Finding-Level Scores: QVS, QDS, and QVSS

Three scores describe a single finding. Each answers a different question and appears in different surfaces.

Basic Scores

QVS (per CVE, 1–100) scores the vulnerability as it exists in the world.

QDS (per detection, 1–100) scores what Qualys detected on your asset.

QVSS (per finding, 0.0–10.0) restates QDS on a CVSS-style scale so that teams can read it at a glance.

How the Scores Relate

The three scores are stages of the same progression, from the risk a vulnerability carries in the world, to the risk a specific detection carries on a specific asset, to the number your teams read on a dashboard.

CVE → QVS (CVE-level risk) → QDS (detection-level risk, per QID) → asset TruRisk™ score
QVSS = the same detection-level risk, restated on a 0.0–10.0 scale

Stage Level Question it answers
QVS CVE How dangerous is this vulnerability in the world, regardless of who has it? Every known CVE is assigned a QVS, whether or not Qualys has a detection signature for it, and independent of your environment.
QDS Detection (QID) How dangerous is this detection on this asset? A QID takes the highest QVS among the CVEs mapped to it, then adjusts for asset context such as compensating controls. A QID with no CVE mapped to it has no QVS to draw on, so its QDS is calculated from Real-time Threat Indicators (RTIs) instead.
Asset TruRisk™ score Asset How much risk does this asset carry? The QDS values of the detections on the asset are aggregated together with asset criticality.
QVSS Finding What do we report and prioritize on? QVSS retains the QDS logic and presents it on a 0.0–10.0 scale in ETM.

QDS values also arrive from CSAM and Policy Audit. Each applies its own rules to determine the QDS result, and those results contribute to the asset's TruRisk™ score alongside VMDR detections.

QVS — Qualys Vulnerability Score

QVS is a Qualys-assigned score for a known CVE, on a scale of 1 to 100, based on multiple factors associated with that CVE.

QVS is computed even for CVEs without a Qualys detection signature, so coverage is not limited to what Qualys can scan for.

QVS is derived from:

Input group What it contributes
Technical details CVSS score, EPSS, CISA KEV listing
Temporal details Exploit Code Maturity (ECM), malware association, active threat actors, and whether the threat is trending

QDS — Qualys Detection Score

QDS is a risk score for a vulnerability that Qualys has detected on an asset. It is assigned per QID in both TruRisk™ 1.0 and TruRisk™ 2.0. QDS starts from the highest QVS among the CVEs mapped to the QID. It also takes into account the controls on the asset that reduce the risk, such as compensating and mitigating controls.

QIDs with No Associated CVE

A VMDR detection (QID) that has no CVE published by the NVD or by threat intelligence providers has no QVS to inherit. For these QIDs, the QDS value is calculated from Real-time Threat Indicators (RTIs) such as zero-day, active attacks, ransomware, and wormable.

QDS values that arrive from CSAM and Policy Audit may have their own rules applied, which govern the resulting QDS. These results also contribute to the asset's TruRisk™ score.

Ranges and Severity

QDS ranges from 1 to 100 with four severity levels:

  • Critical 90–100
  • High 70–89
  • Medium 40–69
  • Low 1–39

Qualys recommends prioritizing findings with a score of 70 or above.

QDS is asset-specific and changes over time. The same vulnerability can carry different QDS values on two assets, because compensating controls are taken into account. A Remote Desktop Protocol vulnerability scores lower on an asset where RDP is disabled.

QVSS — Qualys Vulnerability Scoring System

QVSS is the scoring framework used in ETM to measure the risk of findings, misconfigurations, and other security exposures using a unified 0.0 to 10.0 severity scale. It is powered by Qualys Threat Intelligence and TruRisk™ context.

Why QVSS

QVSS resolves two problems organizations reported:

  • Two different scales — CVSS 0–10 against QDS 1–100 made comparison and communication difficult.
  • Organizations wanted the familiar CVSS-style scale without giving up Qualys threat intelligence.

QVSS retains the QDS logic and maps it to a 0–10 scale, with CVSS-like severity mapping. A score of 9.5 reads immediately as a critical issue. Because it applies to both CVEs and misconfigurations, prioritization is unified across everything you manage. Existing QDS-driven automations and APIs continue to work unchanged.

Base and Environmental Layers

QVSS Score = QVSS Base ± Environmental Adjustments

Layer Scope Inputs
QVSS Base The inherent risk of a CVE or misconfiguration in the global ecosystem. Calculated per signature and stored in the knowledge base. CVSS base vector, attack complexity, privileges required; KEV listing, public exploit, active attacks, EPSS, actor targeting; trending activity, new exploit emergence, and age.
QVSS Environmental An adjustment for your environment, based on asset attributes, control posture, and business impact. Learn more Risk factors that increase the score: Internet Facing, crown-jewel, industry-targeted; compensating controls that decrease it, such as EDR and mitigations.

The combined result is the effective score, which is displayed in ETM and used for prioritization, SLAs, and reporting.

Monitor environmental factors; they can significantly change prioritization.

Severity Mapping

QVSS Range Severity
9.0 – 10.0 Critical
7.0 – 8.9 High
4.0 – 6.9 Medium
0.0 – 3.9 Low

Decimals are preserved, so 9.5 and 9.0 are distinguishable within the Critical band.

Where QVSS Is Displayed

  • Findings listing and finding details (Risk Management tab)
  • Home page top contributors
  • CVE Details. Learn more
  • Business Entity views and Risk Workbench
  • Dashboards, widgets, and reports

Why a Medium CVSS Can Be a Critical QVSS

CVSS describes only the technical characteristics of a vulnerability, not what attackers are doing with it. The following examples show the difference.

CVE-2024-50302

CVE-2024-50302 carries a CVSS score of 5.5, which reads as Medium. Let us see the threat evidence.

Attribute Value What it means
CVSS 5.5 (Medium) Technical severity only
Exploit availability Weaponized exploit available Attackers have a working tool
Trending Actively trending Nov 9 to Dec 6 Being discussed and used in the threat community
Threat actors 1 active threat actor A known actor is exploiting it
Malware association Present Malware campaigns use this vulnerability
EPSS 0.02777 A measurable probability of exploitation
CISA KEV No Not listed, yet other evidence shows active risk
QVSS effective score 9.5 — Critical Raised because attackers are targeting it now

Unlike CVSS, QVSS would surface this to the top versus being buried deep below, out of sight.

CVE-2024-20359

CVE-2024-20359 carries a CVSS score of 6.0, which reads as Medium. Let us see the threat evidence.

Attribute Value What it means
CVSS 6.0 (Medium) Technical severity only
Exploit availability Weaponized exploit and proof-of-concept code Attackers have a working tool, and the method is public
Trending Multiple spikes, with recent dark-web chatter Sustained attacker interest, not a single burst
Threat actors 2 active, including UAT-4356 Named actors are exploiting it
Malware association Ransomware linkage Used in ransomware campaigns
EPSS 0.0008 A low predicted probability — on its own, this signal would not raise the score
CISA KEV Yes Confirmed by CISA as exploited in the wild
QVSS effective score 9.5 — Critical Raised because confirmed exploitation outweighs the moderate technical severity

Read the two examples together, and you can see why no single signal decides the outcome. The first vulnerability is not listed in CISA KEV; this one is. This one has a very low EPSS value; the first has a higher one. Both end up at 9.5, because in each case, a different combination of evidence points the same way, and attackers are using it.

Which Score to Use

Purpose Use
Dashboards, reporting, and communicating with stakeholders QVSS
Automation and APIs that already depend on it, for example, the Host List VM Detection API, which returns the QDS for each detection QDS
Querying a single CVE's inherent score QVS

Frequently Asked Questions

Answers to common questions about Qualys scoring and how to use each score.

What is the difference between QVS, QDS, and QVSS?

QVS scores a known CVE, QDS scores a detection (QID) on a specific asset, and QVSS presents the effective score on a 0–10 scale.

Which score should I use to prioritize findings?

Use QVSS for dashboards, reporting, and risk prioritization. QDS remains relevant for APIs and automation.

Does QDS vary between assets for the same vulnerability?

Yes. QDS considers the configuration and controls of the individual asset, so the same vulnerability can receive different scores on different assets.

Why does my QVSS score change over time?

Threat intelligence and environmental factors change over time, and applying controls can also affect the score.

Does QVS require a Qualys detection signature?

No. QVS is calculated for known CVEs even when there is no Qualys detection signature.

How is QDS calculated for a QID with no CVE?

A QID with no associated CVE has no QVS to inherit, so its QDS is calculated from Real-time Threat Indicators (RTIs). QDS values from CSAM and Policy Audit may have their own rules applied that govern the result.

Does scoring apply to findings detected by third-party tools?

Yes. Findings from connected third-party tools are scored the same way as findings from Qualys sensors. QDS is assigned to third-party vulnerabilities and misconfigurations, and QVSS is shown alongside it in ETM, including under Risk Management.

Related Topics

TruRisk™ Scoring

TruRisk™ Score for Assets

TruRisk™ Score for Tags and Business Entities

TruRisk™ Scoring: Consolidated Formula Reference