Definition

CVSS (Common Vulnerability Scoring System)

The standard 0–10 severity score for vulnerabilities, describing technical impact rather than exploitation likelihood.

An open framework from FIRST for communicating the characteristics and severity of software vulnerabilities as a base score from 0 to 10, with temporal and environmental adjustments (v3.1) or threat and environmental metrics (v4.0). CVSS measures how bad exploitation would be, not how likely it is; pairing it with EPSS and exploitation evidence gives a defensible priority.

Reference: FIRST CVSS v3.1 and v4.0 · Regulation (EU) 2024/2847 on EUR-Lex

Updated 2026-09-12 · Paraphrase for orientation, not legal advice.

Related terms

See the term as a workflow.

Vellaci turns each of these definitions into a record with an owner, a timestamp and evidence.