What is EPSS?
Exploit Prediction Scoring System: FIRST's daily estimate of the probability (0 to 1) that a CVE will see exploitation activity in the next 30 days.
EPSS is a data-driven model fed by CVE details and observed exploitation activity. Each CVE gets a probability and a percentile (how it ranks against all scored CVEs). Scores are published every day and are free to download or query.
A score of 0.10 means an estimated 10% chance of exploitation attempts in the next 30 days; most CVEs score far below 0.01. EPSS answers "how likely", CVSS answers "how bad" and KEV answers "already happening".
Sources
Related terms
- CVSSCommon Vulnerability Scoring System: FIRST's standard 0.0–10.0 score for how severe a vulnerability is, based on how it can be exploited and what it affects.
- KEV catalogCISA's Known Exploited Vulnerabilities catalog: the list of CVEs with reliable evidence of exploitation in the wild, each with a required action and a due date.
- SSVCStakeholder-Specific Vulnerability Categorization: a decision-tree method that turns a few facts about a vulnerability into an action, such as Track, Attend or Act.