Vulnerabilities · GraphQL type

CVEEPSS type

Type CVEEPSS is a CVE's Exploit Prediction Scoring System (EPSS) score: the calibrated chance that exploitation activity is observed in the next 30 days. FIRST publishes a new score for every CVE daily. Use the probability for decisions and the percentile for context; most scores sit near zero because most CVEs are never exploited. Reference: Exploit Prediction Scoring System (EPSS)

Fields

Field Name Description
probability - Float! The chance, from 0 to 1, that exploitation activity is observed in the next 30 days. A score of 0.05 means about 5% of similar CVEs see exploitation activity within that window.
percentile - Float! The share, from 0 to 1, of scored CVEs with the same or a lower probability.
modelVersion - String! The EPSS model that produced the score, such as v2026.06.15. Scores from different models aren't comparable.
scoreDate - Time! When EPSS scored the CVE.

Used by

  • CVE type: Type CVE represents a Common Vulnerabilities and Exposures entry with comprehensive security information

Example

Example

{
  "probability": 123.45,
  "percentile": 123.45,
  "modelVersion": "abc123",
  "scoreDate": "2021-10-07T18:23:25.829Z"
}