we_are_coded.by CODE · The world, decoded
БГ
Concept

CVSS

The BasicsUpdated on 16 August 2026we are coded

CVSS gives every hole in software a number from 0 to 10 - but the ten is for the potential, not for whether anyone is attacking you right now.

Checked on16 August 2026
In short: CVSS (Common Vulnerability Scoring System) is a standard of the international organisation FIRST, in use since 2005 (current version 4.0, November 2023). It is a score from 0 to 10 for how badly a specific hole in software can end. It's given by an international group of security specialists, not the company with the problem. A ten means the worst-case scenario - getting in from outside, no password, without the victim clicking anything. But a high number on its own doesn't say whether anyone is actually using it right now.

The score comes from CVSS - the Common Vulnerability Scoring System, run by FIRST (a coalition of security incident response teams gathered from around the world). Every hole gets a specific identifier, a CVE, and a number on this scale next to it. The number isn't a guess. It's built from several questions: does the attacker need to be on your network or can they act remotely, do they need a password, does the victim have to click something, what exactly do you lose if it falls - data, control of the machine, the service going down.

In practice it looks like this. A hole comes out in a program millions of companies use for files. CVSS gives it a 9.8, because the attack runs over the network, no password, no action from the user, and gives full control of the server. Security departments around the world see that number and put it at the top of this week's patch list. Another hole in the same program gets a 4.2, because the attacker already needs access from inside - that one waits.

The system exists because before it, every vendor made up its own scale - 'critical' for one was 'medium' for another. CVSS gives a common language, so you can compare a hole in accounting software to a hole in a router and decide which to patch first. Vendors use it when they announce a problem, security teams use it to order the patch queue, and the insurance industry uses it too, to assess a client's risk.

The number tells you how scary the door is - not whether someone is standing in front of it right now, pushing.

Any real vibration

News loves to shout 'critical hole, 9.8!' and stop there, as if it were a verdict. It isn't. CVSS measures potential, not reality - it rates how easy and destructive the hole is IN THEORY, if someone decides to use it. Whether someone is actually using it right now is a completely different question, with a different answer - and that's the one that matters to you as a reader.

That's why I always look at the two numbers together: CVSS tells me how bad it could be, and KEV (the US government's list of holes with PROVEN real attacks) tells me whether it's even worth being scared right now. A ten without KEV is a warning sign on the road. A ten with KEV is a car coming straight at you.

The visual is generated code art. No third-party images.
Official primary sources
→FIRST: CVSS - the official specification (v4.0)