Top-1,000 EPSS exploit-risk CVEs, daily
Daily top-1,000 CVEs ranked by FIRST.org EPSS predicted 30-day exploitation probability (keyless public API, free to use with attribution): one row per CVE with the calibrated probability, the population percentile, a fixed risk band, the global rank and the score date. The forward-looking complement to kev_priority_signals (KEV-listed CVEs only): join asset inventories on cve to prioritize patching by predicted exploitation.
- Rows
- 1,000
- Columns
- 10
- Source cadence
- Daily
- Last refreshed
- Oct 3, 2026
- Theme
- technology
| Column | Type | Description |
|---|---|---|
| cve | string | CVE identifier (CVE-YYYY-NNNN). |
| cve_year | integer | Disclosure year from the CVE id. (unit: year) |
| cve_url | string | Canonical CVE.org record URL. |
| exploit_probability | float | EPSS calibrated probability (0-1) of observed exploitation activity for the CVE in the next 30 days; the model's primary output (per the EPSS FAQ). (unit: probability) |
| exploit_percentile | float | EPSS percentile: the CVE's rank against all currently scored vulnerabilities; e.g. 0.99 means a higher score than 99% of scored CVEs (per the EPSS FAQ). (unit: percentile) |
| risk_band | string | Fixed catalog risk band from the probability (critical >= 0.9, high >= 0.7, medium >= 0.5, low < 0.5 — same cuts as kev_priority_signals). EPSS itself defines no bands; these are the catalog's own fixed cuts. |
| risk_rank | integer | 1-based global rank by exploit_probability desc. (unit: rank) |
| top_100_flag | boolean | True for the top-100 highest-probability CVEs. |
| epss_score_date | string | EPSS model run date the scores were published for (ISO date). (unit: date) |
| row_hash | string | Deterministic 12-hex row identity hash (cve|epss_score_date). |
First 10 sample rows — a preview, not the complete dataset.
| cve | cve_year | cve_url | exploit_probability | exploit_percentile | risk_band | risk_rank | top_100_flag | epss_score_date | row_hash |
|---|---|---|---|---|---|---|---|---|---|
| CVE-2024-7593 | 2,024 | https://www.cve.org/CVERecord?id=CVE-2024-7593 | 1 | 1 | critical | 1 | true | 2026-10-03 | 232df244e418 |
| CVE-2024-3400 | 2,024 | https://www.cve.org/CVERecord?id=CVE-2024-3400 | 1 | 1 | critical | 2 | true | 2026-10-03 | 9a926cf6fe43 |
| CVE-2024-23897 | 2,024 | https://www.cve.org/CVERecord?id=CVE-2024-23897 | 1 | 1 | critical | 3 | true | 2026-10-03 | 7337bc2c380b |
| CVE-2024-21893 | 2,024 | https://www.cve.org/CVERecord?id=CVE-2024-21893 | 1 | 1 | critical | 4 | true | 2026-10-03 | 0e5fff298eb9 |
| CVE-2024-21887 | 2,024 | https://www.cve.org/CVERecord?id=CVE-2024-21887 | 1 | 1 | critical | 5 | true | 2026-10-03 | 58bb59b7564a |
| CVE-2023-4966 | 2,023 | https://www.cve.org/CVERecord?id=CVE-2023-4966 | 1 | 1 | critical | 6 | true | 2026-10-03 | 7264186e9969 |
| CVE-2023-44487 | 2,023 | https://www.cve.org/CVERecord?id=CVE-2023-44487 | 1 | 1 | critical | 7 | true | 2026-10-03 | 3aac4eaff97b |
| CVE-2023-35082 | 2,023 | https://www.cve.org/CVERecord?id=CVE-2023-35082 | 1 | 1 | critical | 8 | true | 2026-10-03 | 93d75f7381ec |
| CVE-2023-35078 | 2,023 | https://www.cve.org/CVERecord?id=CVE-2023-35078 | 1 | 1 | critical | 9 | true | 2026-10-03 | 59638f7eae41 |
| CVE-2023-32315 | 2,023 | https://www.cve.org/CVERecord?id=CVE-2023-32315 | 1 | 1 | critical | 10 | true | 2026-10-03 | 772f0f114195 |
- Current
20261003T181406Z-3cff0a7cbc13 · sha256 3cff0a7cbc13…
1,000 rows · first snapshot
Point any LLM at the metadata endpoint — the documentation above is machine-readable too (JSON-LD + Croissant).
curl "https://datazimuts.com/v1/datasets/epss_exploit_risk_intel/epss_top_exploit_risk_daily" | jq '{title, rows, columns_count, license}'import requests
ds = requests.get("https://datazimuts.com/v1/datasets/epss_exploit_risk_intel/epss_top_exploit_risk_daily").json()
print(ds["title"], ds["rows"], "rows")
# Sample rows for an LLM context window
for row in ds.get("sample_rows", [])[:5]:
print(row)API endpoint: https://datazimuts.com/v1/datasets/epss_exploit_risk_intel/epss_top_exploit_risk_daily
Tip: fetch /llms.txt for the full machine-readable catalog.
Where this data comes from and what was made from it. Other people's work shows as counts; only shared projects are named.
Cite this snapshot
Pinned to snapshot 20261003T181406Z-3cff0a7cbc13 and its content hash, so readers get exactly the data you used.
FIRST.org EPSS exploit-risk intelligence. (2026). Top-1,000 EPSS exploit-risk CVEs, daily [Data set, snapshot 20261003T181406Z-3cff0a7cbc13, sha256 3cff0a7cbc13]. Datazimuts. Retrieved 2026-10-05, from https://datazimuts.com/en/datasets/epss_exploit_risk_intel/epss_top_exploit_risk_daily?snapshot=20261003T181406Z-3cff0a7cbc13
@misc{dz_epss_exploit_risk_intel_epss_top_exploit_3cff0a7c,
title = {{Top-1,000 EPSS exploit-risk CVEs, daily}},
author = {{FIRST.org EPSS exploit-risk intelligence}},
year = {2026},
publisher = {Datazimuts},
howpublished = {\url{https://datazimuts.com/en/datasets/epss_exploit_risk_intel/epss_top_exploit_risk_daily?snapshot=20261003T181406Z-3cff0a7cbc13}},
note = {Snapshot 20261003T181406Z-3cff0a7cbc13, sha256 3cff0a7cbc135741e7bc7b88e2580a6a79ff5c1a5b799b8e1b521856cb231b5a; accessed 2026-10-05}
}Embed a table or a chart
Paste this into any page. The embed is pinned to the same snapshot, follows the reader's light or dark setting, and always shows the source, license and a link back.
<iframe src="https://datazimuts.com/embed/chart?dataset=epss_exploit_risk_intel%2Fepss_top_exploit_risk_daily&lang=en&theme=auto&snapshot=20261003T181406Z-3cff0a7cbc13&x=cve_year&y=cve_year&agg=avg" title="Top-1,000 EPSS exploit-risk CVEs, daily" width="100%" height="380" style="border:0" loading="lazy"></iframe>
Ask about this dataset. Answers come only from its catalog record, measured profile and change history, and list the facts they used.