An open standard for assessing the severity of computer security vulnerabilities, producing a 0.0–10.0 score plus a textual vector.
CVSS v3.1 / v4.0 break severity into Base, Temporal, and Environmental metrics. Critical: 9.0–10.0; High: 7.0–8.9; Medium: 4.0–6.9; Low: 0.1–3.9. The score is a starting point — environmental context always matters.
See our web application penetration testing, API security testing, network penetration testing, and cloud security audit services for how we test for and defend against this class of issue.
30-minute call with an OSCP-certified engineer. Tailored proposal in 24 hours.