The Exploit Prediction Scoring System (EPSS) is a data-driven machine-learning model that estimates the probability that a published CVE will be exploited in the wild in the next 30 days.

It offsets subjective judgments with empirical signals from observed exploitation and ongoing activity, helping you focus limited remediation effort where attacks are most likely. EPSS publishes a 0–1 probability (with ranking percentiles) every day for every CVE and makes the data freely and openly accessible via CSV and API as well as a github repo, so it slots easily into workflows and dashboards.

Where to go from here

How It Works Model methodology, feature overview, calibration, and known limitations.

Why EPSS? The empirical case for exploitation likelihood as a prioritization signal. Performance data, CVSS comparison, and what the research shows.

Using EPSS How to set thresholds, combine EPSS with CVSS and KEV, interpret score changes, and avoid common misuses.

Frequently Asked Questions Answers to the questions practitioners ask most often about the score, the percentile, and how EPSS compares to other tools.

Research Peer-reviewed papers, presentations, and the version changelog.

Get the Data API reference, daily CSV downloads, historical scores, and integration examples.

Get involved

The EPSS Special Interest Group (SIG) is a practitioner community focused on putting EPSS to work. Members meet every other Friday, share implementations, and contribute case studies and talks. If you use EPSS or want to, the SIG is where the conversation happens.

Special Thanks

Special thank you to all of our data partners who make EPSS possible. Exploitation activity data used in EPSS is provided in part by a number of industry and government partners, which includes but is not limited to: VulnCheck KEV (VulnCheck Known Exploited Vulnerabilities), Shadow Server Foundation and LevelBlue.


EPSS is maintained by the EPSS Special Interest Group at FIRST. Scores are generated by Empirical Security and published freely to the community.