Most Exploitable CVEs - EPSS Rankings

CVEs ranked by EPSS (Exploit Prediction Scoring System) probability. Higher scores mean a greater likelihood of exploitation in the wild within the next 30 days.

164
EPSS > 50%
156
CISA KEV Listed
35,468
CVEs with EPSS
0.7%
Avg EPSS Score
All Critical High Medium Low
Rank CVE ID EPSS Score Percentile CVSS Flags Summary
7701 CVE-2025-31412
0.14%
34.7th 6.5 This DOM-based cross-site scripting (XSS) vulnerability in the JetProductGallery WordPress plugin al
7702 CVE-2025-31043
0.14%
34.7th 6.5 This DOM-based Cross-Site Scripting (XSS) vulnerability in the JetSearch WordPress plugin allows att
7703 CVE-2025-30987
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the JetBlocks For Elementor WordPress plugin
7704 CVE-2025-31465
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Better Section Navigation Widget WordPre
7705 CVE-2025-31452
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in WP Ultimate Search WordPress plugin allows a
7706 CVE-2025-31450
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the phantom.omaga Toggle Box WordPress plugi
7707 CVE-2025-31433
0.14%
34.7th 6.5 A stored cross-site scripting (XSS) vulnerability in the Magic Embeds WordPress plugin allows attack
7708 CVE-2025-31096
0.14%
34.7th 6.5 This DOM-based Cross-Site Scripting (XSS) vulnerability in the PostX WordPress plugin allows attacke
7709 CVE-2025-31093
0.14%
34.7th 6.5 This vulnerability allows attackers to inject malicious scripts into web pages generated by the RPS
7710 CVE-2025-31088
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Paid Member Subscriptions WordPress plug
7711 CVE-2025-31073
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Unlimited WordPress theme allows attacke
7712 CVE-2025-31092
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Click to Chat WordPress plugin allows at
7713 CVE-2025-26736
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the MorningTime Lite WordPress theme allows
7714 CVE-2025-26732
0.14%
34.7th 6.5 This DOM-based Cross-Site Scripting (XSS) vulnerability in the StoreBiz WordPress theme allows attac
7715 CVE-2025-30925
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in The Pack Elementor addons WordPress plugin a
7716 CVE-2025-30922
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Simplebooklet PDF Viewer and Embedder Wo
7717 CVE-2025-30920
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the WP Posts Carousel WordPress plugin allow
7718 CVE-2025-30900
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in Zoho Billing - Embed Payment Form allows att
7719 CVE-2025-30898
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Persian WooCommerce Shipping WordPress p
7720 CVE-2025-30893
0.14%
34.7th 6.5 This DOM-based Cross-Site Scripting (XSS) vulnerability in the LeadConnector WordPress plugin allows
7721 CVE-2025-30836
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the LatePoint WordPress plugin allows attack
7722 CVE-2025-30832
0.14%
34.7th 6.5 This DOM-based Cross-Site Scripting (XSS) vulnerability in the Themify Event Post WordPress plugin a
7723 CVE-2025-30826
0.14%
34.7th 6.5 This DOM-based cross-site scripting vulnerability in the IP Locator WordPress plugin allows attacker
7724 CVE-2025-30813
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Listamester WordPress plugin allows atta
7725 CVE-2025-30786
0.14%
34.7th 6.5 This DOM-based Cross-Site Scripting (XSS) vulnerability in the Quotes llama WordPress plugin allows
7726 CVE-2025-30779
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Doneren met Mollie WordPress plugin allo
7727 CVE-2025-30776
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Sitekit WordPress plugin allows attacker
7728 CVE-2025-30770
0.14%
34.7th 6.5 This DOM-based Cross-Site Scripting (XSS) vulnerability in the Charitable WordPress plugin allows at
7729 CVE-2025-30768
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the WordPress jAlbum Bridge plugin allows at
7730 CVE-2025-30766
0.14%
34.7th 6.5 This DOM-based cross-site scripting (XSS) vulnerability in Happy Addons for Elementor allows attacke
7731 CVE-2025-28885
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Fiverr.com Official Search Box WordPress
7732 CVE-2025-26869
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Build WordPress theme allows attackers t
7733 CVE-2025-26739
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the newseqo WordPress theme allows attackers
7734 CVE-2025-30551
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the WordPress Pretty file links plugin allow
7735 CVE-2025-29922
0.14%
34.7th 9.6 This vulnerability in kcp allows attackers to create or delete objects in any arbitrary target works
7736 CVE-2024-8616
0.14%
34.7th 8.2 This vulnerability allows authenticated attackers to overwrite arbitrary files on the server hosting
7737 CVE-2024-6982
0.14%
34.7th 8.4 A remote code execution vulnerability in parisneo/lollms version 9.8 allows attackers to bypass Pyth
7738 CVE-2025-0118
0.14%
34.6th 8.0 A vulnerability in Palo Alto Networks GlobalProtect app on Windows allows remote attackers to execut
7739 CVE-2024-41770
0.14%
34.5th 7.5 This vulnerability in IBM Engineering Requirements Management DOORS Next allows remote attackers to
7740 CVE-2025-2771
0.14%
34.7th 5.3 This vulnerability allows remote attackers to bypass authentication on BEC Technologies routers with
7741 CVE-2025-24550
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the JobScore Job Manager WordPress plugin al
7742 CVE-2025-22771
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the WordPress plugin 'The Great Firewords of
7743 CVE-2025-39582
0.14%
34.7th 6.5 This DOM-based cross-site scripting (XSS) vulnerability in the WP Data Access WordPress plugin allow
7744 CVE-2025-39579
0.14%
34.7th 6.5 This DOM-based XSS vulnerability in WP Swings Membership For WooCommerce allows attackers to inject
7745 CVE-2025-39577
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in PropertyHive WordPress plugin allows attacke
7746 CVE-2025-39575
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in WPSight WPCasa WordPress plugin allows attac
7747 CVE-2025-39573
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the WP Posts Carousel WordPress plugin allow
7748 CVE-2025-39555
0.14%
34.7th 6.5 This vulnerability allows attackers to inject malicious scripts into Church Admin WordPress plugin p
7749 CVE-2025-39549
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Most And Least Read Posts Widget WordPre
7750 CVE-2025-39543
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Royal Elementor Addons WordPress plugin

What is EPSS?

The Exploit Prediction Scoring System (EPSS) is a data-driven model developed by FIRST.org that estimates the probability a CVE will be exploited in the wild within the next 30 days. Unlike CVSS which measures severity, EPSS measures likelihood of exploitation — making it ideal for prioritizing which vulnerabilities to patch first.

Why EPSS matters: With thousands of CVEs published monthly, not all vulnerabilities are equally dangerous. EPSS helps security teams focus on the CVEs most likely to be actively exploited, rather than patching solely by CVSS score. A critical CVSS 9.8 vulnerability with 0.1% EPSS may be less urgent than a high CVSS 7.5 with 90% EPSS.

Prioritize by Exploit Risk

Scan your servers and see which vulnerabilities have the highest EPSS scores. Focus on what attackers are actually targeting.

Start Monitoring Free