LiveIn use by CVE Triage
FIRST Exploit Prediction Scoring System (EPSS)
What it is
A daily probability, from 0 to 1, that a CVE will see exploitation activity in the next 30 days, with its percentile rank among all scored CVEs.
Publisher and URL
FIRST.org EPSS Special Interest Group.
Licence
Scores are published free of charge by CSV download and API, with no registration. FIRST asks for attribution when EPSS data is used in publications or products, and we give it on every response.
Update cadence
Daily. A new score is published every day for every scored CVE. We load the daily CSV, which is the right way to keep a local copy; the API is designed for lookups.
Fields we use
CVE ID, EPSS score, percentile, score date, model version. EPSS v5 has been in use since 15 June 2026.
Known gaps
- Only CVEs with published IDs are scored.
- Scores move every day, so we return the score date with every value.
How Stackbyte uses it
The stackbyte.epss.* fields in CVE Triage, and one of the inputs to the triage priority.
Field by field details are in the CVE Triage docs.