How to hit the FIRST EPSS API

EPSS from FIRST at https://api.first.org/data/v1/epss estimates the probability a CVE will be exploited in the next 30 days, updated daily.

Authentication

None — no key, no signup. Every example runs as-is.

Full reference: https://www.first.org/epss/api

Score for a CVE

epss is the probability; percentile ranks it against all CVEs.

curl "https://api.first.org/data/v1/epss?cve=CVE-2021-44228"
Run in PostTaco
Example response (trimmed)
{
  "status": "OK",
  "status-code": 200,
  "version": "1.0",
  "access": "public",
  "total": 1,
  "offset": 0,
  "limit": 100,
  "data": [
    {
      "cve": "CVE-2021-44228",
      "epss": "0.999990000",
      "percentile": "1.000000000",
      "date": "2026-09-23"
    }
  ]
}

Highest-scoring CVEs

curl "https://api.first.org/data/v1/epss?order=!epss&limit=2"
Run in PostTaco
Example response (trimmed)
{
  "status": "OK",
  "status-code": 200,
  "version": "1.0",
  "access": "public",
  "total": 378156,
  "offset": 0,
  "limit": 2,
  "data": [
    {
      "cve": "CVE-2024-3400",
      "epss": "0.999990000",
      "percentile": "1.000000000",
      "date": "2026-09-23"
    },
    {
      "cve": "CVE-2024-23897",
      "epss": "0.999990000",
      "percentile": "0.999950000",
      "date": "2026-09-23"
    }
  ]
}