The CISA KEV catalog tracks vulnerabilities attackers are exploiting right now, not theoretical flaws sitting in a lab. Every CVE listed here is an active risk for any organisation still running the affected software unpatched.
EPSS (Exploit Prediction Scoring System) is a score between 0 and 100% estimating the probability that a given vulnerability will be exploited in the wild within the next 30 days. It complements KEV, which only confirms exploitation that has already happened : EPSS can flag a vulnerability as high-risk before it ever reaches KEV. Trend arrows need a few days of accumulated history to appear, and become meaningful over the following weeks.
Data is aggregated automatically from public sources.