Finding-Level Scores: QVS, QDS, and QVSS
Three scores describe a single finding. Each answers a different question and appears in different surfaces.
Basic Scores
QVS (per CVE, 1–100) scores the vulnerability as it exists in the world.
QDS (per detection, 1–100) scores what Qualys detected on your asset.
QVSS (per finding, 0.0–10.0) restates QDS on a CVSS-style scale so that teams can read it at a glance.
How the Scores Relate
The three scores are stages of the same progression, from the risk a vulnerability carries in the world, to the risk a specific detection carries on a specific asset, to the number your teams read on a dashboard.
CVE → QVS (CVE-level risk) → QDS (detection-level risk, per QID) → asset TruRisk™ score
QVSS = the same detection-level risk, restated on a 0.0–10.0 scale
| Stage | Level | Question it answers |
|---|---|---|
| QVS | CVE | How dangerous is this vulnerability in the world, regardless of who has it? Every known CVE is assigned a QVS, whether or not Qualys has a detection signature for it, and independent of your environment. |
| QDS | Detection (QID) | How dangerous is this detection on this asset? A QID takes the highest QVS among the CVEs mapped to it, then adjusts for asset context such as compensating controls. A QID with no CVE mapped to it has no QVS to draw on, so its QDS is calculated from Real-time Threat Indicators (RTIs) instead. |
| Asset TruRisk™ score | Asset | How much risk does this asset carry? The QDS values of the detections on the asset are aggregated together with asset criticality. |
| QVSS | Finding | What do we report and prioritize on? QVSS retains the QDS logic and presents it on a 0.0–10.0 scale in ETM. |
QDS values also arrive from CSAM and Policy Audit. Each applies its own rules to determine the QDS result, and those results contribute to the asset's TruRisk™ score alongside VMDR detections.
QVS — Qualys Vulnerability Score
QVS is a Qualys-assigned score for a known CVE, on a scale of 1 to 100, based on multiple factors associated with that CVE.
QVS is computed even for CVEs without a Qualys detection signature, so coverage is not limited to what Qualys can scan for.
QVS is derived from:
| Input group | What it contributes |
|---|---|
| Technical details | CVSS score, EPSS, CISA KEV listing |
| Temporal details | Exploit Code Maturity (ECM), malware association, active threat actors, and whether the threat is trending |
QDS — Qualys Detection Score
QDS is a risk score for a vulnerability that Qualys has detected on an asset. It is assigned per QID in both TruRisk™ 1.0 and TruRisk™ 2.0. QDS starts from the highest QVS among the CVEs mapped to the QID. It also takes into account the controls on the asset that reduce the risk, such as compensating and mitigating controls.
QIDs with No Associated CVE
A VMDR detection (QID) that has no CVE published by the NVD or by threat intelligence providers has no QVS to inherit. For these QIDs, the QDS value is calculated from Real-time Threat Indicators (RTIs) such as zero-day, active attacks, ransomware, and wormable.
QDS values that arrive from CSAM and Policy Audit may have their own rules applied, which govern the resulting QDS. These results also contribute to the asset's TruRisk™ score.
Ranges and Severity
QDS ranges from 1 to 100 with four severity levels:
- Critical 90–100
- High 70–89
- Medium 40–69
- Low 1–39
Qualys recommends prioritizing findings with a score of 70 or above.
QDS is asset-specific and changes over time. The same vulnerability can carry different QDS values on two assets, because compensating controls are taken into account. A Remote Desktop Protocol vulnerability scores lower on an asset where RDP is disabled.
QVSS — Qualys Vulnerability Scoring System
QVSS is the scoring framework used in ETM to measure the risk of findings, misconfigurations, and other security exposures using a unified 0.0 to 10.0 severity scale. It is powered by Qualys Threat Intelligence and TruRisk™ context.
Why QVSS
QVSS resolves two problems organizations reported:
- Two different scales — CVSS 0–10 against QDS 1–100 made comparison and communication difficult.
- Organizations wanted the familiar CVSS-style scale without giving up Qualys threat intelligence.
QVSS retains the QDS logic and maps it to a 0–10 scale, with CVSS-like severity mapping. A score of 9.5 reads immediately as a critical issue. Because it applies to both CVEs and misconfigurations, prioritization is unified across everything you manage. Existing QDS-driven automations and APIs continue to work unchanged.
Base and Environmental Layers
QVSS Score = QVSS Base ± Environmental Adjustments
| Layer | Scope | Inputs |
|---|---|---|
| QVSS Base | The inherent risk of a CVE or misconfiguration in the global ecosystem. Calculated per signature and stored in the knowledge base. | CVSS base vector, attack complexity, privileges required; KEV listing, public exploit, active attacks, EPSS, actor targeting; trending activity, new exploit emergence, and age. |
| QVSS Environmental | An adjustment for your environment, based on asset attributes, control posture, and business impact. Learn more | Risk factors that increase the score: Internet Facing, crown-jewel, industry-targeted; compensating controls that decrease it, such as EDR and mitigations. |
The combined result is the effective score, which is displayed in ETM and used for prioritization, SLAs, and reporting.
Monitor environmental factors; they can significantly change prioritization.
Severity Mapping
| QVSS Range | Severity |
|---|---|
| 9.0 – 10.0 | Critical |
| 7.0 – 8.9 | High |
| 4.0 – 6.9 | Medium |
| 0.0 – 3.9 | Low |
Decimals are preserved, so 9.5 and 9.0 are distinguishable within the Critical band.
Where QVSS Is Displayed
- Findings listing and finding details (Risk Management tab)
- Home page top contributors
- CVE Details. Learn more
- Business Entity views and Risk Workbench
- Dashboards, widgets, and reports
Why a Medium CVSS Can Be a Critical QVSS
CVSS describes only the technical characteristics of a vulnerability, not what attackers are doing with it. The following examples show the difference.
CVE-2024-50302
CVE-2024-50302 carries a CVSS score of 5.5, which reads as Medium. Let us see the threat evidence.
| Attribute | Value | What it means |
|---|---|---|
| CVSS | 5.5 (Medium) | Technical severity only |
| Exploit availability | Weaponized exploit available | Attackers have a working tool |
| Trending | Actively trending Nov 9 to Dec 6 | Being discussed and used in the threat community |
| Threat actors | 1 active threat actor | A known actor is exploiting it |
| Malware association | Present | Malware campaigns use this vulnerability |
| EPSS | 0.02777 | A measurable probability of exploitation |
| CISA KEV | No | Not listed, yet other evidence shows active risk |
| QVSS effective score | 9.5 — Critical | Raised because attackers are targeting it now |
Unlike CVSS, QVSS would surface this to the top versus being buried deep below, out of sight.
CVE-2024-20359
CVE-2024-20359 carries a CVSS score of 6.0, which reads as Medium. Let us see the threat evidence.
| Attribute | Value | What it means |
|---|---|---|
| CVSS | 6.0 (Medium) | Technical severity only |
| Exploit availability | Weaponized exploit and proof-of-concept code | Attackers have a working tool, and the method is public |
| Trending | Multiple spikes, with recent dark-web chatter | Sustained attacker interest, not a single burst |
| Threat actors | 2 active, including UAT-4356 | Named actors are exploiting it |
| Malware association | Ransomware linkage | Used in ransomware campaigns |
| EPSS | 0.0008 | A low predicted probability — on its own, this signal would not raise the score |
| CISA KEV | Yes | Confirmed by CISA as exploited in the wild |
| QVSS effective score | 9.5 — Critical | Raised because confirmed exploitation outweighs the moderate technical severity |
Read the two examples together, and you can see why no single signal decides the outcome. The first vulnerability is not listed in CISA KEV; this one is. This one has a very low EPSS value; the first has a higher one. Both end up at 9.5, because in each case, a different combination of evidence points the same way, and attackers are using it.
Which Score to Use
| Purpose | Use |
|---|---|
| Dashboards, reporting, and communicating with stakeholders | QVSS |
| Automation and APIs that already depend on it, for example, the Host List VM Detection API, which returns the QDS for each detection | QDS |
| Querying a single CVE's inherent score | QVS |
Frequently Asked Questions
Answers to common questions about Qualys scoring and how to use each score.
What is the difference between QVS, QDS, and QVSS?
QVS scores a known CVE, QDS scores a detection (QID) on a specific asset, and QVSS presents the effective score on a 0–10 scale.
Which score should I use to prioritize findings?
Use QVSS for dashboards, reporting, and risk prioritization. QDS remains relevant for APIs and automation.
Does QDS vary between assets for the same vulnerability?
Yes. QDS considers the configuration and controls of the individual asset, so the same vulnerability can receive different scores on different assets.
Why does my QVSS score change over time?
Threat intelligence and environmental factors change over time, and applying controls can also affect the score.
Does QVS require a Qualys detection signature?
No. QVS is calculated for known CVEs even when there is no Qualys detection signature.
How is QDS calculated for a QID with no CVE?
A QID with no associated CVE has no QVS to inherit, so its QDS is calculated from Real-time Threat Indicators (RTIs). QDS values from CSAM and Policy Audit may have their own rules applied that govern the result.
Does scoring apply to findings detected by third-party tools?
Yes. Findings from connected third-party tools are scored the same way as findings from Qualys sensors. QDS is assigned to third-party vulnerabilities and misconfigurations, and QVSS is shown alongside it in ETM, including under Risk Management.