CyberMax
Home › Glossary › Vulnerability management

What is EPSS?

Vulnerability management glossary · 1 primary source

Exploit Prediction Scoring System: FIRST's daily estimate of the probability (0 to 1) that a CVE will see exploitation activity in the next 30 days.

EPSS is a data-driven model fed by CVE details and observed exploitation activity. Each CVE gets a probability and a percentile (how it ranks against all scored CVEs). Scores are published every day and are free to download or query.

A score of 0.10 means an estimated 10% chance of exploitation attempts in the next 30 days; most CVEs score far below 0.01. EPSS answers "how likely", CVSS answers "how bad" and KEV answers "already happening".

Sources

Related terms

On this site

All vulnerability management terms · Full glossary