CVSS

Informational

Common Vulnerability Scoring System

Definition

CVSS (Common Vulnerability Scoring System) is an open standard for assessing the severity of security vulnerabilities. It assigns a score from 0.0 to 10.0 based on metrics such as the attack vector, complexity, required privileges, user interaction and the impact on confidentiality, integrity and availability. The current version is CVSS v3.1.

Impact

Objective, standardized assessment of vulnerability severityDetermining patching priorityCalculating rewards in bug bounty programsClear risk communication between technical and business teams

Examples

CVSS v3.1 severity ranges

CVSS scores are classified as: None (0.0), Low (0.1-3.9), Medium (4.0-6.9), High (7.0-8.9), Critical (9.0-10.0). For example, an SSRF that leads to RCE without authentication usually scores a CVSS of 9.8 (Critical), while an Open Redirect on its own usually gets a 3.4 (Low).

External references

Practice CVSS with real labs

Apply what you've learned in safe environments based on real bug bounty reports.

See practice labs
2,482

hunters training

62

labs from real hacks

1,630

completions

$14,790

paid out for these bugs

11 flags captured this week·Real hacks from HackerOne · YesWeHack · Bugcrowd·No commitment·Free Academy
Free · no account

The checklist I run on every new target

47 checks ordered by cost: first what can get you in trouble, then the cheap stuff, and finally the expensive stuff — which is where the big bounties are. I'll send it to your inbox right now.

Unsubscribe in one click, from any email.

BBLabs · bug bounty training

Stop reading about bugs and start hunting them

Create your free account and practice on labs based on real hacks that paid out thousands of euros. The Academy is free forever.

No card · free Academy · cancel anytime