Interactive tool · TRIS v2

Twelve layers in,
one score out

Set the context for any vulnerability: severity, exploitation evidence, exposure, blast radius, financial impact. TRIS v2 recomputes on every input, next to what CVSS alone would have told you.

01 · Score it yourself

A CVSS 9.8 on a dev laptop is not your worst problem.

Every control below is one of the twelve TRIS v2 layers: three foundational signals (CVSS, EPSS, CISA KEV), four contextual (threat actor targeting, asset criticality, public exposure, BASzy validation), and five novel v2 layers (attack path, supply chain, defense efficacy, trajectory, expected financial impact). Move any one and both scores recompute. The presets load four shapes that show up in real environments.

Vulnerability inputs
Foundational · Layers 1-3
CVSS Base Score 7.5
NVD severity. 0 none, 10 maximum theoretical impact.
EPSS Probability 0.65
FIRST.org exploitation prediction. Probability of exploitation in the next 30 days.
CISA KEV Status
Confirmed active exploitation in the wild.
Contextual · Layers 4-7
Threat Actor Targeting
Is a known APT group actively using this CVE against your sector?
Asset Criticality
Public Exposure
BASzy Validation
Does the attack actually work against your environment right now?
Novel v2 Layers · 8-12
Attack Path Blast Radius 47
Number of downstream assets reachable through lateral movement.
Supply Chain Depth
How deep does the vulnerable component sit in your SBOM?
Defense Efficacy (ATT&CK coverage) 31%
Percentage of exploitation-chain techniques your controls cover.
Threat Trajectory
Is exploit activity increasing, stable, or decreasing week over week?
Expected Financial Impact (USD) $1.94M
FAIR-based expected loss. Primary, secondary, and productivity combined.
Try a preset scenario
TRIS v2 score
94/100
ACT
CVSS-only
7.5
Fix Second
TRIS v2
94
Fix First
Layer contributions
L1 CVSS
75
L2 EPSS
65
L3 KEV
100
L4 Threat Actor
100
L5 Asset
100
L6 Exposure
100
L7 BASzy
100
L8 Attack Path
47
L9 Supply Chain
100
L10 Defense
69
L11 Trajectory
100
L12 Financial
70
TRIS v2 analysis

Active exploitation, APT targeting, crown jewel exposure, and accelerating trajectory make this an immediate fix. CVSS underestimates because it only sees severity.

Score your real scan data. Request a demo →

This is a simplified demonstration. Real TRIS v2 uses proprietary weights and diminishing-returns functions documented in the white paper.

02 · Action bands

Cross 90 and the fix jumps the queue.

TRIS v2 outputs a queue position, not a color. The thresholds below are the ones the calculator above applies. Band, not raw score, decides what happens next: ACT items enter the current change window, INFO items get documented and left alone.

ACT 90-100 Fix first

Active exploitation plus context that proves reach. Patch in the current change window, ahead of everything else.

ATTEND 75-89 Fix this week

Contextual signals push it above its CVSS rank. Schedule inside seven days.

TRACK 50-74 Scheduled

Moderate risk under current conditions. Normal patch cycle; watch the trajectory layer.

MONITOR 25-49 Watch

Low risk in this environment. Often a CVSS critical that existing controls already block.

INFO 0-24 Document

Effectively a non-issue here. Record the decision and move on.

Now run it on your scan data.

The calculator takes your word for the context. CVEasy reads it from your connectors and your asset inventory, then scores every finding through the same twelve layers, against 361,000+ indexed CVEs, on your hardware.

Request a Demo → Read the TRIS v2 white paper