EPSS Score Lookup
Get the current EPSS probability and percentile for one CVE or a batch of them, so you can tell likely exploitation from merely high severity.
Uses an external data sourceYour search term is sent to the public authority named on this page so the answer reflects current data.
Data source: FIRST EPSS API
Use the tool
Probability, not severity
CVSS measures how bad exploitation would be. EPSS, the Exploit Prediction Scoring System maintained by FIRST, estimates how likely it is. Specifically, it gives the probability that exploitation activity will be observed for a CVE in the next 30 days, based on observed exploitation, the vulnerability's characteristics and public activity around it. A CVSS 9.8 with an EPSS of 0.1% and a CVSS 6.5 with an EPSS of 90% are very different problems. Most organisations should be looking at the second one first.
Score and percentile
The score is the probability itself, from 0 to 1 (shown here as a percentage). The percentile places it against every other scored CVE: the 95th percentile means it scores higher than 95% of them. Most CVEs have small probabilities, so a score of 10% can already be in the top few percent. Read both together.
Freshness
EPSS is recalculated daily. Every result shows the model date it came from, and this tool caches a batch for up to 12 hours. If FIRST cannot be reached, the last good copy is shown and marked stale. With no copy at all, every row says Unknown. A CVE that FIRST does not score (typically one that is very new or was rejected) is shown as "Not scored", which is a different thing from a low score.
Using it well
EPSS is a prioritisation input, not a verdict. A known-exploited vulnerability in the CISA KEV catalogue is already being exploited, whatever its EPSS. Your own exposure matters too: an internet-facing asset outranks an isolated one. The Vulnerability Prioritization Calculator combines all of these in a formula you can see.
Frequently asked questions
Why did a CVE's EPSS change overnight?
The model is refit on new exploitation and activity data every day. A jump usually means new public exploit code, social media or news activity, or observed exploitation attempts.
Is a low EPSS safe to ignore?
No. It means exploitation is unlikely in the next 30 days across the internet as a whole. A targeted attacker, or a vulnerability in your most critical system, can still justify fixing it quickly.
What model version is this?
Whatever FIRST currently publishes through its public API. The model date is shown on every row.
Source and attribution
Related tools
Rate this tool
Was this tool useful? Your feedback helps us improve it.