The Common Vulnerability Scoring System (CVSS) is an open standard maintained by FIRST for rating the severity of software vulnerabilities on a scale from 0.0 to 10.0.

Severity bands

  • None: 0.0
  • Low: 0.1 to 3.9
  • Medium: 4.0 to 6.9
  • High: 7.0 to 8.9
  • Critical: 9.0 to 10.0

What goes into the score

The base score reflects the intrinsic properties of a flaw: attack vector (network, adjacent, local, physical), attack complexity, privileges required, whether user interaction is needed, and the impact on confidentiality, integrity and availability. The current versions are CVSS v3.1 and CVSS v4.0, released in November 2023.

A score is not the same as risk

CVSS describes how severe a flaw could be, not how likely it is to be attacked or how much it matters in your environment. Pair it with EPSS, which estimates exploitation likelihood, and check the CISA KEV catalog for confirmed in-the-wild exploitation.

How we use it

Our vulnerability coverage lists the CVSS score and vector alongside exploitation status, so the headline number never stands alone.