usage volume remain unknown.
- FIRST CVSS 3.1 specification
Fixed scoring formulas, vectors, severity bands and Appendix A.
Tools in this category
Expand a tool to see its steps, options and supported formats, then open its workspace.
CVSS 3.1 vector scoringScore complete local CVSS 3.1 vectors, inspect every metric and inheritance source, and retain all scores, intermediate values and original bytes.
Score complete local CVSS 3.1 vectors, inspect every metric and inheritance source, and retain all scores, intermediate values and original bytes.
Steps
- Choose one source and vector or CSV mode; supply complete records and stable IDs.
- Run locally, then inspect all three scores, scoring vectors, all 22 metric states and intermediate fields.
- Copy all scores and settings, or download the complete audit and unchanged original.
Capabilities and limits
- Fixed CVSS 3.1: all eight base metrics required; up to 22 distinct metrics in any order. Explicit X and omitted optional metrics are retained separately.
- One complete UTF-8 vector or CSV with exact id,vector header; unique nonempty IDs. Source order and duplicate vector values are preserved.
- Simultaneous limits: 4 MiB input, 10,000 vectors, 512 ASCII bytes/vector, 128 UTF-8 bytes/ID, 2 million total work units; 64 MiB files plus text/copy, 8 MiB typed data, 72 MiB aggregate, 96 MiB wire, 256 MiB owned reservation and one absolute 30-second period. Limits are gates, not a claim that every isolated maximum can be reached together.
- All inputs are local. No CVE lookup, vulnerability scan, metric inference or other CVSS version. Severity does not establish exploitability in a particular deployment.
- Seven complete downloads: JSON audit, scores CSV, metric states CSV, intermediate formulas CSV, settings JSON, original bytes and full FIRST notice. Copy contains all scores and settings. Metric CSV joins to complete IDs through sourceRecord.