Skip to content
Noroxi

Action score.Three signals, one priority.

CVSS tells you how severe a vulnerability is, not how urgent it is. The action score also accounts for what’s happening in the wild.

Formula

formula
action = CVSS × 4  +  (30 if KEV)  +  EPSS × 30         max 40       max 30          max 30
  1. CVSS

    max 40

    Technical severity

    How severe is the vulnerability itself? The CVSS base score is multiplied by 4. A flaw scoring 9.8 out of 10 contributes 39 points.

  2. CISA KEV

    max 30

    Exploited in the wild

    The US Cybersecurity and Infrastructure Security Agency’s list of vulnerabilities confirmed to be actively exploited. Every CVE on the list gets 30 points.

  3. EPSS

    max 30

    Near-term likelihood

    FIRST’s estimate of the probability of exploitation in the next 30 days. A 90% probability contributes 27 points.

Bands

80–100
Now
Patch today or shut off access.
60–79
This week
Don’t wait for the next maintenance window.
40–59
Plan
Add it to your regular patch cycle.
0–39
Monitor
Low priority for now; keep an eye on changes.

Example

A hypervisor flaw with CVSS 8.2 that requires local access, isn’t in KEV, and has a 5% EPSS: 33 + 0 + 2 = 35 · Monitor. A print server flaw with CVSS 7.5 whose EPSS jumped from 13% to 42% in a week: 30 + 0 + 13 = 43 · Plan, and it’s on the trending list. A team that only looks at CVSS patches the first one first.

Data sources

  • NVDCVE records, CVSS vectors, CPE and CWE mappings
  • CISA KEVCatalog of actively exploited vulnerabilities
  • FIRST EPSSDaily exploitation probability estimates
  • Vendor advisoriesAffected and fixed versions

Data comes from NVD, the CVE Program, CISA KEV, FIRST EPSS and OSV; the last update date is shown above the CVE list.

Our publishing principles

  • Every record is published with detection and remediation guidance.
  • We don’t publish working exploit code or step-by-step attack instructions.
  • We don’t link to proof-of-concept repositories; we only note that one exists.
  • Code samples are representative examples that show the flawed pattern and its fix.
Back to the CVE list