How likely is each flaw to be attacked?

EPSS - the Exploit Prediction Scoring System - estimates the chance that a known software flaw will actually be attacked in the next 30 days. It answers 'will anyone try this?', which is a different question from 'how much damage would it do?'.

Flaws with a forecast
Very likely to be attacked
Likely to be attacked
Forecasts that moved

Attack likelihood, band by band

How every scored flaw splits across the likelihood bands

The same picture, as a chart

Most flaws sit on the left: unlikely to be attacked. The few on the right are the ones to watch.