CVSS v3.1 vs v4.0 — across the known-exploited record.
Of the 1,667 known-exploited records, 18 carry both a CVSS v3.1 and a v4.0 base score — the only records where the two scales can be compared directly. CVSSv4 adoption is still sparse (5% of scored records), so this set is small but real, and every divergence below links to the cited record it came from.
01
Coverage
— who carries which scale1,664
records with a CVSS
CVE.org / CISA-ADP / NVD78
carry CVSSv4.0
5% of scored · CVE.org18
carry BOTH v3.1 & v4.0
the comparison set1546
v3.1
CVE.org78
v4.0
CVE.org69
v3.0 / v2.0
legacy · CVE.orgBasis · CVSS base scores as published by the CNA (CVE.org), CISA-ADP, or the NVD feed, captured per record. Version adoption is a coverage finding, not a filter.
02
How v4.0 re-scores v3.1
— on the 18 records carrying both11
v4.0 scores LOWER
than the record's v3.15
v4.0 scores HIGHER
than the record's v3.12
unchanged
v4.0 == v3.10.64
mean |Δ|
absolute base-score gapWhere they diverge most
— |Δ| ≥ 1.5 base-score points; each links to its cited recordBasis · CVE.org CVSS metrics on each record. v3.1 and v4.0 measure different things, so a gap is expected; this is the empirical shift across this known-exploited set, not a claim that either is "right".