FIRST Exploit Prediction Scoring System

EPSS: predictive vulnerability prioritization

EPSS exploitation probability crossed with NVD severity and CISA KEV known exploitation, without confusing prediction with attack evidence.

Interpretation rule

EPSS estimates the probability that a CVE will be exploited in the next 30 days. CISA KEV records known exploitation. When a CVE is in KEV, observed evidence always takes precedence over prediction.

Loading EPSS signals…
How to prioritize CVEs →Known exploitation: CISA KEV →Security dashboard →