Action score.Three signals, one priority.
CVSS tells you how severe a vulnerability is, not how urgent it is. The action score also accounts for what’s happening in the wild.
Formula
action = CVSS × 4 + (30 if KEV) + EPSS × 30 max 40 max 30 max 30CVSS
max 40Technical severity
How severe is the vulnerability itself? The CVSS base score is multiplied by 4. A flaw scoring 9.8 out of 10 contributes 39 points.
CISA KEV
max 30Exploited in the wild
The US Cybersecurity and Infrastructure Security Agency’s list of vulnerabilities confirmed to be actively exploited. Every CVE on the list gets 30 points.
EPSS
max 30Near-term likelihood
FIRST’s estimate of the probability of exploitation in the next 30 days. A 90% probability contributes 27 points.
Bands
- 80–100
- Now
- Patch today or shut off access.
- 60–79
- This week
- Don’t wait for the next maintenance window.
- 40–59
- Plan
- Add it to your regular patch cycle.
- 0–39
- Monitor
- Low priority for now; keep an eye on changes.
Example
A hypervisor flaw with CVSS 8.2 that requires local access, isn’t in KEV, and has a 5% EPSS: 33 + 0 + 2 = 35 · Monitor. A print server flaw with CVSS 7.5 whose EPSS jumped from 13% to 42% in a week: 30 + 0 + 13 = 43 · Plan, and it’s on the trending list. A team that only looks at CVSS patches the first one first.
Data sources
- NVDCVE records, CVSS vectors, CPE and CWE mappings
- CISA KEVCatalog of actively exploited vulnerabilities
- FIRST EPSSDaily exploitation probability estimates
- Vendor advisoriesAffected and fixed versions
Data comes from NVD, the CVE Program, CISA KEV, FIRST EPSS and OSV; the last update date is shown above the CVE list.
Our publishing principles
- Every record is published with detection and remediation guidance.
- We don’t publish working exploit code or step-by-step attack instructions.
- We don’t link to proof-of-concept repositories; we only note that one exists.
- Code samples are representative examples that show the flawed pattern and its fix.