Executive Summary
Score date: …  |  Comparing EPSS model versions side by side  |  EPSS scores = estimated probability of exploitation observed in the wild within the next 30 days (as of the score date)
Loading…
Score Distribution
How EPSS probabilities are distributed across all CVEs — V4 (blue) vs V5 (amber). Most CVEs cluster near zero.
Score Correlation — V4 vs V5 (5,000 sampled CVEs)
Each point is a CVE. Points above the diagonal line scored higher in V5; below = lower. Colored by CVSS severity. Sampling note: 77% of CVEs have V4 scores below 0.01 and cluster invisibly in the bottom-left corner; the chart uses a proportional stratified sample across 10 score buckets to make the high-score region visible.
Score Shift Distribution (V5 − V4)
Distribution of per-CVE score changes. Positive = V5 scored higher, negative = V5 scored lower. Vertical line marks the median shift. Log scale recommended — the near-zero bin is ~1,300× taller than edge bins on linear scale. Note on mean vs. median: The mean delta is −0.00408 (negative) while the median is +0.00298 (positive) — opposite signs. The mean is pulled down by a long left tail: a smaller number of previously-high-scoring CVEs dropped significantly, while the large mass of near-zero CVEs each gained a small amount.
Average EPSS Score by CVSS Severity
Key finding — mean and median tell opposite stories for CRITICAL/HIGH: By mean, V5 lowers CRITICAL (−0.020) and HIGH (−0.003) scores — pulled down by a small number of previously-high-scoring outliers that dropped significantly. By median, V5 raises scores across all four severity bands, including CRITICAL (+0.004) and HIGH (+0.003). The distributions are heavily right-skewed (CRITICAL mean/median ratio ≈ 20×), so the median better represents the typical CVE in each band. Toggle the chart above to compare.
How V4 and V5 scores compare within each CVSS severity band.
SeverityCountAvg V4Avg V5Avg ΔMed V4Med V5
By CWE (Top 40 by CVE Count)
Average EPSS scores grouped by Common Weakness Enumeration. Chart shows top 15 by CVE count, sorted by largest absolute score change. Table (all 40) sorted by delta by default — these 40 CWEs cover ~29.5% of all scored CVEs. The remaining 70.5% have either no CWE assigned or a CWE outside the top 40.
Systematic downgrade pattern: V5 substantially de-prioritizes entire vulnerability classes. CWE-434 (Unrestricted Upload) drops by an average of −0.031 per CVE; CWE-94 (Code Injection) by −0.022; CWE-22 (Path Traversal) by −0.009; CWE-918 (SSRF) by −0.009. Teams using EPSS thresholds to triage these vulnerability types should expect a materially smaller V5 prioritized backlog before adopting.
CWENameCountAvg V4Avg V5Δ
By CVSS v3 Vector Components
How V4 and V5 scores compare across each CVSS metric dimension (Attack Vector, Complexity, Privileges, Impact, etc.). Only the 48.5% of CVEs with CVSS v3 data are included below.
By Vendor (Top 30 by CVE Count)
Vendors with the most CVEs in the dataset and how their scores shifted from V4 to V5. Table sorted by largest absolute delta by default — useful for identifying which vendor portfolios behave most differently between models.
VendorCVEsAvg V4Avg V5ΔMedian V4Median V5
By Product (Top 50 by CVE Count)
Products with the most CVEs and their score comparison. Sorted by largest absolute delta by default.
ProductCVEsAvg V4Avg V5ΔMedian V4Median V5
By CNA / Assigner (Top 30 by CVE Count)
CVE Numbering Authorities ranked by volume of published CVEs and how their assigned CVEs scored in each model. Note: "mitre" (~113k CVEs) represents pre-2017 legacy records where MITRE acted as Naming Authority, not as a scoring CNA — these records typically have no CNA-provided CVSS. V5 Beta status: The V5 model (v2026.05.12) is a public beta; scores may change before general availability and should be validated against your environment before replacing V4 in production workflows.
CNACVEsAvg V4Avg V5ΔMedian V4Median V5
Top 50 Movers — Largest V4 → V5 Score Changes
CVEs where the model change had the greatest impact on predicted exploitation probability.
Model artifact — 2012 antivirus parser cluster: The upgrades list includes 24 CVEs from CVE-2012-1421 through CVE-2012-1463 (antivirus bypass via malformed TAR, ELF, EXE, CAB, Gzip, and ZIP files), all jumping from ≈0.001 to 0.88–0.99 in V5. These share identical description patterns and vendor="n/a". This cluster likely reflects a V5 training signal rather than genuine operational risk change, and should be interpreted with caution. If your environment uses EPSS scores above 0.8 as a hard escalation trigger, audit whether triggering CVEs fall into this pattern before adopting V5.
Top 3 upgrades are the same vulnerability: CVE-2024-29823, CVE-2024-29825, and CVE-2024-29826 all describe the same unspecified SQL Injection in Ivanti EPM Core server (V4≈0.024, V5≈0.999, Δ≈+0.975). They are filed as separate CVEs but represent one underlying issue — treat them as a single data point for prioritization purposes.
CVEYearSeverityV4 ScoreV5 ScoreChange V4 PctileV5 PctileCWEVendorCNADescription
CVEYearSeverityV4 ScoreV5 ScoreChange V4 PctileV5 PctileCWEVendorCNADescription
Data: EPSS by FIRST.org & Cyentia Institute · CVE metadata: CVEProject/cvelistV5 · Built with EPSS-Compare