Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.

Global Accelerated Learning • Est. 1999
Glossary Term EPSS Exploit Prediction Scoring System

Training Camp • Cybersecurity Glossary

What is EPSS Exploit Prediction Scoring System?

The Exploit Prediction Scoring System EPSS estimates the probability a CVE will be exploited within 30 days, aiding risk-based patch prioritization.

Glossary > Governance, Risk & Compliance > EPSS Exploit Prediction Scoring System

Understanding EPSS Exploit Prediction Scoring System

The Exploit Prediction Scoring System EPSS is a data-driven model maintained by FIRST that estimates the probability a given vulnerability will be exploited in the wild within the next 30 days. Each CVE receives a score between 0 and 1, updated daily based on real-world threat data and vulnerability characteristics. Unlike CVSS, which measures severity, EPSS measures likelihood of exploitation, and the two are often combined to drive risk-based vulnerability prioritization.

Learn More About EPSS Exploit Prediction Scoring System:

Ready to Get Certified?

EPSS Exploit Prediction Scoring System is one of the topics you'll master in the CEH Boot Camp.

CEH Boot Camp →