Predicting Global Software Vulnerabilities Using Open Security Databases and Machine Learning
Authors
Department of Computer Science Education, Federal College of Education (Technical), Umunze, Anambra State (Nigeria)
Department of Computer Science Education, Federal College of Education (Technical), Umunze, Anambra State (Nigeria)
Federal Polytechnic, Nasarawa, Nasarawa State (Nigeria)
Department of Physics Education, Federal College of Education (Technical), Umunze, Anambra State (Nigeria)
Department of Physics Education, Federal College of Education (Technical), Umunze, Anambra State (Nigeria)
Article Information
DOI: 10.51244/IJRSI.2026.1313CS014
Subject Category: Computer Science
Volume/Issue: 13/13 | Page No: 167-185
Publication Timeline
Submitted: 2026-06-11
Accepted: 2026-06-16
Published: 2026-06-30
Abstract
The rapid growth of publicly disclosed software vulnerabilities has made risk-based prioritisation essential because organisations cannot remediate every vulnerability immediately. This study developed a temporally validated machine-learning framework for predicting documented exploitation using the Exploit Prediction Scoring System and the Cybersecurity and Infrastructure Security Agency Known Exploited Vulnerabilities catalogue. The analytical cohort comprised 163,402 CVEs assigned to 2015–2023, including 1,049 KEV-labelled vulnerabilities and 162,353 non-KEV records. CVEs from 2015–2021 were used for training, 2022 records for validation and threshold selection, and the 2023 cohort for independent temporal testing. EPSS probability and percentile were evaluated directly and through logistic regression, support vector machine, random forest, XGBoost and CatBoost models. Performance was assessed using precision-recall area under the curve, ROC-AUC, precision, recall, F1-score, Matthews correlation coefficient, Brier score and recall at fixed remediation capacities. KEV-labelled vulnerabilities had substantially higher EPSS probabilities than non-KEV records, with median values of 0.79667 and 0.00291, respectively. On the 2023 test set, logistic regression and the calibrated support vector machine achieved the highest PR-AUC of 0.3764, only marginally exceeding direct EPSS ranking at 0.3763, while all three approaches produced a ROC-AUC of approximately 0.9086. The calibrated support vector machine achieved the lowest Brier score of 0.0047. Operationally, EPSS captured 45.40%, 68.71% and 77.91% of KEV-listed vulnerabilities within the highest-ranked 1%, 5% and 10% of the test cohort, respectively, and produced a lift of 13.74 at a 5% remediation capacity. Ablation analysis showed that EPSS probability and percentile accounted for nearly all predictive discrimination, whereas CVE year added little value and weakened calibration. The findings demonstrate that direct EPSS ranking provides an efficient and parsimonious basis for threat-informed vulnerability prioritisation under severe class imbalance. However, exploitation probability should complement, rather than replace, organisation-specific assessment of asset exposure, business criticality and existing security controls
Keywords
Software vulnerability; EPSS; CISA KEV; machine learning; vulnerability prioritisation; temporal validation; class imbalance
Downloads
References
1. Benjamini, Y., & Hochberg, Y. (1995). Controlling the false discovery rate: A practical and powerful approach to multiple testing. Journal of the Royal Statistical Society: Series B (Methodological), 57(1), 289–300. https://doi.org/10.1111/j.2517-6161.1995.tb02031.x [Google Scholar] [Crossref]
2. Brier, G. W. (1950). Verification of forecasts expressed in terms of probability. Monthly Weather Review, 78(1), 1–3. https://doi.org/10.1175/1520-0493(1950)078%3C0001:VOFEIT%3E2.0.CO;2 [Google Scholar] [Crossref]
3. Chicco, D., & Jurman, G. (2020). The advantages of the Matthews correlation coefficient over F1 score and accuracy in binary classification evaluation. BMC Genomics, 21, Article 6. https://doi.org/10.1186/s12864-019-6413-7 [Google Scholar] [Crossref]
4. Common Weakness Enumeration. (n.d.). Common Weakness Enumeration: A community-developed list of software and hardware weakness types. The MITRE Corporation. Retrieved June 11, 2026, from https://cwe.mitre.org/ [Google Scholar] [Crossref]
5. CVE Program. (n.d.). CVE Program overview. The MITRE Corporation. Retrieved June 11, 2026, from https://www.cve.org/About/Overview [Google Scholar] [Crossref]
6. Cybersecurity and Infrastructure Security Agency. (2026a). Known Exploited Vulnerabilities catalog [Data set]. Retrieved June 11, 2026, from https://www.cisa.gov/known-exploited-vulnerabilities-catalog [Google Scholar] [Crossref]
7. Cybersecurity and Infrastructure Security Agency. (2026b). Known Exploited Vulnerabilities catalog (Version 2026.06.11) [JSON data set]. https://github.com/cisagov/kev-data [Google Scholar] [Crossref]
8. Cybersecurity and Infrastructure Security Agency. (n.d.). Reducing the significant risk of known exploited vulnerabilities. Retrieved June 11, 2026, from https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities [Google Scholar] [Crossref]
9. Dimitriadis, T., Gneiting, T., & Jordan, A. I. (2021). Stable reliability diagrams for probabilistic classifiers. Proceedings of the National Academy of Sciences of the United States of America, 118(8), Article e2016191118. https://doi.org/10.1073/pnas.2016191118 [Google Scholar] [Crossref]
10. Forum of Incident Response and Security Teams. (2019). Common Vulnerability Scoring System version 3.1: Specification document. https://www.first.org/cvss/v3.1/specification-document [Google Scholar] [Crossref]
11. Forum of Incident Response and Security Teams. (2026a). Exploit Prediction Scoring System. Retrieved June 11, 2026, from https://www.first.org/epss/ [Google Scholar] [Crossref]
12. Forum of Incident Response and Security Teams. (2026b). EPSS scores for June 11, 2026 [CSV data set]. https://www.first.org/epss/data_stats [Google Scholar] [Crossref]
13. Forum of Incident Response and Security Teams. (2026c). The EPSS model. Retrieved June 11, 2026, from https://www.first.org/epss/model [Google Scholar] [Crossref]
14. Forum of Incident Response and Security Teams. (2026d). Understanding EPSS probabilities and percentiles. Retrieved June 11, 2026, from https://www.first.org/epss/articles/prob_percentile_bins [Google Scholar] [Crossref]
15. Jacobs, J., Romanosky, S., Edwards, B., Adjerid, I., & Roytman, M. (2021). Exploit Prediction Scoring System. Digital Threats: Research and Practice, 2(3), Article 20. https://doi.org/10.1145/3436242 [Google Scholar] [Crossref]
16. Jacobs, J., Romanosky, S., Suciu, O., Edwards, B., & Sarabi, A. (2023). Enhancing vulnerability prioritization: Data-driven exploit predictions with community-driven insights. In 2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW) (pp. 194–206). IEEE. https://doi.org/10.1109/EuroSPW59978.2023.00027 [Google Scholar] [Crossref]
17. Manning, C. D., Raghavan, P., & Schütze, H. (2008). Introduction to information retrieval. Cambridge University Press. https://doi.org/10.1017/CBO9780511809071 [Google Scholar] [Crossref]
18. Meyes, R., Lu, M., de Puiseau, C. W., & Meisen, T. (2019). Ablation studies in artificial neural networks. arXiv. https://doi.org/10.48550/arXiv.1901.08644 [Google Scholar] [Crossref]
19. National Institute of Standards and Technology. (2026a). National Vulnerability Database. Retrieved June 11, 2026, from https://nvd.nist.gov/ [Google Scholar] [Crossref]
20. National Institute of Standards and Technology. (2026b). National Vulnerability Database data feeds. Retrieved June 11, 2026, from https://nvd.nist.gov/vuln/data-feeds [Google Scholar] [Crossref]
21. National Institute of Standards and Technology. (2026c). NVD vulnerability APIs. Retrieved June 11, 2026, from https://nvd.nist.gov/developers/vulnerabilities [Google Scholar] [Crossref]
22. National Institute of Standards and Technology. (2026d). Understanding NVD vulnerability detail pages. Retrieved June 11, 2026, from https://nvd.nist.gov/vuln/vulnerability-detail-pages [Google Scholar] [Crossref]
23. National Institute of Standards and Technology. (2026e). Vulnerability metrics: Common Vulnerability Scoring System. Retrieved June 11, 2026, from https://nvd.nist.gov/vuln-metrics/cvss [Google Scholar] [Crossref]
24. National Institute of Standards and Technology. (2026f). NVD CVE modified feed: JSON 2.0 snapshot dated June 11, 2026 [Data set]. National Vulnerability Database. [Google Scholar] [Crossref]
25. Platt, J. C. (2000). Probabilistic outputs for support vector machines and comparisons to regularized likelihood methods. In A. J. Smola, P. L. Bartlett, B. Schölkopf, & D. Schuurmans (Eds.), Advances in large margin classifiers (pp. 61–74). MIT Press. [Google Scholar] [Crossref]
26. Saito, T., & Rehmsmeier, M. (2015). The precision-recall plot is more informative than the ROC plot when evaluating binary classifiers on imbalanced datasets. PLOS ONE, 10(3), Article e0118432. https://doi.org/10.1371/journal.pone.0118432 [Google Scholar] [Crossref]
27. Souppaya, M., & Scarfone, K. (2022). Guide to enterprise patch management planning: Preventive maintenance for technology (NIST Special Publication 800-40 Revision 4). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-40r4 [Google Scholar] [Crossref]
28. Sperandei, S. (2014). Understanding logistic regression analysis. Biochemia Medica, 24(1), 12–18. https://doi.org/10.11613/BM.2014.003 [Google Scholar] [Crossref]
Metrics
Views & Downloads
Similar Articles
- What the Desert Fathers Teach Data Scientists: Ancient Ascetic Principles for Ethical Machine-Learning Practice
- Comparative Analysis of Some Machine Learning Algorithms for the Classification of Ransomware
- Comparative Performance Analysis of Some Priority Queue Variants in Dijkstra’s Algorithm
- Transfer Learning in Detecting E-Assessment Malpractice from a Proctored Video Recordings.
- Dual-Modal Detection of Parkinson’s Disease: A Clinical Framework and Deep Learning Approach Using NeuroParkNet