CVSS Triage
CVSS v4 Triage Workspace
Parse CVSS v4 vectors, add analyst context, and generate stakeholder-ready outputs without pretending to compute official CVSS scores.
Severity vs Risk
CVSS describes inherent technical severity. It does not know your asset value, internet exposure, exploit activity, or operational consequences.
- Use CVSS to understand the vulnerability, not to replace analyst judgment.
- Use exposure, exploit status, and business impact to set priority.
- Treat the score as source-provided input unless your scorer is standards-verified.
CVSS Input
Paste a CVSS v4 vector or build one with the metric controls below.
This phase supports factual parsing for CVSS v4 base metrics and the documented exploit maturity metric.
Base Metric Builder
Use the selectors to build a valid base vector without relying on memory.
Context
Priority guidance is derived from this operational context, not from CVSS alone.
Outputs
Generate analyst-facing outputs after validating the vector and reviewing context.
Parse a valid vector, fill the context fields, and generate outputs to populate this workspace.