CVSS Calculator
Load a CVE to see every CVSS vector published for it, its EPSS exploit probability, CISA KEV status and SSVC values, or paste a vector. Then set the metrics for your environment in CVSS 3.1 or 4.0 and get a patch priority that weighs exploitation and exposure along with severity.
How the calculator works
CVSS 3.0 and 3.1 scores use the equations in FIRST's specifications, including the temporal and environmental groups. CVSS 4.0 has no closed formula: it maps a vector to equivalence classes and interpolates between scored macrovectors, so this page runs FIRST's own reference code for it, unmodified. Both were checked against published CVE records and against an independent CVSS library.
- Load a CVE to pull its record from the CVE Program, which carries the CNA's vectors and CISA's Vulnrichment data (SSVC, KEV, and a CISA vector when the CNA gave none), plus EPSS from FIRST. A published score that its own vector does not produce is flagged.
- Pick a vector to load it, then change any metric. The vector string, the score and the link in your address bar update as you go, so a link reopens the same scoring.
- Set your context and the priority panel combines exploitation, EPSS, exposure, asset value and your environmental score into a patch window, listing each reason.
The priority rule
| Priority | Patch within | When |
|---|---|---|
| Act now | 48 hours | Exploited in the wild and reachable from the internet, or exploited on a crown-jewel system. |
| Next window | 7 days | Exploited anywhere else, or EPSS of 10% or more, or a score of 9.0 or more on an internet-facing system. |
| Scheduled | 30 days | A score of 7.0 or more, or EPSS of 1% or more. |
| Routine | 90 days | Everything else. Isolated or low-value systems drop one level, never below routine. |
This is pwnsy's rule of thumb, close to how CISA's BOD 22-01 treats known exploited CVEs. Your own policy and regulator deadlines come first.
CVSS calculator FAQ
What is the difference between CVSS 3.1 and CVSS 4.0?
CVSS 4.0 splits impact into the vulnerable system and subsequent systems instead of a single Scope metric, adds Attack Requirements, replaces the temporal group with one Exploit Maturity metric, and scores from a lookup of equivalence classes rather than a formula. Scores are named by the groups used: CVSS-B for base only, CVSS-BT with threat, CVSS-BTE with environment.
Why does the published score not match the vector?
Sometimes the record is wrong: a CNA typed a score that its own vector does not produce. For CVSS 4.0 the more common reason is that the vector includes Exploit Maturity while the published number is the base-only CVSS-B score. The calculator shows both and flags a gap.
Should I patch by CVSS score?
Not on its own. CVSS measures severity if exploited. EPSS estimates the chance of exploitation in the next 30 days, and the CISA KEV catalog lists CVEs already exploited. Most exploited CVEs are not critical by CVSS, so the priority on this page starts from exploitation and exposure, then uses severity.
Where does the CVE data come from?
The CVE record comes from the CVE Program's API, which includes the CNA's own CVSS vectors and CISA's Vulnrichment data: its CVSS vector where the CNA gave none, SSVC decision points and KEV status. EPSS comes from FIRST's API. Your browser fetches both directly.
CVSS 4.0 scoring by FIRST's reference calculator (BSD-2-Clause). CVE records from the CVE Program, EPSS from FIRST, KEV and SSVC from CISA Vulnrichment.