EPSS predicts exploitation, CVSS scores severity. Where they disagree, how to combine them, and what to do when both say critical.

The Exploit Prediction Scoring System (EPSS) is a vulnerability management framework developed in 2019 that’s managed by the Forum of Incident Response and Security Teams (FIRST).
Using a machine learning model trained on comprehensive data ranging from vendor reports to white hat research, the EPSS estimates the probability that a vulnerability will be exploited within thirty days, reflected as a percentile score.
The model assigns this score to each newly discovered vulnerability based on over 1100 variables.
The EPSS is updated daily and can be downloaded from FIRST’s website in CSV format. Vulnerabilities in the EPSS are categorized by their Common Vulnerabilities and Exposures (CVE) identifiers per MITRE’s CVE List. Each vulnerability is also assigned two scores:
In addition to a percentile score, the EPSS groups vulnerabilities into one of four categories:
True Negatives: Vulnerabilities with a low EPSS score and no exploits in observed data.
From a security perspective, EPSS is important because it supports better, more accurate vulnerability remediation.
Because the EPSS model is trained on real-world exploitation attempts and vulnerability databases, it can accurately predict how likely threat actors are to exploit a vulnerability. This adds valuable context to metrics, such as the Common Vulnerability Scoring System (CVSS), allowing teams to avoid wasting time and energy remediating vulnerabilities where exploitation is unlikely.
When evaluating a vulnerability, the EPSS first ingests data on the vulnerability’s age, MITRE CVE listing, CVSS score, Common Weakness Enumeration (CWE), and associated vendor. The model also draws from the National Vulnerability Database and pulls data from security vendors, government agencies, exploitation records, and vulnerability databases. Other sources include the Cybersecurity and Infrastructure Agency’s (CISA’s) Known Exploited Vulnerabilities catalog and data gathered by FIRST and its partners.
The EPSS model processes and analyzes this data to generate a score for each vulnerability.
EPSS differs from other vulnerability scoring systems in a few ways.
It’s measured as a percentage, representing the chance bad actors will exploit a vulnerability.
It’s also open-source and leverages machine learning for scoring, further setting it apart from traditional scoring.
FIRST also manages the Common Vulnerability Scoring System. This system measures how much damage a vulnerability can do if it’s exploited, a metric known as severity.
The system assigns vulnerabilities a severity score of 0-10, with 10 being the highest. The severity score is calculated based on the following groups of metrics:
Each CVSS vulnerability fits into one of four severity levels: None (0), Low (0.1-3.9), Medium (4.0-6.9), High (7.0-8.9), or Critical (9.0-10.0).
The Common Weakness Scoring System (CWSS), developed as part of the Common Weakness Enumeration (CWE) project, measures flaws or security errors in software, known as weaknesses.
While not themselves vulnerabilities, these weaknesses are potentially exploitable by threat actors.MITRE created CWSS as a companion to its Common Weakness Enumeration (CWE) framework. This system is measured across three categories:
To calculate CWSS, each category is assigned a weighted subscore multiplied by the three scores to produce a score between 0 and 100.
The Exploit Prediction Scoring System (EPSS) is a data-driven framework developed in 2019 by FIRST to predict how likely a vulnerability will be exploited in the wild within the next 30 days. Scores range from 0 to 1 indicating probability, and are ranked as percentiles to help security teams prioritize effectively.
CVSS (Common Vulnerability Scoring System) measures the severity of a vulnerability based on its potential impact (e.g., damage, access complexity), using a 0 to 10 scale. EPSS, on the other hand, predicts real-world exploit likelihood, not severity, providing a complementary perspective focused on actual attacker behavior.
EPSS trains a machine learning model on data drawn from CVE details, CVSS, CWE, vendor reports, security vendor, and government databases (such as CISA’s Known Exploited Vulnerabilities), and real-world exploit telemetry.
Scores are refreshed daily and published in a downloadable CSV via FIRST’s EPSS portal. This frequent update allows teams to respond quickly as new exploitation trends emerge.
Yes. EPSS has demonstrated strong predictive accuracy. The current model achieves approximately an 82% performance improvement in distinguishing exploited vulnerabilities over earlier versions. Many security teams use it to focus remediation on vulnerabilities with higher real-world threat potential.
EPSS predicts only the probability of exploitation, not the potential impact of a vulnerability. Low-scoring vulnerabilities may still cause significant damage, depending on the environment. EPSS also relies on past data trends and may lag slightly in predicting novel threat techniques.
Tamnoon reads the findings your scanner already raised, closes what Tamnoon can prove safe through your own controls, and declines the rest in writing with the evidence why.