The Lab · Threat intelligence

Exploit odds

Sort a queue by severity alone and plenty of the wrong things land at the top. Two public datasets say more: CISA's catalogue of flaws already exploited, and FIRST's daily forecast of which CVEs will see exploitation in the next 30 days. We'll join them over six exhibits and run them against a fictional queue.

A snapshot of both datasets is embedded in this page, so nothing is fetched and only your progress is saved. The estate, its severity labels and the simulated forecasters are synthetic. This page is not affiliated with or endorsed by FIRST or CISA (see About the data).

About the data

Where this comes from

  • EPSS scores from FIRST, https://www.first.org/epss. EPSS is maintained by the EPSS SIG at FIRST, and the scores are generated by Empirical Security and published freely. Cite: Jacobs, Romanosky, Edwards, Roytman and Adjerid (2021), "Exploit Prediction Scoring System", Digital Threats: Research and Practice 2(3).
  • CISA's Known Exploited Vulnerabilities catalogue, distributed under CC0 1.0.
  • This page is not affiliated with or endorsed by FIRST, Empirical Security, CISA or DHS.
  • The snapshot keeps cumulative counts at a fixed grid of thresholds and every catalogue CVE with its score, percentile, vendor, product and deadline. It also keeps the highest scores outside the catalogue and a seeded sample of the rest.
  • Every field was checked when the snapshot was built and again when this page loaded. Text from the datasets reaches the page as plain text, and a CVE becomes a link to NVD only when it has the CVE-YYYY-NNNN form.
  • The catalogue's deadlines come from Binding Operational Directives, and BOD 22-01 created the catalogue.
  • The estate, its severity labels and the simulated forecasters are synthetic. No real organisation, host or person appears.
  • Nothing is fetched: the page runs from the snapshot in this file, and the links here open only when you follow them. The snapshot is rebuilt by tools/make-epss.js, which refuses any input it cannot validate.