# What is CVSS Score? CVSS, EPSS, and KEV explained ![Prasanna Kumar](https://www.manageengine.com/ems/images/tools/employee/prasanna-dp.png) Prasanna Kumar Last updated on: October 2026 14 Min Read ## Key Takeaways - CVSS measures vulnerability severity, not exploitation likelihood. It rates the technical characteristics of a vulnerability on a 0 to 10 scale. - EPSS and CISA KEV add exploitation context. EPSS estimates the likelihood that a vulnerability will be exploited in the wild, while KEV identifies vulnerabilities that are known to have been exploited. - Effective vulnerability prioritization uses multiple signals. Combining severity, exploitation likelihood, confirmed exploitation, and environmental context helps security teams focus remediation efforts. ## What is a vulnerability score? Every year, security researchers publish tens of thousands of new vulnerabilities. No organization can patch them all at the same pace they are published. That gap between what needs fixing and what teams can realistically address is where vulnerability scoring becomes essential. Scoring gives each vulnerability a numeric value so security teams can sort the CVEs into a ranked, workable list. But not all scoring systems measure the same thing. Understanding what each system requires, and what it does not, is the difference between a remediation plan that reduces real risk and one that wastes time on theoretical threats. This article covers the three scoring signals, CVSS, EPSS, and CISA KEV and gives a picture of what each one measures, where each falls short on its own, and how they work together to give a complete picture of vulnerability risk. A vulnerability score is a numeric value assigned to a security flaw to indicate how severe it is. Each of these signals provides a different view of vulnerability risk: 1. **CVSS** measures how technically severe a vulnerability could be if exploited 2. **EPSS** measures how likely a vulnerability is to be exploited within the next 30 days 3. **CISA KEV** confirms which vulnerabilities are being actively exploited in real attacks at the moment Each signal answers a different question, and no single score gives the full picture. That is why mature vulnerability management programs use all three of them together, rather than relying on any one signal alone. ## What is CVSS? The Common Vulnerability Scoring System (CVSS) is an open standard for rating the technical severity of software vulnerabilities. It is a numeric score ranging from 0.0 to 10.0. A higher score indicates a more severe vulnerability in terms of the potential damage and the ease with which it can be exploited. CVSS is maintained by FIRST (Forum of Incident Response and Security Teams) and is used across the cybersecurity industry as the baseline to determine the severity of a particular vulnerability. ## How CVSS is calculated The metrics used to calculate CVSS depends on the version. CVSS v3.1 organizes metrics into three groups: Base, Temporal, and Environmental. CVSS v4.0, the current version, uses four groups: Base, Threat, Environmental, and Supplemental. Base metrics capture properties intrinsic to the vulnerability itself. This includes properties that stay constant regardless of environment or time, such as: 1. **Attack vector:** Can the attacker exploit this remotely over a network, from an adjacent network, or only with local or physical access to the system? 2. **Attack complexity:** Is the attack straightforward, or does it require specific conditions to be in place? 3. **Privileges required:** Does the attacker need no access at all, limited user access, or administrator level privileges? 4. **User interaction:** Can the attack succeed automatically, or does it require a person to take an action such as clicking a link? 5. **Impact on confidentiality, integrity, and availability:** If exploited, what is the potential damage to data secrecy, data accuracy, and system uptime? Threat metrics (CVSS v4.0) reflect characteristics of the vulnerability that change over time. This group contains a single metric, Exploit Maturity, which captures whether working exploit code exists and how it is being used, from no known exploits through proof of concept to active use in attacks. In CVSS v3.1, the equivalent group is called Temporal metrics and contains three metrics: Exploit Code Maturity, Remediation Level, and Report Confidence. CVSS v4.0 simplified this by retiring Remediation Level and Report Confidence and renaming Exploit Code Maturity to Exploit Maturity. Environmental metrics let organizations adjust the score based on their specific context. If the affected asset is not critical to business operations, or if backup measures are already in place, then the organization can weigh the score accordingly. Supplemental metrics (CVSS v4.0 only) provide additional context about the vulnerability without changing the numerical score. FIRST designed this group to give vendors and security teams additional context about how a vulnerability might behave and how hard it is to respond to. These metrics include: 1. **Safety (S):** Whether exploitation could cause physical harm or safety impacts, relevant for operational technology and industrial control systems. 2. **Automatable (AU):** Whether the steps from initial access to exploitation can be automated at scale, to check for mass exploitation potential. 3. **Recovery (R):** How well the affected system recovers after exploitation, from full recovery through partial to irrecoverable. 4. **Value Density (V):** Whether exploiting a vulnerability gives an attacker access to a concentrated, high-value target (like a central database or domain controller) or a diffuse, lower-value one (like an isolated endpoint). 5. **Vulnerability Response Effort (RE):** Tracks the remediation difficulty for the vendor. Whether a simple patch deployment is sufficient, or whether the fix requires configuration changes and workarounds. 6. **Provider Urgency (U):** The vendor adds an urgency signal for the vulnerability. ## What do CVSS score ranges mean? | CVSS Score | Severity Level | |---|---| | 0.0 | None | | 0.1 to 3.9 | Low | | 4.0 to 6.9 | Medium | | 7.0 to 8.9 | High | | 9.0 to 10.0 | Critical | A CVSS score of 9.8 falls within the Critical severity range and indicates very high technical severity. The exact characteristics of the vulnerability, including how it can be exploited and the potential impact, are described by its CVSS vector string rather than by the score alone. ### CVSS v3.1 and CVSS v4.0 CVSS v3.1 remains widely used and is a part of many compliance and remediation workflows. The NVD relies heavily on CVSS v3.1 for its historical and current database catalogs. Because millions of security tools sync with the NVD on a daily basis, v3.1 remains widely used by default. CVSS v4.0, published by FIRST in 2023, is the latest version of the framework. The most significant structural change in v4.0 is the simplification of the Temporal metric group into a Threat metric group. CVSS v3.1's Temporal group includes three metrics, namely, Exploit Code Maturity, Remediation Level, and Report Confidence. CVSS v4.0's Threat group retires two of those and retains a single metric, Exploit Maturity. CVSS v4.0 also adds Supplemental metrics that provide context beyond the numeric score, and it extends scoring coverage to safety considerations relevant to operational technology, industrial control systems, and IoT environments. Both versions are in active use across the industry. ## Why is CVSS alone not enough for vulnerability prioritization? CVSS describes the technical severity of a vulnerability, but severity alone does not indicate how urgently it needs to be remediated. This creates a practical challenge. When a single scan surfaces thousands of CVEs scoring 7.0 or above, treating all of them as equal priority is not possible. In the process, teams end up chasing theoretical risk while missing the vulnerabilities attackers are actively using. Consider two examples: Vulnerability A has a CVSS score of 9.8. It has been publicly known for two years, has no published exploit code, and affects a niche application deployed in very few environments. Vulnerability B has a CVSS score of 6.5. It was disclosed three months ago, already has an active exploit, and threat intelligence indicates it is being used in ransomware campaigns. By CVSS alone, Vulnerability A looks far more urgent. In practice, Vulnerability B is the one that needs immediate attention. CVSS cannot distinguish between the two scenarios because it measures severity, not exploitation activity. EPSS exists precisely to fill that gap. ## What is EPSS? The Exploit Prediction Scoring System (EPSS) is a machine learning model that estimates the probability a vulnerability will be exploited in the wild within the next 30 days. It is maintained by [FIRST](https://www.first.org/epss/), the same organization responsible for CVSS. EPSS produces a score between 0.0 and 1.0, or 0% to 100%. A score of 0.94 means there is a 94 percent predicted probability that the vulnerability will be exploited within 30 days. A score of 0.003 means exploitation is very unlikely in that window. ## How EPSS works EPSS updates daily. The model trains on data from the National Vulnerability Database (NVD), Exploit-DB, CISA KEV, and observed exploitation activity across the internet. It learns patterns connecting vulnerability characteristics to real world exploitation behaviour, then applies that learning to newly published CVEs to generate daily predictions. Since the model updates every day, an EPSS score can shift significantly. A vulnerability that scores low today can move sharply higher if new exploit code is published or if attackers begin targeting it actively. EPSS does not replace CVSS. Compliance frameworks require CVSS as reference for mandatory remediation. The two systems are designed to be used together: CVSS describes the technical severity of a vulnerability, while EPSS estimates how likely it is to be exploited in the wild. ## What is CISA KEV? The CISA Known Exploited Vulnerabilities catalog is a list of CVEs confirmed to be actively exploited in real attacks. It is maintained by the Cybersecurity and Infrastructure Security Agency (CISA) and updated continuously as new exploitation is confirmed. Where EPSS predicts future exploitation probability, CISA KEV confirms that exploitation is already happening. Under CISA Binding Operational Directive 22-01, Federal Civilian Executive Branch agencies are required to remediate vulnerabilities listed in the KEV catalog by the deadlines specified by CISA. Many private sector organizations have adopted similar policies because KEV provides a high-confidence signal of known exploitation. A vulnerability can carry a low CVSS score, a modest EPSS value, and still appear in KEV, and it needs to be prioritized. A vulnerability in the KEV catalog should receive immediate attention regardless of what the other scores suggest, because its exploitation has already been confirmed in real attacks. ## How to Prioritize Vulnerabilities Using CVSS, EPSS, and KEV Each signal answers one specific question: - **CVSS:** How damaging could this be if exploited? - **EPSS:** How likely is exploitation within the next 30 days? - **KEV:** Is this being exploited right now? | CVSS | EPSS | On KEV? | Recommended Action | |---|---|---|---| | High or Critical | High | Yes | Immediate remediation | | High or Critical | High | No | Prioritize urgently | | High or Critical | Low | No | Schedule in standard queue | | Medium or Low | High | Yes | Prioritize urgently despite low severity | | Medium or Low | Low | No | Deprioritize | This approach can help teams focus their remediation efforts on vulnerabilities that combine significant severity with meaningful exploitation risk, rather than treating every high-severity finding as equally urgent. ## How Do Composite Risk Scores Improve Vulnerability Prioritization? CVSS, EPSS, and KEV each provide a different view of vulnerability risk, but they do not always point to the same vulnerabilities. A vulnerability can have a Critical CVSS score while having a low EPSS score and no KEV listing. Another can have a Medium CVSS score while showing a high likelihood of exploitation or confirmed exploitation. This creates a practical question: How should security teams prioritize vulnerabilities when these signals point in different directions? One approach is to combine multiple signals into a composite risk score. Such scores can incorporate factors such as technical severity, exploitation likelihood, confirmed exploitation, asset criticality, exploit availability, and exposure to produce a more context-aware view of risk. Another approach is to use a structured decision framework rather than a single score. SSVC (Stakeholder-Specific Vulnerability Categorization), developed by Carnegie Mellon University's Software Engineering Institute with CISA, is an example. It evaluates factors such as exploitation status, exposure, and mission impact to determine an appropriate response rather than assigning a single numerical score. Research shows why combining these signals can improve vulnerability prioritization. A 2025 study from Kagawa University tested a decision tree that first used KEV and EPSS to identify vulnerabilities with higher likelihood of exploitation, and then applied CVSS to assess severity. Across 28,377 vulnerabilities, the approach reduced the number requiring priority attention from about 16,000 to 850 while retaining 85.6% coverage of confirmed exploited vulnerabilities. The key difference is that a composite approach moves beyond asking how severe is this vulnerability? It considers how severe the vulnerability is, how likely it is to be exploited, whether exploitation has been confirmed, and how relevant the vulnerability is to the specific environment. ## How Vulnerability Manager Plus scores and prioritizes vulnerabilities ManageEngine Vulnerability Manager Plus integrates CVSS, EPSS, and a range of additional signals into a composite Risk Score that moves security teams from a raw list of CVEs to a focused, ranked remediation plan. This AI/ML-driven scoring model continuously evaluates multiple real-world risk factors, including: - **Exploit availability:** Presence of publicly available or weaponized proof-of-concepts. - **Active exploitation:** Evidence of known exploited vulnerabilities and in-the-wild attacks. - **Threat actor interest:** Mentions in underground forums and ransomware affiliate activity. - **CVSS severity:** Base severity score indicating the inherent technical impact. - **Predicted exploit probability:** Likelihood of exploitation based on factors such as Exploit Prediction Scoring System (EPSS). - **Vulnerability age:** Duration for which the vulnerability has been exposed. - **Remediation availability:** Availability of patches or mitigation measures. - **Prevalence:** Number of affected endpoints within the environment. - **Exposure duration:** Time period for which the vulnerability remains unaddressed in the environment. - **ML-driven insights:** Cross-vulnerability correlations and historical exploit behaviour patterns. Vulnerability Manager Plus console displays CVSS v3, CVSS v4, and EPSS scores as individual risk indicators, alongside advisories from CISA and CERT. Security teams can see exactly why a vulnerability ranks where it does, making it easier to communicate remediation decisions to management and satisfy audit requirements. Two capabilities set Vulnerability Manager Plus apart from standard CVSS and EPSS frameworks: The Emerging Risk Catalog is a continuously updated repository that captures early warning signals around emerging vulnerabilities, such as exploit chatter, proof-of-concept availability, and attack trends. It helps security teams identify vulnerabilities showing signs of increasing risk before they become widely exploited. The Vulnerability Timeline provides a view of a CVE's history, helping security teams track important events such as its disclosure, exploit availability, KEV listing, and discovery in their environment. This makes it easier to understand how a vulnerability has evolved and assess its urgency. ### About the author ![Prasanna Kumar](https://www.manageengine.com/ems/images/tools/employee/prasanna-dp.png) **Prasanna Kumar** is a Product Consultant at ManageEngine, specializing in Unified Endpoint Management and security solutions. He helps organizations evaluate, implement, and optimize endpoint management strategies aligned with industry best practices. ## Frequently Asked Questions ![faq](https://www.manageengine.com/ems/images/icon/box-icon-v5-7.svg) ### Does EPSS work for zero-day vulnerabilities? EPSS is designed to score publicly disclosed vulnerabilities with CVE identifiers. It does not score undisclosed zero-day vulnerabilities that have not yet been assigned a CVE ID. Once a vulnerability is publicly disclosed and receives a CVE, it can receive an EPSS score.