Most Exploitable CVEs - EPSS Rankings

CVEs ranked by EPSS (Exploit Prediction Scoring System) probability. Higher scores mean a greater likelihood of exploitation in the wild within the next 30 days.

164
EPSS > 50%
156
CISA KEV Listed
35,468
CVEs with EPSS
0.7%
Avg EPSS Score
All Critical High Medium Low
Rank CVE ID EPSS Score Percentile CVSS Flags Summary
7751 CVE-2025-39529
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Scriptless Social Sharing WordPress plug
7752 CVE-2025-39525
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the WordPress Logo Carousel Slider plugin al
7753 CVE-2025-39516
0.14%
34.7th 6.5 This DOM-based XSS vulnerability in the Author WIP Progress Bar WordPress plugin allows attackers to
7754 CVE-2025-39514
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in Asgaros Forum allows attackers to inject mal
7755 CVE-2025-30982
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the MyBookProgress WordPress plugin allows a
7756 CVE-2025-26951
0.14%
34.7th 6.5 This DOM-based Cross-Site Scripting (XSS) vulnerability in the C9 Blocks WordPress plugin allows att
7757 CVE-2025-26934
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Glossy Blog WordPress theme allows attac
7758 CVE-2025-26870
0.14%
34.7th 6.5 This DOM-based Cross-Site Scripting (XSS) vulnerability in the JetEngine WordPress plugin allows att
7759 CVE-2025-26749
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the WPFactory Additional Custom Product Tabs
7760 CVE-2025-22269
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Real Testimonials WordPress plugin allow
7761 CVE-2025-26982
0.14%
34.7th 6.5 This DOM-based Cross-Site Scripting (XSS) vulnerability in the DSGVO Youtube WordPress plugin allows
7762 CVE-2025-26744
0.14%
34.7th 6.5 This DOM-based Cross-Site Scripting (XSS) vulnerability in the JetBlog WordPress plugin allows attac
7763 CVE-2025-32214
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Hive Support WordPress plugin allows att
7764 CVE-2025-32495
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Waymark WordPress plugin allows attacker
7765 CVE-2025-31020
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Simple Spoiler WordPress plugin allows a
7766 CVE-2025-32211
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Broadstreet WordPress plugin allows atta
7767 CVE-2025-32207
0.14%
34.7th 6.5 This vulnerability allows attackers to inject malicious scripts into web pages generated by the Ni W
7768 CVE-2025-32194
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in LA-Studio Element Kit for Elementor allows a
7769 CVE-2025-32192
0.14%
34.7th 6.5 This stored Cross-Site Scripting (XSS) vulnerability in Ultra Addons Lite for Elementor allows attac
7770 CVE-2025-32190
0.14%
34.7th 6.5 This DOM-based cross-site scripting (XSS) vulnerability in the Musician's Pack for Elementor WordPre
7771 CVE-2025-32188
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Advanced Woo Labels WordPress plugin all
7772 CVE-2025-32186
0.14%
34.7th 6.5 This DOM-based Cross-Site Scripting (XSS) vulnerability in Turbo Addons for Elementor allows attacke
7773 CVE-2025-32184
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Ultimate Store Kit Elementor Addons Word
7774 CVE-2025-32182
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Spider Elements WordPress plugin allows
7775 CVE-2025-32179
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Maps for WP WordPress plugin allows atta
7776 CVE-2025-32177
0.14%
34.7th 6.5 A stored cross-site scripting (XSS) vulnerability in the pgn4web Embed Chessboard WordPress plugin a
7777 CVE-2025-32175
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in VK Filter Search WordPress plugin allows att
7778 CVE-2025-32173
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the B Blocks WordPress plugin allows attacke
7779 CVE-2025-32171
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Table Block by Tableberg WordPress plugi
7780 CVE-2025-32167
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in SurveyJS allows attackers to inject maliciou
7781 CVE-2025-32165
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Doppler Forms WordPress plugin allows at
7782 CVE-2025-32162
0.14%
34.7th 6.5 This vulnerability allows attackers to inject malicious scripts into web pages viewed by other users
7783 CVE-2025-31407
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Tiger WordPress theme allows attackers t
7784 CVE-2025-31126
0.14%
34.6th 5.3 An attacker controlling the element.json well-known file can potentially access media encryption key
7785 CVE-2025-31893
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Botnet Attack Blocker WordPress plugin a
7786 CVE-2025-31819
0.14%
34.7th 6.5 This Cross-site Scripting (XSS) vulnerability in the Nova Blocks WordPress plugin allows attackers t
7787 CVE-2025-31897
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Arrow Custom Feed for Twitter WordPress
7788 CVE-2025-31894
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in Infoway LLC's Ebook Downloader WordPress plu
7789 CVE-2025-31891
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Gosign Posts Slider Block WordPress plug
7790 CVE-2025-31884
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the WordPress Norse Rune Oracle plugin allow
7791 CVE-2025-31875
0.14%
34.7th 6.5 This DOM-based cross-site scripting (XSS) vulnerability in the FancyPost WordPress plugin allows att
7792 CVE-2025-31873
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the SheetDB WordPress plugin allows attacker
7793 CVE-2025-31869
0.14%
34.7th 6.5 This stored Cross-Site Scripting (XSS) vulnerability in the Black Widgets For Elementor WordPress pl
7794 CVE-2025-31861
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Perfect Font Awesome Integration WordPre
7795 CVE-2025-31850
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the PDF Generator Addon for Elementor Page B
7796 CVE-2025-31844
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in the Magical Blocks WordPress plugin allows a
7797 CVE-2025-31835
0.14%
34.7th 6.5 This vulnerability allows attackers to inject malicious scripts into web pages generated by the WP P
7798 CVE-2025-31829
0.14%
34.7th 6.5 This DOM-based cross-site scripting vulnerability in the ShopCred WordPress plugin allows attackers
7799 CVE-2025-31823
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in WPoperation Elementor Addons allows attacker
7800 CVE-2025-31818
0.14%
34.7th 6.5 This stored cross-site scripting (XSS) vulnerability in ContentBot AI Writer WordPress plugin allows

What is EPSS?

The Exploit Prediction Scoring System (EPSS) is a data-driven model developed by FIRST.org that estimates the probability a CVE will be exploited in the wild within the next 30 days. Unlike CVSS which measures severity, EPSS measures likelihood of exploitation — making it ideal for prioritizing which vulnerabilities to patch first.

Why EPSS matters: With thousands of CVEs published monthly, not all vulnerabilities are equally dangerous. EPSS helps security teams focus on the CVEs most likely to be actively exploited, rather than patching solely by CVSS score. A critical CVSS 9.8 vulnerability with 0.1% EPSS may be less urgent than a high CVSS 7.5 with 90% EPSS.

Prioritize by Exploit Risk

Scan your servers and see which vulnerabilities have the highest EPSS scores. Focus on what attackers are actually targeting.

Start Monitoring Free