Data source resources

EPSS (FIRST)

EPSS is an external exploit-likelihood signal used by DevSecure Intelligence to help vendors and security teams understand which vulnerabilities are more likely to be exploited.

What is EPSS?

EPSS, the Exploit Prediction Scoring System from FIRST, estimates the probability that a vulnerability will be exploited in the wild over the next 30 days.

Why exploit probability matters

Exploit probability helps separate widely exploitable issues from vulnerabilities that are severe on paper but less likely to be used in current attack activity.

How DevSecure Intelligence uses EPSS

DevSecure Intelligence uses EPSS as an exploit-likelihood signal alongside CVSS, CISA KEV, exploit evidence, source coverage, and patch intelligence.

How EPSS affects prioritisation

Higher EPSS probability and percentile values can raise a CVE's rank when they align with severity, exposure, known exploitation, or patch signals.

DevSecure does not own or publish EPSS. FIRST maintains the official EPSS data and methodology.

Official FIRST EPSS page