Definition
CVSS (Common Vulnerability Scoring System)
The standard 0–10 severity score for vulnerabilities, describing technical impact rather than exploitation likelihood.
An open framework from FIRST for communicating the characteristics and severity of software vulnerabilities as a base score from 0 to 10, with temporal and environmental adjustments (v3.1) or threat and environmental metrics (v4.0). CVSS measures how bad exploitation would be, not how likely it is; pairing it with EPSS and exploitation evidence gives a defensible priority.
Reference: FIRST CVSS v3.1 and v4.0 · Regulation (EU) 2024/2847 on EUR-Lex
Updated 2026-09-12 · Paraphrase for orientation, not legal advice.