Free tool

CVSS 3.1 & 4.0 calculator that writes the finding

Score a vulnerability in CVSS 3.1 or 4.0, add a business-risk rating, and copy report-ready severity text with a written justification. No signup. From the team behind the Cairn pentest reporting platform.

Attack VectorAV
Attack ComplexityAC
Privileges RequiredPR
User InteractionUI
ScopeS
ConfidentialityC
IntegrityI
AvailabilityA
CVSS 3.1 base score9.8Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Report-ready

Paste this straight into the finding.

Severity: Critical (CVSS 3.1 base 9.8)
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Justification: The flaw is reachable over the network with no privileges and no user interaction, fully compromising confidentiality, integrity and availability.
Scoring one finding by hand is fine. Scoring a hundred isn’t.
Cairn’s Report module has this built in — CVSS 3.1 and 4.0, base, temporal and environmental, a Likelihood/Impact risk model, and severity that rolls up across the whole report. Score once; it writes and updates every finding.
See Report

Which version should I use?

CVSS 3.1 is still the most widely required version and what most clients and compliance frameworks expect today. CVSS 4.0 is the current standard, with a finer model that separates the impact on the vulnerable system from downstream (“subsequent”) systems and adds an attack-requirements metric. If your client hasn’t specified, quote 3.1 and keep 4.0 alongside — this tool gives you both from the same finding.

FAQ
What is CVSS?

The Common Vulnerability Scoring System is the industry standard for rating the severity of a security vulnerability from 0.0 to 10.0. This tool computes the base score for both CVSS 3.1 and CVSS 4.0 from their base metrics.

What is the difference between CVSS 3.1 and 4.0?

CVSS 4.0 is the current standard. It refines the model: it separates the impact on the vulnerable system (VC/VI/VA) from downstream subsequent systems (SC/SI/SA), adds an Attack Requirements metric, and expands User Interaction. CVSS 3.1 is still the most widely required version and what most compliance frameworks expect today, so this tool gives you both.

Can I add a business risk rating?

Yes. CVSS is technical severity; most reports also carry a business risk from a Likelihood x Impact matrix. Toggle it on, pick a cell, and the report block includes both the CVSS score and the risk rating.

What do the severity ratings mean?

Both versions map the numeric score to a rating: None (0.0), Low (0.1–3.9), Medium (4.0–6.9), High (7.0–8.9) and Critical (9.0–10.0).

Does this calculate temporal and environmental scores?

This free tool covers the base score plus an optional business-risk rating, which is what most reports quote. Cairn’s Report module has the full calculator built in — 3.1 and 4.0, base, temporal and environmental — and auto-scores findings across an entire report.

← Back to the platform