Exploit Prediction Scoring System
Definition
A daily estimate of the probability that a published CVE will be exploited in the wild during the next 30 days.
Why it matters
Use probability, percentile and movement together. EPSS helps rank a large population, but it must be combined with product presence, reachability, consequence and controls.
Use it in practice
Start with authoritative evidence, record the source and freshness, and be explicit about what this term can and cannot tell you. Connect it to asset context and a named action rather than treating it as an isolated label.
Related terms
CVE · KEV · Exploitability