Skip to content

Data collected

CVEs Live

EPSS score lookup

Paste up to 100 CVE IDs, or any text that contains them, and get today’s EPSS for each, with the ones already in CISA KEV placed first.

A scanner report, an advisory or a plain list: identifiers are picked out of the text.

The identifiers are sent from your browser to api.first.org (FIRST). Nothing is sent to this site.

What EPSS measures

EPSS is a model published by FIRST.org that gives every CVE a probability, between 0 and 1, of being exploited in the wild in the next 30 days. The model is retrained on observed exploitation and all scores are recalculated daily, so a score is always tied to a date.

Probability and percentile

The probability is the estimate. The percentile says how that estimate ranks among all scored CVEs. They diverge a lot: because the vast majority of CVEs score close to zero, a probability of 5% can already be above the 90th percentile. Use the probability to reason about likelihood and the percentile to compare CVEs with each other.

How to use it with KEV and CVSS

  1. If the CVE is in KEV, exploitation is confirmed. Fix it; the EPSS value no longer changes the decision.
  2. Outside KEV, a high EPSS says exploitation is likely soon. Treat it as the next queue.
  3. Use CVSS to judge the impact on your systems once you know the CVE is worth attention.

What it is not

EPSS is not a measure of severity, and it knows nothing about your environment. A low score is not a guarantee: new CVEs start low and can jump within days when exploit code is published, which is why this lookup always reads the current score from FIRST instead of a stored copy.

0%25%50%75%100%
A score is tied to a date: the same CVE can read low one day and high the next. Illustrative.

Highest EPSS scores

The 40 CVEs with the highest probability in the EPSS model of 2 Oct 2026, as collected on 3 Oct 2026. 38 of them are in CISA KEV.

  1. CVE-2024-7593Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  2. CVE-2024-3400Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  3. CVE-2024-23897Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  4. CVE-2024-21893Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  5. CVE-2024-21887Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  6. CVE-2023-4966Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  7. CVE-2023-44487Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  8. CVE-2023-35082Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  9. CVE-2023-35078Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  10. CVE-2023-32315Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  11. CVE-2023-27350Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  12. CVE-2023-22518Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  13. CVE-2023-1671Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  14. CVE-2023-1389Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  15. CVE-2023-0669Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  16. CVE-2022-29464Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  17. CVE-2022-26134Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  18. CVE-2021-4510599.999% · 100th
  19. CVE-2021-44228Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  20. CVE-2021-40438Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  21. CVE-2021-35464Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  22. CVE-2021-34473Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  23. CVE-2021-26086Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  24. CVE-2021-26084Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  25. CVE-2021-22005Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  26. CVE-2021-21985Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  27. CVE-2021-1498Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  28. CVE-2020-5902Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  29. CVE-2019-19781Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  30. CVE-2019-11510Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  31. CVE-2019-0708Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  32. CVE-2018-13379Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  33. CVE-2017-9841Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  34. CVE-2017-5638Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  35. CVE-2015-1635Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  36. CVE-2014-6271Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  37. CVE-2014-356699.999% · 100th
  38. CVE-2014-0160Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.999% · 100th
  39. CVE-2025-53770Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.998% · 100th
  40. CVE-2022-22954Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog99.998% · 100th

Questions

What is an EPSS score?

EPSS, the Exploit Prediction Scoring System maintained by FIRST.org, estimates the probability, from 0 to 1, that a CVE will see exploitation activity in the wild in the next 30 days. It is produced by a model trained on observed exploitation and is recalculated every day for all published CVEs.

What is the difference between EPSS probability and percentile?

The probability is the estimate itself: 0.05 means a 5% chance of exploitation activity in the next 30 days. The percentile ranks that CVE against all others: the 95th percentile means the score is equal to or higher than that of 95% of scored CVEs. Because most CVEs have very low scores, a probability of only a few percent can already sit above the 90th percentile.

What EPSS value should I treat as high?

There is no official threshold. FIRST advises choosing one according to how much remediation effort you can afford: a lower threshold catches more of the exploited CVEs but costs more work. Whatever you choose, treat a KEV listing as stronger evidence than any EPSS value, because it is observed exploitation and not a forecast.

Does EPSS replace CVSS?

No. They answer different questions: CVSS describes severity if the vulnerability is exploited, EPSS estimates how likely exploitation is. Using both, with KEV on top, gives a better order of work than either alone.

Where do the scores on this page come from?

From the public EPSS API of FIRST.org (api.first.org). The lookup asks the API directly from your browser at the moment you press the button, and shows the model date returned with each score.

Related sections