Latest commit

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

VersionCVSSLicenseClient Side

VECTOR

Bug Hunter CVSS Calculator

A dark-themed, single-file CVSS v3.1 scoring engine built for bug bounty hunters and security researchers.

FeaturesQuickstartDecision TreeOWASP PresetsAudit LogTech StackSecurityLicense


Features

CVSS v3.1 Scoring Engine

Full implementation of the Common Vulnerability Scoring System v3.1 specification:

  • Base Score — Attack Vector, Attack Complexity, Privileges Required, User Interaction, Scope, Confidentiality, Integrity, Availability
  • Temporal Score — Exploit Maturity, Remediation Level, Report Confidence
  • Environmental Score — Confidentiality, Integrity, Availability Requirements (CR/IR/AR)
  • Real-time animated gauge with severity classification (NONE → LOW → MEDIUM → HIGH → CRITICAL)
  • CRITICAL scores (9.0+) trigger a pulse animation to draw attention

Vuln Decision Tree

28 vulnerability categories with 89 pre-scored scenarios across all severity levels:

CategoryKeyCategoryKey
Cross-Site Request ForgeryCSRFRemote Code ExecutionRCE
Cross-Site ScriptingXSSXML External EntityXXE
CORS MisconfigurationCORSServer-Side Template InjectionSSTI
Insecure Direct Object ReferenceIDOROpen RedirectREDIR
Business Logic FlawsBIZMalicious File UploadUPLOAD
Server-Side Request ForgerySSRFAuthentication BypassAUTHBYP
SQL InjectionSQLIRace ConditionRACE
Insecure DeserializationDESERJWT VulnerabilitiesJWT
GraphQL VulnerabilitiesGQLAPI Security FlawsAPIS
Subdomain TakeoverSUBTKClickjackingCLICKJ
HTTP Request SmugglingSMUGGLWeb Cache PoisoningCACHEP
Host Header InjectionHOSTHDRPath TraversalPATHTR
Information DisclosureINFOLEAKMissing Rate LimitingRATELIM
Mass AssignmentMASSASGNPrototype PollutionPROTOPL

Each scenario includes:

  • Real-world description
  • Pre-calculated CVSS score
  • Severity + Bounty Tier classification
  • One-click vector loading into the calculator

OWASP Quick Presets

One-click loading of OWASP Top 10 (2021) vulnerability vectors:

  • A01 — Broken Access Control
  • A02 — Cryptographic Failures
  • A03 — Injection (SQLi, XSS, Command Injection)
  • A04 — Insecure Design
  • A05 — Security Misconfiguration
  • A06 — Vulnerable Components
  • A07 — Auth & Session Failures
  • A08 — Software & Data Integrity
  • A09 — Security Logging Failures
  • A10 — Server-Side Request Forgery

Bounty Tier Mapping

Automatic classification into bug bounty payout tiers:

ScoreSeverityTierTypical Payout
9.0 – 10.0CRITICALP1$2,000 – $10,000+
7.0 – 8.9HIGHP2$500 – $2,000
4.0 – 6.9MEDIUMP3$150 – $500
0.1 – 3.9LOWP4$50 – $150
0.0NONEP5$0 – $50 (Info)

Audit Log

  • Commit calculated vectors to a local audit log
  • Copy any vector to clipboard with one click
  • Export full audit log as JSON
  • Entries stored in localStorage with UUID identifiers
  • Maximum 50 entries with duplicate detection

Vector Parser

Paste any CVSS v3.1 vector string and parse it directly into the calculator:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Quickstart

Option 1: Open directly

# Clone the repo
git clone https://github.com/YOUR_USERNAME/vector.git
# Open in browser
open index.html

Option 2: Serve locally

# Python
python -m http.server 8080
# Node.js
npx serve .# Then open http://localhost:8080

No build step. No dependencies to install. Just open index.html.


Usage

Calculate a CVSS Score

  1. Select values for all 8 base metrics (Attack Vector, Attack Complexity, etc.)
  2. Optionally set Temporal metrics (Exploit Maturity, Remediation Level, Report Confidence)
  3. The score updates in real-time on the gauge
  4. Click Commit to Audit Log to save

Use the Decision Tree

  1. Scroll to the Vuln Decision Tree section
  2. Select a vulnerability category tab (CSRF, XSS, SQLi, etc.)
  3. Click a scenario card to view details
  4. Click Load Vector into Calculator to auto-fill all metrics

Parse a Vector String

  1. Click Parse Vector String in the sidebar
  2. Paste any CVSS v3.1 vector (e.g., CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
  3. Click Parse & Load
  4. Metrics auto-fill and score calculates

Apply OWASP Presets

  1. Select an OWASP category from the dropdown
  2. Click Apply
  3. Vector loads with a description of the vulnerability class

Tech Stack

TechnologyPurpose
HTML5Semantic structure
CSS3Dark theme with CSS variables, custom properties
JavaScript (ES6+)CVSS calculation engine, DOM manipulation
GSAP 3.12.5Scroll animations, gauge animations, UI transitions
Tailwind CSSUtility-first layout helpers
Google FontsBebas Neue (display), JetBrains Mono (code), Space Grotesk (body)

All external scripts loaded with Subresource Integrity (SRI) hashes.


Project Structure

vector/
├── index.html # Complete SPA — HTML + CSS + JS in one file
├── README.md # This file
└── UPDATE.md # Full changelog

Security

Implemented Protections

ProtectionDescription
XSS PreventionescapeHtml() sanitizes all data before innerHTML injection
Safe DOM RenderingDecision Tree uses createElement + textContent instead of innerHTML
Input WhitelistingAll CVSS keys/values validated against VALID_CVSS_KEYS before processing
localStorage ValidationsanitizeLogEntry() validates type, length, and score range of all entries
SRI HashesGSAP scripts loaded with integrity + crossorigin attributes
No Inline HandlersEvent listeners attached via addEventListener, not onclick attributes
UUID Audit EntriesEach log entry gets a v4 UUID to prevent ID collisions

Threat Model

This is a client-side only tool. All calculations happen in the browser. No data is sent to any server. The audit log uses localStorage for persistence.


Accessibility

  • role="radiogroup" + aria-label on all metric option grids
  • aria-label on every radio input
  • aria-live="polite" on score gauge and live clock
  • Global focus-visible styles for keyboard navigation
  • Focus trap in the Parse Vector modal
  • High-contrast dark theme

Browser Support

BrowserStatus
Chrome 90+Full support
Firefox 90+Full support
Safari 15+Full support
Edge 90+Full support

Contributing

  1. Fork the repository
  2. Create a feature branch (git checkout -b feature/new-vuln-category)
  3. Make your changes in index.html
  4. Test in at least two browsers
  5. Submit a pull request

Adding a New Vulnerability Category

  1. Add a new entry to the DT_DATA object in the <script> section
  2. Add a <button class="dt-tab" data-vuln="YOUR_KEY">Label</button> to the #dt-tabs div
  3. Follow the existing format: label, icon, scenarios[] with id, tier, sev, score, color, name, desc, vector

License

MIT License. Use it, fork it, modify it.


VECTOR — Built for bug hunters who take scoring seriously.

About

A professional, interactive CVSS v3.1 Scoring Engine & Vulnerability Decision Tree built for Bug Bounty Hunters and Security Researchers.

Topics

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Latest commit

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

VersionCVSSLicenseClient Side

VECTOR

Bug Hunter CVSS Calculator

A dark-themed, single-file CVSS v3.1 scoring engine built for bug bounty hunters and security researchers.

FeaturesQuickstartDecision TreeOWASP PresetsAudit LogTech StackSecurityLicense


Features

CVSS v3.1 Scoring Engine

Full implementation of the Common Vulnerability Scoring System v3.1 specification:

  • Base Score — Attack Vector, Attack Complexity, Privileges Required, User Interaction, Scope, Confidentiality, Integrity, Availability
  • Temporal Score — Exploit Maturity, Remediation Level, Report Confidence
  • Environmental Score — Confidentiality, Integrity, Availability Requirements (CR/IR/AR)
  • Real-time animated gauge with severity classification (NONE → LOW → MEDIUM → HIGH → CRITICAL)
  • CRITICAL scores (9.0+) trigger a pulse animation to draw attention

Vuln Decision Tree

28 vulnerability categories with 89 pre-scored scenarios across all severity levels:

CategoryKeyCategoryKey
Cross-Site Request ForgeryCSRFRemote Code ExecutionRCE
Cross-Site ScriptingXSSXML External EntityXXE
CORS MisconfigurationCORSServer-Side Template InjectionSSTI
Insecure Direct Object ReferenceIDOROpen RedirectREDIR
Business Logic FlawsBIZMalicious File UploadUPLOAD
Server-Side Request ForgerySSRFAuthentication BypassAUTHBYP
SQL InjectionSQLIRace ConditionRACE
Insecure DeserializationDESERJWT VulnerabilitiesJWT
GraphQL VulnerabilitiesGQLAPI Security FlawsAPIS
Subdomain TakeoverSUBTKClickjackingCLICKJ
HTTP Request SmugglingSMUGGLWeb Cache PoisoningCACHEP
Host Header InjectionHOSTHDRPath TraversalPATHTR
Information DisclosureINFOLEAKMissing Rate LimitingRATELIM
Mass AssignmentMASSASGNPrototype PollutionPROTOPL

Each scenario includes:

  • Real-world description
  • Pre-calculated CVSS score
  • Severity + Bounty Tier classification
  • One-click vector loading into the calculator

OWASP Quick Presets

One-click loading of OWASP Top 10 (2021) vulnerability vectors:

  • A01 — Broken Access Control
  • A02 — Cryptographic Failures
  • A03 — Injection (SQLi, XSS, Command Injection)
  • A04 — Insecure Design
  • A05 — Security Misconfiguration
  • A06 — Vulnerable Components
  • A07 — Auth & Session Failures
  • A08 — Software & Data Integrity
  • A09 — Security Logging Failures
  • A10 — Server-Side Request Forgery

Bounty Tier Mapping

Automatic classification into bug bounty payout tiers:

ScoreSeverityTierTypical Payout
9.0 – 10.0CRITICALP1$2,000 – $10,000+
7.0 – 8.9HIGHP2$500 – $2,000
4.0 – 6.9MEDIUMP3$150 – $500
0.1 – 3.9LOWP4$50 – $150
0.0NONEP5$0 – $50 (Info)

Audit Log

  • Commit calculated vectors to a local audit log
  • Copy any vector to clipboard with one click
  • Export full audit log as JSON
  • Entries stored in localStorage with UUID identifiers
  • Maximum 50 entries with duplicate detection

Vector Parser

Paste any CVSS v3.1 vector string and parse it directly into the calculator:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Quickstart

Option 1: Open directly

# Clone the repo
git clone https://github.com/YOUR_USERNAME/vector.git
# Open in browser
open index.html

Option 2: Serve locally

# Python
python -m http.server 8080
# Node.js
npx serve .# Then open http://localhost:8080

No build step. No dependencies to install. Just open index.html.


Usage

Calculate a CVSS Score

  1. Select values for all 8 base metrics (Attack Vector, Attack Complexity, etc.)
  2. Optionally set Temporal metrics (Exploit Maturity, Remediation Level, Report Confidence)
  3. The score updates in real-time on the gauge
  4. Click Commit to Audit Log to save

Use the Decision Tree

  1. Scroll to the Vuln Decision Tree section
  2. Select a vulnerability category tab (CSRF, XSS, SQLi, etc.)
  3. Click a scenario card to view details
  4. Click Load Vector into Calculator to auto-fill all metrics

Parse a Vector String

  1. Click Parse Vector String in the sidebar
  2. Paste any CVSS v3.1 vector (e.g., CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
  3. Click Parse & Load
  4. Metrics auto-fill and score calculates

Apply OWASP Presets

  1. Select an OWASP category from the dropdown
  2. Click Apply
  3. Vector loads with a description of the vulnerability class

Tech Stack

TechnologyPurpose
HTML5Semantic structure
CSS3Dark theme with CSS variables, custom properties
JavaScript (ES6+)CVSS calculation engine, DOM manipulation
GSAP 3.12.5Scroll animations, gauge animations, UI transitions
Tailwind CSSUtility-first layout helpers
Google FontsBebas Neue (display), JetBrains Mono (code), Space Grotesk (body)

All external scripts loaded with Subresource Integrity (SRI) hashes.


Project Structure

vector/
├── index.html # Complete SPA — HTML + CSS + JS in one file
├── README.md # This file
└── UPDATE.md # Full changelog

Security

Implemented Protections

ProtectionDescription
XSS PreventionescapeHtml() sanitizes all data before innerHTML injection
Safe DOM RenderingDecision Tree uses createElement + textContent instead of innerHTML
Input WhitelistingAll CVSS keys/values validated against VALID_CVSS_KEYS before processing
localStorage ValidationsanitizeLogEntry() validates type, length, and score range of all entries
SRI HashesGSAP scripts loaded with integrity + crossorigin attributes
No Inline HandlersEvent listeners attached via addEventListener, not onclick attributes
UUID Audit EntriesEach log entry gets a v4 UUID to prevent ID collisions

Threat Model

This is a client-side only tool. All calculations happen in the browser. No data is sent to any server. The audit log uses localStorage for persistence.


Accessibility

  • role="radiogroup" + aria-label on all metric option grids
  • aria-label on every radio input
  • aria-live="polite" on score gauge and live clock
  • Global focus-visible styles for keyboard navigation
  • Focus trap in the Parse Vector modal
  • High-contrast dark theme

Browser Support

BrowserStatus
Chrome 90+Full support
Firefox 90+Full support
Safari 15+Full support
Edge 90+Full support

Contributing

  1. Fork the repository
  2. Create a feature branch (git checkout -b feature/new-vuln-category)
  3. Make your changes in index.html
  4. Test in at least two browsers
  5. Submit a pull request

Adding a New Vulnerability Category

  1. Add a new entry to the DT_DATA object in the <script> section
  2. Add a <button class="dt-tab" data-vuln="YOUR_KEY">Label</button> to the #dt-tabs div
  3. Follow the existing format: label, icon, scenarios[] with id, tier, sev, score, color, name, desc, vector

License

MIT License. Use it, fork it, modify it.


VECTOR — Built for bug hunters who take scoring seriously.

About

A professional, interactive CVSS v3.1 Scoring Engine & Vulnerability Decision Tree built for Bug Bounty Hunters and Security Researchers.

Topics

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

VersionCVSSLicenseClient Side

VECTOR

Bug Hunter CVSS Calculator

A dark-themed, single-file CVSS v3.1 scoring engine built for bug bounty hunters and security researchers.

FeaturesQuickstartDecision TreeOWASP PresetsAudit LogTech StackSecurityLicense


Features

CVSS v3.1 Scoring Engine

Full implementation of the Common Vulnerability Scoring System v3.1 specification:

  • Base Score — Attack Vector, Attack Complexity, Privileges Required, User Interaction, Scope, Confidentiality, Integrity, Availability
  • Temporal Score — Exploit Maturity, Remediation Level, Report Confidence
  • Environmental Score — Confidentiality, Integrity, Availability Requirements (CR/IR/AR)
  • Real-time animated gauge with severity classification (NONE → LOW → MEDIUM → HIGH → CRITICAL)
  • CRITICAL scores (9.0+) trigger a pulse animation to draw attention

Vuln Decision Tree

28 vulnerability categories with 89 pre-scored scenarios across all severity levels:

CategoryKeyCategoryKey
Cross-Site Request ForgeryCSRFRemote Code ExecutionRCE
Cross-Site ScriptingXSSXML External EntityXXE
CORS MisconfigurationCORSServer-Side Template InjectionSSTI
Insecure Direct Object ReferenceIDOROpen RedirectREDIR
Business Logic FlawsBIZMalicious File UploadUPLOAD
Server-Side Request ForgerySSRFAuthentication BypassAUTHBYP
SQL InjectionSQLIRace ConditionRACE
Insecure DeserializationDESERJWT VulnerabilitiesJWT
GraphQL VulnerabilitiesGQLAPI Security FlawsAPIS
Subdomain TakeoverSUBTKClickjackingCLICKJ
HTTP Request SmugglingSMUGGLWeb Cache PoisoningCACHEP
Host Header InjectionHOSTHDRPath TraversalPATHTR
Information DisclosureINFOLEAKMissing Rate LimitingRATELIM
Mass AssignmentMASSASGNPrototype PollutionPROTOPL

Each scenario includes:

  • Real-world description
  • Pre-calculated CVSS score
  • Severity + Bounty Tier classification
  • One-click vector loading into the calculator

OWASP Quick Presets

One-click loading of OWASP Top 10 (2021) vulnerability vectors:

  • A01 — Broken Access Control
  • A02 — Cryptographic Failures
  • A03 — Injection (SQLi, XSS, Command Injection)
  • A04 — Insecure Design
  • A05 — Security Misconfiguration
  • A06 — Vulnerable Components
  • A07 — Auth & Session Failures
  • A08 — Software & Data Integrity
  • A09 — Security Logging Failures
  • A10 — Server-Side Request Forgery

Bounty Tier Mapping

Automatic classification into bug bounty payout tiers:

ScoreSeverityTierTypical Payout
9.0 – 10.0CRITICALP1$2,000 – $10,000+
7.0 – 8.9HIGHP2$500 – $2,000
4.0 – 6.9MEDIUMP3$150 – $500
0.1 – 3.9LOWP4$50 – $150
0.0NONEP5$0 – $50 (Info)

Audit Log

  • Commit calculated vectors to a local audit log
  • Copy any vector to clipboard with one click
  • Export full audit log as JSON
  • Entries stored in localStorage with UUID identifiers
  • Maximum 50 entries with duplicate detection

Vector Parser

Paste any CVSS v3.1 vector string and parse it directly into the calculator:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Quickstart

Option 1: Open directly

# Clone the repo
git clone https://github.com/YOUR_USERNAME/vector.git
# Open in browser
open index.html

Option 2: Serve locally

# Python
python -m http.server 8080
# Node.js
npx serve .# Then open http://localhost:8080

No build step. No dependencies to install. Just open index.html.


Usage

Calculate a CVSS Score

  1. Select values for all 8 base metrics (Attack Vector, Attack Complexity, etc.)
  2. Optionally set Temporal metrics (Exploit Maturity, Remediation Level, Report Confidence)
  3. The score updates in real-time on the gauge
  4. Click Commit to Audit Log to save

Use the Decision Tree

  1. Scroll to the Vuln Decision Tree section
  2. Select a vulnerability category tab (CSRF, XSS, SQLi, etc.)
  3. Click a scenario card to view details
  4. Click Load Vector into Calculator to auto-fill all metrics

Parse a Vector String

  1. Click Parse Vector String in the sidebar
  2. Paste any CVSS v3.1 vector (e.g., CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
  3. Click Parse & Load
  4. Metrics auto-fill and score calculates

Apply OWASP Presets

  1. Select an OWASP category from the dropdown
  2. Click Apply
  3. Vector loads with a description of the vulnerability class

Tech Stack

TechnologyPurpose
HTML5Semantic structure
CSS3Dark theme with CSS variables, custom properties
JavaScript (ES6+)CVSS calculation engine, DOM manipulation
GSAP 3.12.5Scroll animations, gauge animations, UI transitions
Tailwind CSSUtility-first layout helpers
Google FontsBebas Neue (display), JetBrains Mono (code), Space Grotesk (body)

All external scripts loaded with Subresource Integrity (SRI) hashes.


Project Structure

vector/
├── index.html # Complete SPA — HTML + CSS + JS in one file
├── README.md # This file
└── UPDATE.md # Full changelog

Security

Implemented Protections

ProtectionDescription
XSS PreventionescapeHtml() sanitizes all data before innerHTML injection
Safe DOM RenderingDecision Tree uses createElement + textContent instead of innerHTML
Input WhitelistingAll CVSS keys/values validated against VALID_CVSS_KEYS before processing
localStorage ValidationsanitizeLogEntry() validates type, length, and score range of all entries
SRI HashesGSAP scripts loaded with integrity + crossorigin attributes
No Inline HandlersEvent listeners attached via addEventListener, not onclick attributes
UUID Audit EntriesEach log entry gets a v4 UUID to prevent ID collisions

Threat Model

This is a client-side only tool. All calculations happen in the browser. No data is sent to any server. The audit log uses localStorage for persistence.


Accessibility

  • role="radiogroup" + aria-label on all metric option grids
  • aria-label on every radio input
  • aria-live="polite" on score gauge and live clock
  • Global focus-visible styles for keyboard navigation
  • Focus trap in the Parse Vector modal
  • High-contrast dark theme

Browser Support

BrowserStatus
Chrome 90+Full support
Firefox 90+Full support
Safari 15+Full support
Edge 90+Full support

Contributing

  1. Fork the repository
  2. Create a feature branch (git checkout -b feature/new-vuln-category)
  3. Make your changes in index.html
  4. Test in at least two browsers
  5. Submit a pull request

Adding a New Vulnerability Category

  1. Add a new entry to the DT_DATA object in the <script> section
  2. Add a <button class="dt-tab" data-vuln="YOUR_KEY">Label</button> to the #dt-tabs div
  3. Follow the existing format: label, icon, scenarios[] with id, tier, sev, score, color, name, desc, vector

License

MIT License. Use it, fork it, modify it.


VECTOR — Built for bug hunters who take scoring seriously.

About

A professional, interactive CVSS v3.1 Scoring Engine & Vulnerability Decision Tree built for Bug Bounty Hunters and Security Researchers.

Topics

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

VersionCVSSLicenseClient Side

VECTOR

Bug Hunter CVSS Calculator

A dark-themed, single-file CVSS v3.1 scoring engine built for bug bounty hunters and security researchers.

FeaturesQuickstartDecision TreeOWASP PresetsAudit LogTech StackSecurityLicense


Features

CVSS v3.1 Scoring Engine

Full implementation of the Common Vulnerability Scoring System v3.1 specification:

  • Base Score — Attack Vector, Attack Complexity, Privileges Required, User Interaction, Scope, Confidentiality, Integrity, Availability
  • Temporal Score — Exploit Maturity, Remediation Level, Report Confidence
  • Environmental Score — Confidentiality, Integrity, Availability Requirements (CR/IR/AR)
  • Real-time animated gauge with severity classification (NONE → LOW → MEDIUM → HIGH → CRITICAL)
  • CRITICAL scores (9.0+) trigger a pulse animation to draw attention

Vuln Decision Tree

28 vulnerability categories with 89 pre-scored scenarios across all severity levels:

CategoryKeyCategoryKey
Cross-Site Request ForgeryCSRFRemote Code ExecutionRCE
Cross-Site ScriptingXSSXML External EntityXXE
CORS MisconfigurationCORSServer-Side Template InjectionSSTI
Insecure Direct Object ReferenceIDOROpen RedirectREDIR
Business Logic FlawsBIZMalicious File UploadUPLOAD
Server-Side Request ForgerySSRFAuthentication BypassAUTHBYP
SQL InjectionSQLIRace ConditionRACE
Insecure DeserializationDESERJWT VulnerabilitiesJWT
GraphQL VulnerabilitiesGQLAPI Security FlawsAPIS
Subdomain TakeoverSUBTKClickjackingCLICKJ
HTTP Request SmugglingSMUGGLWeb Cache PoisoningCACHEP
Host Header InjectionHOSTHDRPath TraversalPATHTR
Information DisclosureINFOLEAKMissing Rate LimitingRATELIM
Mass AssignmentMASSASGNPrototype PollutionPROTOPL

Each scenario includes:

  • Real-world description
  • Pre-calculated CVSS score
  • Severity + Bounty Tier classification
  • One-click vector loading into the calculator

OWASP Quick Presets

One-click loading of OWASP Top 10 (2021) vulnerability vectors:

  • A01 — Broken Access Control
  • A02 — Cryptographic Failures
  • A03 — Injection (SQLi, XSS, Command Injection)
  • A04 — Insecure Design
  • A05 — Security Misconfiguration
  • A06 — Vulnerable Components
  • A07 — Auth & Session Failures
  • A08 — Software & Data Integrity
  • A09 — Security Logging Failures
  • A10 — Server-Side Request Forgery

Bounty Tier Mapping

Automatic classification into bug bounty payout tiers:

ScoreSeverityTierTypical Payout
9.0 – 10.0CRITICALP1$2,000 – $10,000+
7.0 – 8.9HIGHP2$500 – $2,000
4.0 – 6.9MEDIUMP3$150 – $500
0.1 – 3.9LOWP4$50 – $150
0.0NONEP5$0 – $50 (Info)

Audit Log

  • Commit calculated vectors to a local audit log
  • Copy any vector to clipboard with one click
  • Export full audit log as JSON
  • Entries stored in localStorage with UUID identifiers
  • Maximum 50 entries with duplicate detection

Vector Parser

Paste any CVSS v3.1 vector string and parse it directly into the calculator:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Quickstart

Option 1: Open directly

# Clone the repo
git clone https://github.com/YOUR_USERNAME/vector.git
# Open in browser
open index.html

Option 2: Serve locally

# Python
python -m http.server 8080
# Node.js
npx serve .# Then open http://localhost:8080

No build step. No dependencies to install. Just open index.html.


Usage

Calculate a CVSS Score

  1. Select values for all 8 base metrics (Attack Vector, Attack Complexity, etc.)
  2. Optionally set Temporal metrics (Exploit Maturity, Remediation Level, Report Confidence)
  3. The score updates in real-time on the gauge
  4. Click Commit to Audit Log to save

Use the Decision Tree

  1. Scroll to the Vuln Decision Tree section
  2. Select a vulnerability category tab (CSRF, XSS, SQLi, etc.)
  3. Click a scenario card to view details
  4. Click Load Vector into Calculator to auto-fill all metrics

Parse a Vector String

  1. Click Parse Vector String in the sidebar
  2. Paste any CVSS v3.1 vector (e.g., CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
  3. Click Parse & Load
  4. Metrics auto-fill and score calculates

Apply OWASP Presets

  1. Select an OWASP category from the dropdown
  2. Click Apply
  3. Vector loads with a description of the vulnerability class

Tech Stack

TechnologyPurpose
HTML5Semantic structure
CSS3Dark theme with CSS variables, custom properties
JavaScript (ES6+)CVSS calculation engine, DOM manipulation
GSAP 3.12.5Scroll animations, gauge animations, UI transitions
Tailwind CSSUtility-first layout helpers
Google FontsBebas Neue (display), JetBrains Mono (code), Space Grotesk (body)

All external scripts loaded with Subresource Integrity (SRI) hashes.


Project Structure

vector/
├── index.html # Complete SPA — HTML + CSS + JS in one file
├── README.md # This file
└── UPDATE.md # Full changelog

Security

Implemented Protections

ProtectionDescription
XSS PreventionescapeHtml() sanitizes all data before innerHTML injection
Safe DOM RenderingDecision Tree uses createElement + textContent instead of innerHTML
Input WhitelistingAll CVSS keys/values validated against VALID_CVSS_KEYS before processing
localStorage ValidationsanitizeLogEntry() validates type, length, and score range of all entries
SRI HashesGSAP scripts loaded with integrity + crossorigin attributes
No Inline HandlersEvent listeners attached via addEventListener, not onclick attributes
UUID Audit EntriesEach log entry gets a v4 UUID to prevent ID collisions

Threat Model

This is a client-side only tool. All calculations happen in the browser. No data is sent to any server. The audit log uses localStorage for persistence.


Accessibility

  • role="radiogroup" + aria-label on all metric option grids
  • aria-label on every radio input
  • aria-live="polite" on score gauge and live clock
  • Global focus-visible styles for keyboard navigation
  • Focus trap in the Parse Vector modal
  • High-contrast dark theme

Browser Support

BrowserStatus
Chrome 90+Full support
Firefox 90+Full support
Safari 15+Full support
Edge 90+Full support

Contributing

  1. Fork the repository
  2. Create a feature branch (git checkout -b feature/new-vuln-category)
  3. Make your changes in index.html
  4. Test in at least two browsers
  5. Submit a pull request

Adding a New Vulnerability Category

  1. Add a new entry to the DT_DATA object in the <script> section
  2. Add a <button class="dt-tab" data-vuln="YOUR_KEY">Label</button> to the #dt-tabs div
  3. Follow the existing format: label, icon, scenarios[] with id, tier, sev, score, color, name, desc, vector

License

MIT License. Use it, fork it, modify it.


VECTOR — Built for bug hunters who take scoring seriously.

About

A professional, interactive CVSS v3.1 Scoring Engine & Vulnerability Decision Tree built for Bug Bounty Hunters and Security Researchers.

Topics

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Latest commit

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

VersionCVSSLicenseClient Side

VECTOR

Bug Hunter CVSS Calculator

A dark-themed, single-file CVSS v3.1 scoring engine built for bug bounty hunters and security researchers.

FeaturesQuickstartDecision TreeOWASP PresetsAudit LogTech StackSecurityLicense


Features

CVSS v3.1 Scoring Engine

Full implementation of the Common Vulnerability Scoring System v3.1 specification:

  • Base Score — Attack Vector, Attack Complexity, Privileges Required, User Interaction, Scope, Confidentiality, Integrity, Availability
  • Temporal Score — Exploit Maturity, Remediation Level, Report Confidence
  • Environmental Score — Confidentiality, Integrity, Availability Requirements (CR/IR/AR)
  • Real-time animated gauge with severity classification (NONE → LOW → MEDIUM → HIGH → CRITICAL)
  • CRITICAL scores (9.0+) trigger a pulse animation to draw attention

Vuln Decision Tree

28 vulnerability categories with 89 pre-scored scenarios across all severity levels:

CategoryKeyCategoryKey
Cross-Site Request ForgeryCSRFRemote Code ExecutionRCE
Cross-Site ScriptingXSSXML External EntityXXE
CORS MisconfigurationCORSServer-Side Template InjectionSSTI
Insecure Direct Object ReferenceIDOROpen RedirectREDIR
Business Logic FlawsBIZMalicious File UploadUPLOAD
Server-Side Request ForgerySSRFAuthentication BypassAUTHBYP
SQL InjectionSQLIRace ConditionRACE
Insecure DeserializationDESERJWT VulnerabilitiesJWT
GraphQL VulnerabilitiesGQLAPI Security FlawsAPIS
Subdomain TakeoverSUBTKClickjackingCLICKJ
HTTP Request SmugglingSMUGGLWeb Cache PoisoningCACHEP
Host Header InjectionHOSTHDRPath TraversalPATHTR
Information DisclosureINFOLEAKMissing Rate LimitingRATELIM
Mass AssignmentMASSASGNPrototype PollutionPROTOPL

Each scenario includes:

  • Real-world description
  • Pre-calculated CVSS score
  • Severity + Bounty Tier classification
  • One-click vector loading into the calculator

OWASP Quick Presets

One-click loading of OWASP Top 10 (2021) vulnerability vectors:

  • A01 — Broken Access Control
  • A02 — Cryptographic Failures
  • A03 — Injection (SQLi, XSS, Command Injection)
  • A04 — Insecure Design
  • A05 — Security Misconfiguration
  • A06 — Vulnerable Components
  • A07 — Auth & Session Failures
  • A08 — Software & Data Integrity
  • A09 — Security Logging Failures
  • A10 — Server-Side Request Forgery

Bounty Tier Mapping

Automatic classification into bug bounty payout tiers:

ScoreSeverityTierTypical Payout
9.0 – 10.0CRITICALP1$2,000 – $10,000+
7.0 – 8.9HIGHP2$500 – $2,000
4.0 – 6.9MEDIUMP3$150 – $500
0.1 – 3.9LOWP4$50 – $150
0.0NONEP5$0 – $50 (Info)

Audit Log

  • Commit calculated vectors to a local audit log
  • Copy any vector to clipboard with one click
  • Export full audit log as JSON
  • Entries stored in localStorage with UUID identifiers
  • Maximum 50 entries with duplicate detection

Vector Parser

Paste any CVSS v3.1 vector string and parse it directly into the calculator:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Quickstart

Option 1: Open directly

# Clone the repo
git clone https://github.com/YOUR_USERNAME/vector.git
# Open in browser
open index.html

Option 2: Serve locally

# Python
python -m http.server 8080
# Node.js
npx serve .# Then open http://localhost:8080

No build step. No dependencies to install. Just open index.html.


Usage

Calculate a CVSS Score

  1. Select values for all 8 base metrics (Attack Vector, Attack Complexity, etc.)
  2. Optionally set Temporal metrics (Exploit Maturity, Remediation Level, Report Confidence)
  3. The score updates in real-time on the gauge
  4. Click Commit to Audit Log to save

Use the Decision Tree

  1. Scroll to the Vuln Decision Tree section
  2. Select a vulnerability category tab (CSRF, XSS, SQLi, etc.)
  3. Click a scenario card to view details
  4. Click Load Vector into Calculator to auto-fill all metrics

Parse a Vector String

  1. Click Parse Vector String in the sidebar
  2. Paste any CVSS v3.1 vector (e.g., CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
  3. Click Parse & Load
  4. Metrics auto-fill and score calculates

Apply OWASP Presets

  1. Select an OWASP category from the dropdown
  2. Click Apply
  3. Vector loads with a description of the vulnerability class

Tech Stack

TechnologyPurpose
HTML5Semantic structure
CSS3Dark theme with CSS variables, custom properties
JavaScript (ES6+)CVSS calculation engine, DOM manipulation
GSAP 3.12.5Scroll animations, gauge animations, UI transitions
Tailwind CSSUtility-first layout helpers
Google FontsBebas Neue (display), JetBrains Mono (code), Space Grotesk (body)

All external scripts loaded with Subresource Integrity (SRI) hashes.


Project Structure

vector/
├── index.html # Complete SPA — HTML + CSS + JS in one file
├── README.md # This file
└── UPDATE.md # Full changelog

Security

Implemented Protections

ProtectionDescription
XSS PreventionescapeHtml() sanitizes all data before innerHTML injection
Safe DOM RenderingDecision Tree uses createElement + textContent instead of innerHTML
Input WhitelistingAll CVSS keys/values validated against VALID_CVSS_KEYS before processing
localStorage ValidationsanitizeLogEntry() validates type, length, and score range of all entries
SRI HashesGSAP scripts loaded with integrity + crossorigin attributes
No Inline HandlersEvent listeners attached via addEventListener, not onclick attributes
UUID Audit EntriesEach log entry gets a v4 UUID to prevent ID collisions

Threat Model

This is a client-side only tool. All calculations happen in the browser. No data is sent to any server. The audit log uses localStorage for persistence.


Accessibility

  • role="radiogroup" + aria-label on all metric option grids
  • aria-label on every radio input
  • aria-live="polite" on score gauge and live clock
  • Global focus-visible styles for keyboard navigation
  • Focus trap in the Parse Vector modal
  • High-contrast dark theme

Browser Support

BrowserStatus
Chrome 90+Full support
Firefox 90+Full support
Safari 15+Full support
Edge 90+Full support

Contributing

  1. Fork the repository
  2. Create a feature branch (git checkout -b feature/new-vuln-category)
  3. Make your changes in index.html
  4. Test in at least two browsers
  5. Submit a pull request

Adding a New Vulnerability Category

  1. Add a new entry to the DT_DATA object in the <script> section
  2. Add a <button class="dt-tab" data-vuln="YOUR_KEY">Label</button> to the #dt-tabs div
  3. Follow the existing format: label, icon, scenarios[] with id, tier, sev, score, color, name, desc, vector

License

MIT License. Use it, fork it, modify it.


VECTOR — Built for bug hunters who take scoring seriously.

About

A professional, interactive CVSS v3.1 Scoring Engine & Vulnerability Decision Tree built for Bug Bounty Hunters and Security Researchers.

Topics

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

VersionCVSSLicenseClient Side

VECTOR

Bug Hunter CVSS Calculator

A dark-themed, single-file CVSS v3.1 scoring engine built for bug bounty hunters and security researchers.

FeaturesQuickstartDecision TreeOWASP PresetsAudit LogTech StackSecurityLicense


Features

CVSS v3.1 Scoring Engine

Full implementation of the Common Vulnerability Scoring System v3.1 specification:

  • Base Score — Attack Vector, Attack Complexity, Privileges Required, User Interaction, Scope, Confidentiality, Integrity, Availability
  • Temporal Score — Exploit Maturity, Remediation Level, Report Confidence
  • Environmental Score — Confidentiality, Integrity, Availability Requirements (CR/IR/AR)
  • Real-time animated gauge with severity classification (NONE → LOW → MEDIUM → HIGH → CRITICAL)
  • CRITICAL scores (9.0+) trigger a pulse animation to draw attention

Vuln Decision Tree

28 vulnerability categories with 89 pre-scored scenarios across all severity levels:

CategoryKeyCategoryKey
Cross-Site Request ForgeryCSRFRemote Code ExecutionRCE
Cross-Site ScriptingXSSXML External EntityXXE
CORS MisconfigurationCORSServer-Side Template InjectionSSTI
Insecure Direct Object ReferenceIDOROpen RedirectREDIR
Business Logic FlawsBIZMalicious File UploadUPLOAD
Server-Side Request ForgerySSRFAuthentication BypassAUTHBYP
SQL InjectionSQLIRace ConditionRACE
Insecure DeserializationDESERJWT VulnerabilitiesJWT
GraphQL VulnerabilitiesGQLAPI Security FlawsAPIS
Subdomain TakeoverSUBTKClickjackingCLICKJ
HTTP Request SmugglingSMUGGLWeb Cache PoisoningCACHEP
Host Header InjectionHOSTHDRPath TraversalPATHTR
Information DisclosureINFOLEAKMissing Rate LimitingRATELIM
Mass AssignmentMASSASGNPrototype PollutionPROTOPL

Each scenario includes:

  • Real-world description
  • Pre-calculated CVSS score
  • Severity + Bounty Tier classification
  • One-click vector loading into the calculator

OWASP Quick Presets

One-click loading of OWASP Top 10 (2021) vulnerability vectors:

  • A01 — Broken Access Control
  • A02 — Cryptographic Failures
  • A03 — Injection (SQLi, XSS, Command Injection)
  • A04 — Insecure Design
  • A05 — Security Misconfiguration
  • A06 — Vulnerable Components
  • A07 — Auth & Session Failures
  • A08 — Software & Data Integrity
  • A09 — Security Logging Failures
  • A10 — Server-Side Request Forgery

Bounty Tier Mapping

Automatic classification into bug bounty payout tiers:

ScoreSeverityTierTypical Payout
9.0 – 10.0CRITICALP1$2,000 – $10,000+
7.0 – 8.9HIGHP2$500 – $2,000
4.0 – 6.9MEDIUMP3$150 – $500
0.1 – 3.9LOWP4$50 – $150
0.0NONEP5$0 – $50 (Info)

Audit Log

  • Commit calculated vectors to a local audit log
  • Copy any vector to clipboard with one click
  • Export full audit log as JSON
  • Entries stored in localStorage with UUID identifiers
  • Maximum 50 entries with duplicate detection

Vector Parser

Paste any CVSS v3.1 vector string and parse it directly into the calculator:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Quickstart

Option 1: Open directly

# Clone the repo
git clone https://github.com/YOUR_USERNAME/vector.git
# Open in browser
open index.html

Option 2: Serve locally

# Python
python -m http.server 8080
# Node.js
npx serve .# Then open http://localhost:8080

No build step. No dependencies to install. Just open index.html.


Usage

Calculate a CVSS Score

  1. Select values for all 8 base metrics (Attack Vector, Attack Complexity, etc.)
  2. Optionally set Temporal metrics (Exploit Maturity, Remediation Level, Report Confidence)
  3. The score updates in real-time on the gauge
  4. Click Commit to Audit Log to save

Use the Decision Tree

  1. Scroll to the Vuln Decision Tree section
  2. Select a vulnerability category tab (CSRF, XSS, SQLi, etc.)
  3. Click a scenario card to view details
  4. Click Load Vector into Calculator to auto-fill all metrics

Parse a Vector String

  1. Click Parse Vector String in the sidebar
  2. Paste any CVSS v3.1 vector (e.g., CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
  3. Click Parse & Load
  4. Metrics auto-fill and score calculates

Apply OWASP Presets

  1. Select an OWASP category from the dropdown
  2. Click Apply
  3. Vector loads with a description of the vulnerability class

Tech Stack

TechnologyPurpose
HTML5Semantic structure
CSS3Dark theme with CSS variables, custom properties
JavaScript (ES6+)CVSS calculation engine, DOM manipulation
GSAP 3.12.5Scroll animations, gauge animations, UI transitions
Tailwind CSSUtility-first layout helpers
Google FontsBebas Neue (display), JetBrains Mono (code), Space Grotesk (body)

All external scripts loaded with Subresource Integrity (SRI) hashes.


Project Structure

vector/
├── index.html # Complete SPA — HTML + CSS + JS in one file
├── README.md # This file
└── UPDATE.md # Full changelog

Security

Implemented Protections

ProtectionDescription
XSS PreventionescapeHtml() sanitizes all data before innerHTML injection
Safe DOM RenderingDecision Tree uses createElement + textContent instead of innerHTML
Input WhitelistingAll CVSS keys/values validated against VALID_CVSS_KEYS before processing
localStorage ValidationsanitizeLogEntry() validates type, length, and score range of all entries
SRI HashesGSAP scripts loaded with integrity + crossorigin attributes
No Inline HandlersEvent listeners attached via addEventListener, not onclick attributes
UUID Audit EntriesEach log entry gets a v4 UUID to prevent ID collisions

Threat Model

This is a client-side only tool. All calculations happen in the browser. No data is sent to any server. The audit log uses localStorage for persistence.


Accessibility

  • role="radiogroup" + aria-label on all metric option grids
  • aria-label on every radio input
  • aria-live="polite" on score gauge and live clock
  • Global focus-visible styles for keyboard navigation
  • Focus trap in the Parse Vector modal
  • High-contrast dark theme

Browser Support

BrowserStatus
Chrome 90+Full support
Firefox 90+Full support
Safari 15+Full support
Edge 90+Full support

Contributing

  1. Fork the repository
  2. Create a feature branch (git checkout -b feature/new-vuln-category)
  3. Make your changes in index.html
  4. Test in at least two browsers
  5. Submit a pull request

Adding a New Vulnerability Category

  1. Add a new entry to the DT_DATA object in the <script> section
  2. Add a <button class="dt-tab" data-vuln="YOUR_KEY">Label</button> to the #dt-tabs div
  3. Follow the existing format: label, icon, scenarios[] with id, tier, sev, score, color, name, desc, vector

License

MIT License. Use it, fork it, modify it.


VECTOR — Built for bug hunters who take scoring seriously.

About

A professional, interactive CVSS v3.1 Scoring Engine & Vulnerability Decision Tree built for Bug Bounty Hunters and Security Researchers.

Topics

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

VersionCVSSLicenseClient Side

VECTOR

Bug Hunter CVSS Calculator

A dark-themed, single-file CVSS v3.1 scoring engine built for bug bounty hunters and security researchers.

FeaturesQuickstartDecision TreeOWASP PresetsAudit LogTech StackSecurityLicense


Features

CVSS v3.1 Scoring Engine

Full implementation of the Common Vulnerability Scoring System v3.1 specification:

  • Base Score — Attack Vector, Attack Complexity, Privileges Required, User Interaction, Scope, Confidentiality, Integrity, Availability
  • Temporal Score — Exploit Maturity, Remediation Level, Report Confidence
  • Environmental Score — Confidentiality, Integrity, Availability Requirements (CR/IR/AR)
  • Real-time animated gauge with severity classification (NONE → LOW → MEDIUM → HIGH → CRITICAL)
  • CRITICAL scores (9.0+) trigger a pulse animation to draw attention

Vuln Decision Tree

28 vulnerability categories with 89 pre-scored scenarios across all severity levels:

CategoryKeyCategoryKey
Cross-Site Request ForgeryCSRFRemote Code ExecutionRCE
Cross-Site ScriptingXSSXML External EntityXXE
CORS MisconfigurationCORSServer-Side Template InjectionSSTI
Insecure Direct Object ReferenceIDOROpen RedirectREDIR
Business Logic FlawsBIZMalicious File UploadUPLOAD
Server-Side Request ForgerySSRFAuthentication BypassAUTHBYP
SQL InjectionSQLIRace ConditionRACE
Insecure DeserializationDESERJWT VulnerabilitiesJWT
GraphQL VulnerabilitiesGQLAPI Security FlawsAPIS
Subdomain TakeoverSUBTKClickjackingCLICKJ
HTTP Request SmugglingSMUGGLWeb Cache PoisoningCACHEP
Host Header InjectionHOSTHDRPath TraversalPATHTR
Information DisclosureINFOLEAKMissing Rate LimitingRATELIM
Mass AssignmentMASSASGNPrototype PollutionPROTOPL

Each scenario includes:

  • Real-world description
  • Pre-calculated CVSS score
  • Severity + Bounty Tier classification
  • One-click vector loading into the calculator

OWASP Quick Presets

One-click loading of OWASP Top 10 (2021) vulnerability vectors:

  • A01 — Broken Access Control
  • A02 — Cryptographic Failures
  • A03 — Injection (SQLi, XSS, Command Injection)
  • A04 — Insecure Design
  • A05 — Security Misconfiguration
  • A06 — Vulnerable Components
  • A07 — Auth & Session Failures
  • A08 — Software & Data Integrity
  • A09 — Security Logging Failures
  • A10 — Server-Side Request Forgery

Bounty Tier Mapping

Automatic classification into bug bounty payout tiers:

ScoreSeverityTierTypical Payout
9.0 – 10.0CRITICALP1$2,000 – $10,000+
7.0 – 8.9HIGHP2$500 – $2,000
4.0 – 6.9MEDIUMP3$150 – $500
0.1 – 3.9LOWP4$50 – $150
0.0NONEP5$0 – $50 (Info)

Audit Log

  • Commit calculated vectors to a local audit log
  • Copy any vector to clipboard with one click
  • Export full audit log as JSON
  • Entries stored in localStorage with UUID identifiers
  • Maximum 50 entries with duplicate detection

Vector Parser

Paste any CVSS v3.1 vector string and parse it directly into the calculator:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Quickstart

Option 1: Open directly

# Clone the repo
git clone https://github.com/YOUR_USERNAME/vector.git
# Open in browser
open index.html

Option 2: Serve locally

# Python
python -m http.server 8080
# Node.js
npx serve .# Then open http://localhost:8080

No build step. No dependencies to install. Just open index.html.


Usage

Calculate a CVSS Score

  1. Select values for all 8 base metrics (Attack Vector, Attack Complexity, etc.)
  2. Optionally set Temporal metrics (Exploit Maturity, Remediation Level, Report Confidence)
  3. The score updates in real-time on the gauge
  4. Click Commit to Audit Log to save

Use the Decision Tree

  1. Scroll to the Vuln Decision Tree section
  2. Select a vulnerability category tab (CSRF, XSS, SQLi, etc.)
  3. Click a scenario card to view details
  4. Click Load Vector into Calculator to auto-fill all metrics

Parse a Vector String

  1. Click Parse Vector String in the sidebar
  2. Paste any CVSS v3.1 vector (e.g., CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
  3. Click Parse & Load
  4. Metrics auto-fill and score calculates

Apply OWASP Presets

  1. Select an OWASP category from the dropdown
  2. Click Apply
  3. Vector loads with a description of the vulnerability class

Tech Stack

TechnologyPurpose
HTML5Semantic structure
CSS3Dark theme with CSS variables, custom properties
JavaScript (ES6+)CVSS calculation engine, DOM manipulation
GSAP 3.12.5Scroll animations, gauge animations, UI transitions
Tailwind CSSUtility-first layout helpers
Google FontsBebas Neue (display), JetBrains Mono (code), Space Grotesk (body)

All external scripts loaded with Subresource Integrity (SRI) hashes.


Project Structure

vector/
├── index.html # Complete SPA — HTML + CSS + JS in one file
├── README.md # This file
└── UPDATE.md # Full changelog

Security

Implemented Protections

ProtectionDescription
XSS PreventionescapeHtml() sanitizes all data before innerHTML injection
Safe DOM RenderingDecision Tree uses createElement + textContent instead of innerHTML
Input WhitelistingAll CVSS keys/values validated against VALID_CVSS_KEYS before processing
localStorage ValidationsanitizeLogEntry() validates type, length, and score range of all entries
SRI HashesGSAP scripts loaded with integrity + crossorigin attributes
No Inline HandlersEvent listeners attached via addEventListener, not onclick attributes
UUID Audit EntriesEach log entry gets a v4 UUID to prevent ID collisions

Threat Model

This is a client-side only tool. All calculations happen in the browser. No data is sent to any server. The audit log uses localStorage for persistence.


Accessibility

  • role="radiogroup" + aria-label on all metric option grids
  • aria-label on every radio input
  • aria-live="polite" on score gauge and live clock
  • Global focus-visible styles for keyboard navigation
  • Focus trap in the Parse Vector modal
  • High-contrast dark theme

Browser Support

BrowserStatus
Chrome 90+Full support
Firefox 90+Full support
Safari 15+Full support
Edge 90+Full support

Contributing

  1. Fork the repository
  2. Create a feature branch (git checkout -b feature/new-vuln-category)
  3. Make your changes in index.html
  4. Test in at least two browsers
  5. Submit a pull request

Adding a New Vulnerability Category

  1. Add a new entry to the DT_DATA object in the <script> section
  2. Add a <button class="dt-tab" data-vuln="YOUR_KEY">Label</button> to the #dt-tabs div
  3. Follow the existing format: label, icon, scenarios[] with id, tier, sev, score, color, name, desc, vector

License

MIT License. Use it, fork it, modify it.


VECTOR — Built for bug hunters who take scoring seriously.

About

A professional, interactive CVSS v3.1 Scoring Engine & Vulnerability Decision Tree built for Bug Bounty Hunters and Security Researchers.

Topics

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Latest commit

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

VersionCVSSLicenseClient Side

VECTOR

Bug Hunter CVSS Calculator

A dark-themed, single-file CVSS v3.1 scoring engine built for bug bounty hunters and security researchers.

FeaturesQuickstartDecision TreeOWASP PresetsAudit LogTech StackSecurityLicense


Features

CVSS v3.1 Scoring Engine

Full implementation of the Common Vulnerability Scoring System v3.1 specification:

  • Base Score — Attack Vector, Attack Complexity, Privileges Required, User Interaction, Scope, Confidentiality, Integrity, Availability
  • Temporal Score — Exploit Maturity, Remediation Level, Report Confidence
  • Environmental Score — Confidentiality, Integrity, Availability Requirements (CR/IR/AR)
  • Real-time animated gauge with severity classification (NONE → LOW → MEDIUM → HIGH → CRITICAL)
  • CRITICAL scores (9.0+) trigger a pulse animation to draw attention

Vuln Decision Tree

28 vulnerability categories with 89 pre-scored scenarios across all severity levels:

CategoryKeyCategoryKey
Cross-Site Request ForgeryCSRFRemote Code ExecutionRCE
Cross-Site ScriptingXSSXML External EntityXXE
CORS MisconfigurationCORSServer-Side Template InjectionSSTI
Insecure Direct Object ReferenceIDOROpen RedirectREDIR
Business Logic FlawsBIZMalicious File UploadUPLOAD
Server-Side Request ForgerySSRFAuthentication BypassAUTHBYP
SQL InjectionSQLIRace ConditionRACE
Insecure DeserializationDESERJWT VulnerabilitiesJWT
GraphQL VulnerabilitiesGQLAPI Security FlawsAPIS
Subdomain TakeoverSUBTKClickjackingCLICKJ
HTTP Request SmugglingSMUGGLWeb Cache PoisoningCACHEP
Host Header InjectionHOSTHDRPath TraversalPATHTR
Information DisclosureINFOLEAKMissing Rate LimitingRATELIM
Mass AssignmentMASSASGNPrototype PollutionPROTOPL

Each scenario includes:

  • Real-world description
  • Pre-calculated CVSS score
  • Severity + Bounty Tier classification
  • One-click vector loading into the calculator

OWASP Quick Presets

One-click loading of OWASP Top 10 (2021) vulnerability vectors:

  • A01 — Broken Access Control
  • A02 — Cryptographic Failures
  • A03 — Injection (SQLi, XSS, Command Injection)
  • A04 — Insecure Design
  • A05 — Security Misconfiguration
  • A06 — Vulnerable Components
  • A07 — Auth & Session Failures
  • A08 — Software & Data Integrity
  • A09 — Security Logging Failures
  • A10 — Server-Side Request Forgery

Bounty Tier Mapping

Automatic classification into bug bounty payout tiers:

ScoreSeverityTierTypical Payout
9.0 – 10.0CRITICALP1$2,000 – $10,000+
7.0 – 8.9HIGHP2$500 – $2,000
4.0 – 6.9MEDIUMP3$150 – $500
0.1 – 3.9LOWP4$50 – $150
0.0NONEP5$0 – $50 (Info)

Audit Log

  • Commit calculated vectors to a local audit log
  • Copy any vector to clipboard with one click
  • Export full audit log as JSON
  • Entries stored in localStorage with UUID identifiers
  • Maximum 50 entries with duplicate detection

Vector Parser

Paste any CVSS v3.1 vector string and parse it directly into the calculator:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Quickstart

Option 1: Open directly

# Clone the repo
git clone https://github.com/YOUR_USERNAME/vector.git
# Open in browser
open index.html

Option 2: Serve locally

# Python
python -m http.server 8080
# Node.js
npx serve .# Then open http://localhost:8080

No build step. No dependencies to install. Just open index.html.


Usage

Calculate a CVSS Score

  1. Select values for all 8 base metrics (Attack Vector, Attack Complexity, etc.)
  2. Optionally set Temporal metrics (Exploit Maturity, Remediation Level, Report Confidence)
  3. The score updates in real-time on the gauge
  4. Click Commit to Audit Log to save

Use the Decision Tree

  1. Scroll to the Vuln Decision Tree section
  2. Select a vulnerability category tab (CSRF, XSS, SQLi, etc.)
  3. Click a scenario card to view details
  4. Click Load Vector into Calculator to auto-fill all metrics

Parse a Vector String

  1. Click Parse Vector String in the sidebar
  2. Paste any CVSS v3.1 vector (e.g., CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
  3. Click Parse & Load
  4. Metrics auto-fill and score calculates

Apply OWASP Presets

  1. Select an OWASP category from the dropdown
  2. Click Apply
  3. Vector loads with a description of the vulnerability class

Tech Stack

TechnologyPurpose
HTML5Semantic structure
CSS3Dark theme with CSS variables, custom properties
JavaScript (ES6+)CVSS calculation engine, DOM manipulation
GSAP 3.12.5Scroll animations, gauge animations, UI transitions
Tailwind CSSUtility-first layout helpers
Google FontsBebas Neue (display), JetBrains Mono (code), Space Grotesk (body)

All external scripts loaded with Subresource Integrity (SRI) hashes.


Project Structure

vector/
├── index.html # Complete SPA — HTML + CSS + JS in one file
├── README.md # This file
└── UPDATE.md # Full changelog

Security

Implemented Protections

ProtectionDescription
XSS PreventionescapeHtml() sanitizes all data before innerHTML injection
Safe DOM RenderingDecision Tree uses createElement + textContent instead of innerHTML
Input WhitelistingAll CVSS keys/values validated against VALID_CVSS_KEYS before processing
localStorage ValidationsanitizeLogEntry() validates type, length, and score range of all entries
SRI HashesGSAP scripts loaded with integrity + crossorigin attributes
No Inline HandlersEvent listeners attached via addEventListener, not onclick attributes
UUID Audit EntriesEach log entry gets a v4 UUID to prevent ID collisions

Threat Model

This is a client-side only tool. All calculations happen in the browser. No data is sent to any server. The audit log uses localStorage for persistence.


Accessibility

  • role="radiogroup" + aria-label on all metric option grids
  • aria-label on every radio input
  • aria-live="polite" on score gauge and live clock
  • Global focus-visible styles for keyboard navigation
  • Focus trap in the Parse Vector modal
  • High-contrast dark theme

Browser Support

BrowserStatus
Chrome 90+Full support
Firefox 90+Full support
Safari 15+Full support
Edge 90+Full support

Contributing

  1. Fork the repository
  2. Create a feature branch (git checkout -b feature/new-vuln-category)
  3. Make your changes in index.html
  4. Test in at least two browsers
  5. Submit a pull request

Adding a New Vulnerability Category

  1. Add a new entry to the DT_DATA object in the <script> section
  2. Add a <button class="dt-tab" data-vuln="YOUR_KEY">Label</button> to the #dt-tabs div
  3. Follow the existing format: label, icon, scenarios[] with id, tier, sev, score, color, name, desc, vector

License

MIT License. Use it, fork it, modify it.


VECTOR — Built for bug hunters who take scoring seriously.

About

A professional, interactive CVSS v3.1 Scoring Engine & Vulnerability Decision Tree built for Bug Bounty Hunters and Security Researchers.

Topics

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages