<?xml version="1.0" encoding="UTF-8" ?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:media="http://search.yahoo.com/mrss/">
 <channel>
  <title>Common Vulnerability Scoring System News</title>
  <link>https://www.first.org/newsroom/news/cvss</link>
  <atom:link href="https://www.first.org/newsroom/news/cvss.xml" rel="self" type="application/rss+xml" />
  <itunes:author>FIRST.Org</itunes:author>
  <itunes:owner>
    <itunes:email>media@first.org</itunes:email>
  </itunes:owner>
  <category>Business</category>
  <category>News</category>
  <category>Technology</category>
  <itunes:category text="Business"><itunes:category text="Non-Profit"/></itunes:category>
  <itunes:category text="News"><itunes:category text="Tech News"/><itunes:category text="Business News"/></itunes:category>
  <itunes:category text="Technology"/>
  <description>CVSS proposes an open and universal vulnerability scoring system to address and solve the lack of cohesion and interoperability among vendor-specific ones, resulting on the promotion of a common language to discuss vulnerability severity and impact.</description>
  <dc:publisher>FIRST.Org</dc:publisher>
  <copyright>© 1995-2026 by FIRST.org, Inc.</copyright>
  <pubDate>Wed, 12 Jun 2024 23:41:46 +0000</pubDate>
  <lastBuildDate>Mon, 02 Feb 2026 16:55:38 +0000</lastBuildDate>
  <generator>Tecnodesign (https://tecnodz.com)</generator>
  <language>en-us</language>
  <ttl>20</ttl>
  <image>
    <title>Common Vulnerability Scoring System News</title>
    <link>https://www.first.org/newsroom/news/cvss</link>
    <url>https://www.first.org/_/img/1st.png</url>
  </image>
  <itunes:image href="https://www.first.org/_/img/1st.png"/>
  <itunes:explicit>false</itunes:explicit>  <item>
    <title>FIRST has officially published the latest version of the Common Vulnerability Scoring System (CVSS v4.0)</title>
    <link>https://www.first.org/newsroom/releases/20231101</link>
    <description>&lt;p&gt;In June 2023, attendees at the 35th Annual FIRST Conference, in Montréal, Canada got a first-look preview of the new version of the Common Vulnerability Scoring System (CVSS), version 4.0.  After two month of public comment followed by two months of addressing those comments, FIRST is proud to announce the official publication of CVSS version 4.0.&lt;/p&gt;</description>
    <itunes:image href="https://www.first.org/_/img/news/20231101-cvss-v4-news.jpg"/>
    <pubDate>Wed, 01 Nov 2023 17:00:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:40933</guid>
  </item>
  <item>
    <title>Understanding CVSS v3.1 </title>
    <link>https://securityboulevard.com/2019/11/understanding-cvss-v3-1/</link>
    <description>&lt;p&gt;Article on CVSS v3.1 on Security Boulevard, a syndicated blog post from WhiteSource. The article explains the changes made in CVSS v3.1, their importance, and how this scoring should figure in when looking at security vulnerabilities.&lt;/p&gt;</description>
    <pubDate>Thu, 14 Nov 2019 00:00:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:40744</guid>
  </item>
  <item>
    <title>CVSS update addresses vulnerabilities in critical infrastructure sectors</title>
    <link>https://portswigger.net/daily-swig/cvss-update-addresses-vulnerabilities-in-critical-infrastructure-sectors</link>
    <description>&lt;p&gt;An updated version of the Common Vulnerability Scoring System (CVSS) has been introduced, complete with new functionality to make it easier for security professionals to measure threats faced by critical infrastructure sectors, among other improvements.&lt;/p&gt;</description>
    <pubDate>Thu, 18 Jul 2019 00:00:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:40730</guid>
  </item>
  <item>
    <title>FIRST publishes updated Common Vulnerability Scoring System for worldwide security teams</title>
    <link>https://www.first.org/newsroom/releases/20190712</link>
    <description>&lt;p&gt;July 12th, 2019 - The Forum of Incident Response and Security Teams (FIRST) has published an update of its internationally recognized &lt;strong&gt;Common Vulnerability Scoring System (CVSS)&lt;/strong&gt;. CVSS is a common scoring system designed to provide open and universally standard severity ratings of software vulnerabilities for the security community.  Used by organizations worldwide, version 3.1 documentation is now available on the FIRST website for members and non-members to &lt;a href="https://www.first.org/cvss/v3-1/"&gt;reference&lt;/a&gt;.&lt;/p&gt;</description>
    <pubDate>Fri, 12 Jul 2019 13:00:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:40728</guid>
  </item>
  <item>
    <title>FIRST Announces CVSS Version 3.1 </title>
    <link>http://www.techbabbler.com/2019/07/12/first-announces-cvss-version-3-1/</link>
    <description>&lt;p&gt;The Forum of Incident Response and Security Teams (FIRST) on Friday announced version 3.1 of the Common Vulnerability Scoring System (CVSS).  CVSS is a widely adopted standard for rating the severity of software vulnerabilities, and it provides a framework for communicating the characteristics and impact of security flaws.&lt;/p&gt;</description>
    <pubDate>Fri, 12 Jul 2019 00:00:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:40731</guid>
  </item>
  <item>
    <title>Scoring Cisco Security Vulnerabilities with CVSSv3</title>
    <link>https://blogs.cisco.com/security/scoring-cisco-security-vulnerabilities-with-cvssv3</link>
    <description>&lt;p&gt;&lt;em&gt;Cisco Blogs&lt;/em&gt; – Omar Santos of Cisco describes the value of using CVSSv3 to score security advisories that address security vulnerabilities in Cisco software&lt;/p&gt;</description>
    <pubDate>Thu, 19 Jan 2017 00:00:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:40594</guid>
  </item>
  <item>
    <title>CVSS-SIG successful working meeting during the 20th annual FIRST conference</title>
    <link>https://www.first.org/cvss/meeting_agenda_20080623.html </link>
    <description>&lt;p&gt;The Common Vulnerability Scoring System Special Interest Group (CVSS- SIG) had a very busy and successful working meeting during the 20th annual FIRST conference in Vancouver. We covered many of the CVSS use cases post v2 deployment - namely PCI and S-CAP - thanks for all the great participation.&lt;/p&gt;</description>
    <pubDate>Mon, 07 Jul 2008 18:43:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:40330</guid>
  </item>
  <item>
    <title>FIRST CVSS-SIG meeting,	Vancouver 2008</title>
    <link>https://www.first.org/meetings/cvss/</link>
    <description>&lt;p&gt;The Common Vulnerability Scoring System Special Interest Group (CVSS-SIG) has scheduled a working meeting during the 20th annual FIRST conference in Vancouver (June 22-27,2008). This meeting will take place on Monday, June 23rd  08:30-10:30 PST&lt;/p&gt;</description>
    <pubDate>Fri, 20 Jun 2008 20:17:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:40262</guid>
  </item>
  <item>
    <title>New Scoring System Protects Credit Card Transactions</title>
    <link>https://www.first.org/newsroom/globalsecurity/sql101.html</link>
    <description>&lt;p&gt;ScienceDaily — As this year's holiday season approaches, your credit card transactions may be a little more secure thanks to standards adopted by the payment card industry. The latest incarnation of these standards include the Common Vulnerability Scoring System (CVSS) Version 2 that was coauthored this year by researchers at the National Institute of Standards and Technology and Carnegie Mellon University in collaboration with 23 other organizations&lt;/p&gt;</description>
    <pubDate>Sun, 11 Nov 2007 13:34:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:34564</guid>
  </item>
  <item>
    <title>The Common Vulnerability Scoring System (CVSS) and Its Applicability to Federal Agency Systems</title>
    <link>https://www.first.org/cvss/v2/cvss_applicability</link>
    <description>&lt;p&gt;NIST IR 7435 is published as final.  CVSS provides an open framework for communicating the characteristics and impacts of IT vulnerabilities.  &lt;/p&gt;</description>
    <pubDate>Fri, 31 Aug 2007 16:41:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:97</guid>
  </item>
  <item>
    <title>CVSS Version 2 Scoring with Nessus and the Passive Vulnerability Scanner</title>
    <link>https://www.first.org/newsroom/globalsecurity/sql92.html</link>
    <description>&lt;p&gt;On Wednesday, August 15th, 2007, Tenable Network Security will begin converting CVSS base scores for Nessus and the Passive Vulnerability Scanner (PVS) plugins from version 1 to version 2. This blog entry discusses how some of the plugin severity...&lt;/p&gt;</description>
    <pubDate>Thu, 19 Jul 2007 15:22:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:34565</guid>
  </item>
  <item>
    <title>CVSS Version 2 Scoring with Nessus and the Passive Vulnerability Scanner</title>
    <link>http://blog.tenablesecurity.com/2007/07/cvss-version-2-.html</link>
    <description>&lt;p&gt;On Wednesday, August 15th, 2007, Tenable Network Security will begin converting CVSS base scores for Nessus and the Passive Vulnerability Scanner (PVS) plugins from version 1 to version 2. This blog entry discusses how some of the plugin severity...&lt;/p&gt;</description>
    <pubDate>Thu, 19 Jul 2007 15:22:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:92</guid>
  </item>
  <item>
    <title>A revised vulnerability rating system gains steam</title>
    <link>https://www.first.org/newsroom/globalsecurity/sql91.html</link>
    <description>&lt;p&gt;A standardized system to rank computer system vulnerabilities has been revised to help IT managers make better decisions more quickly about potential threats [SearchWinIt.com]&lt;/p&gt;</description>
    <pubDate>Mon, 09 Jul 2007 21:00:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:34566</guid>
  </item>
  <item>
    <title>A revised vulnerability rating system gains steam</title>
    <link>http://searchwinit.techtarget.com/originalContent/0,289142,sid1_gci1263306,00.html</link>
    <description>&lt;p&gt;A standardized system to rank computer system vulnerabilities has been revised to help IT managers make better decisions more quickly about potential threats [SearchWinIt.com]&lt;/p&gt;</description>
    <pubDate>Mon, 09 Jul 2007 21:00:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:91</guid>
  </item>
  <item>
    <title>New tool for testing application security</title>
    <link>https://www.first.org/newsroom/globalsecurity/sql89.html</link>
    <description>&lt;p&gt;Standards-based system to rate vulnerabilities [Computerworld]&lt;/p&gt;</description>
    <pubDate>Tue, 26 Jun 2007 17:00:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:34567</guid>
  </item>
  <item>
    <title>New tool for testing application security</title>
    <link>http://computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9025760</link>
    <description>&lt;p&gt;Standards-based system to rate vulnerabilities [Computerworld]&lt;/p&gt;</description>
    <pubDate>Tue, 26 Jun 2007 17:00:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:89</guid>
  </item>
  <item>
    <title>NIST releases FISMA security control tools</title>
    <link>https://www.first.org/newsroom/globalsecurity/sql77.html</link>
    <description>&lt;p&gt;The National Institute of Standards and Technology has released a suite of tools to help automate vulnerability management and evaluate compliance with federal IT security requirements.&lt;/p&gt;</description>
    <pubDate>Thu, 21 Jun 2007 05:24:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:34568</guid>
  </item>
  <item>
    <title>NIST releases FISMA security control tools</title>
    <link>http://www.gcn.com/online/vol1_no1/44331-1.html</link>
    <description>&lt;p&gt;The National Institute of Standards and Technology has released a suite of tools to help automate vulnerability management and evaluate compliance with federal IT security requirements.&lt;/p&gt;</description>
    <pubDate>Thu, 21 Jun 2007 05:24:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:77</guid>
  </item>
  <item>
    <title>National Vulnerability Database Version 2.0 - NVD Now Supports CVSS Version 2.0 (June 20, 2007)!!</title>
    <link>https://www.first.org/newsroom/globalsecurity/sql76.html</link>
    <description>&lt;p&gt;NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance.&lt;/p&gt;</description>
    <pubDate>Wed, 20 Jun 2007 22:00:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:34569</guid>
  </item>
  <item>
    <title>National Vulnerability Database Version 2.0 - NVD Now Supports CVSS Version 2.0 (June 20, 2007)!!</title>
    <link>http://nvd.nist.gov/cvss.cfm</link>
    <description>&lt;p&gt;NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance.&lt;/p&gt;</description>
    <pubDate>Wed, 20 Jun 2007 22:00:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:76</guid>
  </item>
  <item>
    <title>Flaw grading system graduates to next version</title>
    <link>https://www.first.org/newsroom/globalsecurity/sql75.html</link>
    <description>&lt;p&gt;The Forum of Incident Response and Security Teams (FIRST) announced on Wednesday a revised version of the Common Vulnerability Scoring System (CVSS), which modifies the ranking system's recipe for judging the severity of software flaws.&lt;/p&gt;</description>
    <pubDate>Wed, 20 Jun 2007 20:00:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:34570</guid>
  </item>
  <item>
    <title>Flaw grading system graduates to next version</title>
    <link>http://www.securityfocus.com/brief/531</link>
    <description>&lt;p&gt;The Forum of Incident Response and Security Teams (FIRST) announced on Wednesday a revised version of the Common Vulnerability Scoring System (CVSS), which modifies the ranking system's recipe for judging the severity of software flaws.&lt;/p&gt;</description>
    <pubDate>Wed, 20 Jun 2007 20:00:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:75</guid>
  </item>
  <item>
    <title>New version of Common Vulnerability Scoring System released</title>
    <link>https://www.first.org/newsroom/releases/20070620-1.html</link>
    <description>&lt;p&gt;Seville Spain – June 20, 2007: Millions of computer users worldwide will enjoy more secure virtual experiences and transactions with the advent today of CVSSv2 – the latest version of the Common Vulnerability Scoring System.&lt;/p&gt;</description>
    <pubDate>Wed, 20 Jun 2007 02:00:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:71</guid>
  </item>
  <item>
    <title>Magic Numbers or Snake Oil? The Common Vulnerability Scoring System</title>
    <link>https://www.first.org/newsroom/globalsecurity/sql66.html</link>
    <description>&lt;p&gt;Can a single number sum up the full significance of a security vulnerability? The CVSS attempts to prove that it can, but it has its weak points.&lt;/p&gt;</description>
    <pubDate>Wed, 30 May 2007 15:15:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:34571</guid>
  </item>
  <item>
    <title>Magic Numbers or Snake Oil? The Common Vulnerability Scoring System</title>
    <link>http://www.heise-security.co.uk/articles/89049</link>
    <description>&lt;p&gt;Can a single number sum up the full significance of a security vulnerability? The CVSS attempts to prove that it can, but it has its weak points.&lt;/p&gt;</description>
    <pubDate>Wed, 30 May 2007 15:15:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:66</guid>
  </item>
  <item>
    <title>CVSS Scores and Calculators</title>
    <link>https://www.first.org/cvss/scores.html</link>
    <description>&lt;p&gt;Several sites provide easy ways to get CVSS scores. The major ones are listed on the SIG website.&lt;/p&gt;</description>
    <pubDate>Fri, 01 Dec 2006 14:25:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:42</guid>
  </item>
  <item>
    <title>FIRST Urges Wide-Scale Adoption of New Common Vulnerability Scoring System (CVSS)</title>
    <link>https://www.first.org/newsroom/releases/20050919.html</link>
    <description>&lt;p&gt;The Forum of Incident Response and Security Teams (FIRST)  a not-for-profit network of computer security incident response teams representing government, law enforcement, ...&lt;/p&gt;</description>
    <pubDate>Tue, 20 Sep 2005 00:53:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:7</guid>
  </item>
  <item>
    <title>FIRST Selected to Lead Scoring Standard for Security Vulnerabilities Scoring System</title>
    <link>https://www.first.org/newsroom/releases/20050511.html</link>
    <description>&lt;p&gt;The biggest challenge facing any new standard is the universal adoption of the standard. In order to address the inconsistency of scoring metrics for vulnerabilities...&lt;/p&gt;</description>
    <pubDate>Wed, 11 May 2005 06:05:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:8</guid>
  </item>
  <item>
    <title>Call to Arms for Corporate Chiefs to Attend "Critical" Cyber Conference</title>
    <link>https://www.first.org/newsroom/releases/20050427.html</link>
    <description>&lt;p&gt;Corporate executives from around the world were today being urged to attend a special conference on risk, to be staged this June in Singapore by FIRST, the world's premier force...&lt;/p&gt;</description>
    <pubDate>Wed, 27 Apr 2005 19:18:00 +0000</pubDate>
    <guid isPermaLink="false">firstnews:9</guid>
  </item>
 </channel>
</rss>