CVE Priority Checker
Turn a list of CVEs into an explained remediation queue using CVSS, CISA KEV and FIRST EPSS.
CVE identifiers (up to 20)
How it works
CISA KEV listings come first, followed by EPSS estimates of at least 10%, then critical and high CVSS severity. The 10% threshold is a CyberWorldOps triage rule, not an official FIRST category. EPSS estimates exploitation in the next 30 days; CVSS describes severity. They answer different questions.
Use this queue alongside exposure, asset importance, affected versions and vendor guidance. When our CVE mirror has no record, KEV membership is checked against the official CISA catalog, cached for up to ten minutes. Unavailable data stays unknown. CISA deadlines apply to covered US federal agencies. EPSS queries send the entered CVE identifiers to FIRST. Results can be reused from a five-minute cache; their check time and EPSS date are shown.