DEV Community

endoflife-ai
endoflife-ai

Posted on Originally published at endoflife.ai

EOL Risk Score vs EPSS vs CISA KEV: What Each One Tells You

EPSS estimates if a CVE will be exploited in the next 30 days. KEV lists CVEs already exploited. The EOL Risk Score rates a version's lifecycle risk.

Side by side

EPSS CISA KEV EOL Risk Score
What is rated One CVE One CVE One version of one product
What it says How likely exploitation is in the next 30 days CISA has added the CVE to its catalog of vulnerabilities known to be exploited in the wild How risky the version is to keep running
Form A probability from 0 to 1, with a percentile rank A list: a CVE is on it or not, with a date added and a due date for US federal agencies A 0 to 100 score, grouped into four risk bands, with its four contributing factors shown
Updated Recalculated daily for every CVE. The model itself is revised from time to time; FIRST put version 5 live in June 2026 As CISA adds entries At every build, as dates pass and KEV changes
Knows whether the version is still supported No No Yes, it is the largest factor
Published by FIRST CISA endoflife.ai

What's covered

  • Side by side
  • How the EOL Risk Score uses KEV
  • Using them together

Full guide with every version, risk scores, and live updates: https://endoflife.ai/article-eol-risk-score-vs-epss

Top comments (0)