Type CVEEPSS is a CVE's Exploit Prediction Scoring System (EPSS) score: the calibrated chance that exploitation activity is observed in the next 30 days. FIRST publishes a new score for every CVE daily. Use the probability for decisions and the percentile for context; most scores sit near zero because most CVEs are never exploited. Reference: Exploit Prediction Scoring System (EPSS)
Fields
| Field Name | Description |
|---|---|
probability - Float!
|
The chance, from 0 to 1, that exploitation activity is observed in the next 30 days. A score of 0.05 means about 5% of similar CVEs see exploitation activity within that window. |
percentile - Float!
|
The share, from 0 to 1, of scored CVEs with the same or a lower probability. |
modelVersion - String!
|
The EPSS model that produced the score, such as v2026.06.15. Scores from different models aren't comparable. |
scoreDate - Time!
|
When EPSS scored the CVE. |
Used by
CVEtype: Type CVE represents a Common Vulnerabilities and Exposures entry with comprehensive security information
Example
Example
{
"probability": 123.45,
"percentile": 123.45,
"modelVersion": "abc123",
"scoreDate": "2021-10-07T18:23:25.829Z"
}