EPSS (Exploit Prediction Scoring System)
EPSS is a data-driven model from FIRST.org that estimates the probability a CVE will be exploited in the wild within the next 30 days. Scores range from 0 to 1 (0%–100%). EPSS helps prioritize patching by combining NVD data with real-world exploitation observations.
Frequently Asked Questions
What is EPSS (Exploit Prediction Scoring System)?
EPSS is a data-driven model from FIRST.org that estimates the probability a CVE will be exploited in the wild within the next 30 days. Scores range from 0 to 1 (0%–100%). EPSS helps prioritize patching by combining NVD data with real-world exploitation observations.
How is EPSS (Exploit Prediction Scoring System) related to CVSS (Common Vulnerability Scoring System)?
EPSS (Exploit Prediction Scoring System) and CVSS (Common Vulnerability Scoring System) are both key concepts in threat intelligence. CVSS is an open framework for communicating the severity of software vulnerabilities. A CVSS v3 base score from 0 to 10 reflects factors like attack vector, complexity, privileges required, and impact on confidentiality, integrity, and availability. Scores ≥ 9.0 are Critical; ≥ 7.0 are High.
Related Terms
CVSS (Common Vulnerability Scoring System)
CVSS is an open framework for communicating the severity of software vulnerabilities. A CVSS v3 base score from 0 to 10 reflects factors like attack vector, complexity, privileges required, and impact on confidentiality, integrity, and availability. Scores ≥ 9.0 are Critical; ≥ 7.0 are High.
CVE (Common Vulnerabilities and Exposures)
CVE is a public catalogue of known cybersecurity vulnerabilities, maintained by MITRE and sponsored by CISA. Each entry has a unique CVE ID (e.g., CVE-2024-12345), a description, and references. CVE IDs are the universal language for tracking and patching specific vulnerabilities.
KEV (CISA Known Exploited Vulnerabilities)
The CISA KEV catalog lists CVEs that have been confirmed as actively exploited in the wild. US federal agencies are required to patch KEV vulnerabilities by mandated due dates. KEV status is the highest-urgency signal for vulnerability prioritization.
Put this intelligence to work
Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.