EPSS estimates if a CVE will be exploited in the next 30 days. KEV lists CVEs already exploited. The EOL Risk Score rates a version's lifecycle risk.
Side by side
| EPSS | CISA KEV | EOL Risk Score | |
|---|---|---|---|
| What is rated | One CVE | One CVE | One version of one product |
| What it says | How likely exploitation is in the next 30 days | CISA has added the CVE to its catalog of vulnerabilities known to be exploited in the wild | How risky the version is to keep running |
| Form | A probability from 0 to 1, with a percentile rank | A list: a CVE is on it or not, with a date added and a due date for US federal agencies | A 0 to 100 score, grouped into four risk bands, with its four contributing factors shown |
| Updated | Recalculated daily for every CVE. The model itself is revised from time to time; FIRST put version 5 live in June 2026 | As CISA adds entries | At every build, as dates pass and KEV changes |
| Knows whether the version is still supported | No | No | Yes, it is the largest factor |
| Published by | FIRST | CISA | endoflife.ai |
What's covered
- Side by side
- How the EOL Risk Score uses KEV
- Using them together
Full guide with every version, risk scores, and live updates: https://endoflife.ai/article-eol-risk-score-vs-epss
Top comments (0)