Direct Entry Guided Rubric

Standard CVSS v4.0 base scoring, per the FIRST.org specification. Choose values for each metric directly; best if you're already familiar with CVSS 4.0's metric set (Attack Requirements, and separate Vulnerable System / Subsequent System impact metrics). Looking for CVSS v3.1 instead? Use the CVSS 3.1 scoring tool.

Findings are kept only in your current browser session and are cleared when it ends — nothing is saved to a database or shared with anyone.

Leave as-is to auto-assign the next ID, following your own numbering pattern if you use a custom one, or type your own.
If this finding has a public CVE with a published CVSS v4.0 score, look it up to prefill the description and metrics below. NVD's coverage of v4.0 scores is still limited.
Exploitability Metrics
Vulnerable System Impact
Subsequent System Impact