Chat with AI and run tools instantly.
The Exploit Prediction Scoring System (EPSS) by FIRST.org estimates the probability that a CVE will be exploited in the wild within 30 days. Look up exploit scores for specific CVEs, discover the most exploitable vulnerabilities, track score trends over time, and filter by score or percentile ranges for risk prioritization.
Live probe refreshed Sep 14, 2026 · Endpoint host mcp.mcpbundles.com
Domain knowledge for EPSS — workflow patterns, data models, and gotchas for your AI agent.
The Exploit Prediction Scoring System (EPSS) by FIRST.org estimates the probability a CVE will be exploited within 30 days. Prioritize remediation by exploit likelihood.
Most Exploitable
Discover the most exploitable CVEs by EPSS score. Filter by minimum/maximum exploit probability to find vulnerabilities most likely to be exploited in the wild. Results are sorted by score descending. Use min_score=0.9 for critical-risk CVEs, 0.5 for moderate-and-above.
Risk Report
Generate a threat landscape report showing how many CVEs fall into each EPSS risk band (CRITICAL/HIGH/MEDIUM/LOW). Provides total counts at each threshold without listing individual CVEs. Optionally scope to a CVE year or pattern. Use this for executive-level risk summaries.
Score At Date
Connect EPSS to any MCP client in minutes
Opens ChatGPT on the web or desktop and asks it to use the WebMCP tools available here.
You’ll sign in to MCPBundles when your client connects.
https://mcp.mcpbundles.com/bundle/epssSign in once, then chat here with saved access — one connection to many servers, with a history of what your AI ran.
Chat with AI and run tools instantly.
Browse all toolsGet the EPSS exploit prediction score for a CVE at a specific historical date. Useful for understanding how exploit risk has evolved, or for retrospective analysis of vulnerability prioritization decisions.
Score By Percentile
Find CVEs by EPSS percentile ranking. The percentile shows where a CVE ranks relative to all other scored CVEs. A percentile of 0.99 means the CVE has a higher exploit probability than 99% of all CVEs. Results are sorted by EPSS score descending.
Score History
Get the 30-day EPSS score trend for a specific CVE. Shows how the exploit prediction probability has changed over the past month. Useful for identifying rising threats or confirming score stability.
Score Lookup
Look up EPSS exploit prediction scores for one or more CVEs. Returns the probability (0-1) that each CVE will be exploited in the wild within 30 days, plus its percentile ranking among all scored CVEs. Accepts comma-separated CVE IDs for batch lookups.
Search
Search the EPSS database by CVE ID pattern. Find all scored CVEs matching a text pattern — useful for year-based analysis (e.g., 'CVE-2025'), vendor-range exploration, or finding CVEs when you only know a partial ID. Combine with min_score to filter for high-risk matches only.
Triage
Triage a list of CVEs from a vulnerability scan by exploit probability. Pass in CVE IDs from a scan report and get back a prioritized remediation plan grouped by risk level (CRITICAL/HIGH/MEDIUM/LOW) with the most exploitable vulnerabilities first. Designed for bulk prioritization of scan results.
The Exploit Prediction Scoring System (EPSS) by FIRST.org estimates the probability that a CVE will be exploited in the wild within 30 days. Look up exploit scores for specific CVEs, discover the most exploitable vulnerabilities, track score trends over time, and filter by score or percentile ranges for risk prioritization. It provides 8 tools that AI agents can use through the Model Context Protocol (MCP).
Add the MCPBundles server URL to your MCP client configuration (Claude Desktop, Cursor, VS Code, etc.). The URL format is: https://mcp.mcpbundles.com/bundle/epss. Authentication is handled automatically.
© 2026 ThinkChain Inc. All rights reserved.
EPSS provides 8 tools that can be called by AI agents, along with a SKILL.md that gives your AI agent domain knowledge about when and how to use them.
EPSS uses open data APIs — no authentication required.
MCPBundles is an independent platform built on the open Model Context Protocol standard. Not affiliated with Anthropic PBC or Claude.
Other MCP servers in this category from the directory index
OPUSWatch provides API-based solutions for managing operational risk and ensuring regulatory complia...
12 tools