• Home  
  • EPSS, a GitHub PoC or a Nuclei Template: Which Warns First?

EPSS, a GitHub PoC or a Nuclei Template: Which Warns First?

Measured 2026-09-28 against the live CISA KEV catalogue (1,728 entries), the FIRST EPSS scores of 2025-09-28, 10,937 CVEs with public proof-of-concept repositories on GitHub, and 4,625 CVEs with a template in the Nuclei scanner’s public repository. Every number on this page is recomputed from those sources when the page rebuilds. Part three of a series, after the EPSS study and the GitHub PoC study.

The question

Defenders have three free, public early-warning signals for a vulnerability that is about to be exploited: a high EPSS score, a proof-of-concept exploit on GitHub, and a template for Nuclei, the open-source scanner that both security teams and attackers use to sweep the internet for a specific flaw. A Nuclei template means checking millions of hosts for that CVE takes one command.

Each signal has been studied on its own. Coverage figures exist — the CISA-KEV tracker by rxerium follows how much of the catalogue Nuclei can scan, and runZero’s KEVology looked at exploit timelines. What we could not find published is the forward-looking scoreboard: take every CVE a year ago, note which signals it already had, and count how many CISA went on to confirm as exploited. That is what this page measures, with all three signals on the same population.

Half 1 — when CISA confirms exploitation, was the signal already there?

CISA added 547 vulnerabilities to KEV in the last two years. For each one we took the date the first Nuclei template for it landed in the public repository, and the date of the first public GitHub PoC repository.

First appeared Nuclei template GitHub PoC
Before CISA listed it 21% 33%
Same day 1% 4%
After CISA listed it 15% 23%
Never, to date 63% 40%
Median lead, when it came first 35 days 40 days
Median delay, when it came after 14 days 4 days

63% of the vulnerabilities CISA confirmed in the last two years have never had a Nuclei template, against 40% with no public GitHub PoC. When a template did exist before the listing (21% of cases), it arrived a median 35 days early. When it came after, it took a median 14 days — slower than GitHub PoCs, which followed a listing by a median 4 days.

Half 2 — the scoreboard, one year ahead

We went back to 2025-09-28 and took every CVE that EPSS scored that day and CISA had not yet listed: 294,493 vulnerabilities. Over the following year, 94 of them (0.032%) were added to KEV. For each signal, the table shows how many CVEs it flagged on that day, how often those went on to be confirmed, and what share of the year’s 94 confirmations it had flagged in advance.

Signal a year ago CVEs flagged Share of all CVEs Reached KEV Hit rate vs. all CVEs Caught in advance
EPSS > 0.9 779 0.26% 11 1.41% 44.2× 12%
Public GitHub PoC 6,374 2.16% 36 0.56% 17.7× 38%
Nuclei template 2,997 1.02% 19 0.63% 19.9× 20%
Nuclei template + GitHub PoC 730 0.25% 12 1.64% 51.5× 13%
Any of the three 8,736 2.97% 47 0.54% 16.9× 50%
All three 362 0.12% 5 1.38% 43.3× 5%
None of the three 285,757 97.03% 47 0.02% 0.5× 50%

No single signal sees most of it coming. A public GitHub PoC flagged 38% of the year’s confirmations, a Nuclei template 20%, and EPSS above 0.9 12%. Watching all three together flagged 8,736 CVEs — 3.0% of the population — and caught 50%. The other 50% showed none of the three signals a year before CISA confirmed them.

A Nuclei template is the narrower of the two exploit signals: 2,997 CVEs had one, against 6,374 with a GitHub PoC. Its hit rate (0.63%) was similar to the PoC’s (0.56%), so it caught less. The best hit rate on the page belongs to Nuclei template + GitHub PoC: 1.64%, or 51.5 times the rate for an average CVE. It rests on 12 confirmations, so read the exact figure as a direction rather than a constant.

What this means for triage

  • Stack the signals. Each one alone missed most of what followed; together they flagged about 3% of CVEs and caught about 50% of the next year’s confirmations. Filtered to the products you actually run, that list gets much shorter.
  • The strongest public signal on this page was Nuclei template + GitHub PoC. When it appears, move the CVE up the queue.
  • Absence is not reassurance. 63% of recently confirmed vulnerabilities never got a Nuclei template, and about 50% of next year’s confirmations had no public signal a year ahead. Knowing which of your products face the internet has to cover that half.
  • KEV itself is the one list that is always actionable. Our daily KEV tracker and EPSS watchlist update every day.

Method and limits

  • Nuclei templates are detection checks, not exploits. They are community-written, and many are written in response to exploitation news. This page measures when public mass-scanning capability existed, not who used it.
  • Template date is the commit date when a template for the CVE first landed in the repository’s main branch, on any path — the 2023 move of templates into new folders does not reset it. A template can exist in a pull request earlier.
  • “Had a template a year ago” means it was in the repository tree on that day (commit 2fe61c4199); templates deleted before then are not counted.
  • GitHub PoC data comes from the PoC-in-GitHub index and counts repositories, not verified exploits; deleted repositories are missing. We do not link to any PoC.
  • KEV is CISA’s confirmation, not all exploitation, and Half 2 covers only CVEs that already existed a year ago. Combination rows rest on small counts.
  • Consistency check: the EPSS and GitHub PoC rows are computed again here with separate code and must match our GitHub PoC study for the same date, or the page is not published.

Sources: CISA KEV catalogue, FIRST EPSS, PoC-in-GitHub and nuclei-templates. Recomputed monthly; last run 2026-09-28.

About AI Post Daily

Independent coverage of artificial intelligence, machine learning, cybersecurity, and the technology shaping our future.

Contact: Get in touch

Known Exploited Vulnerabilities Tracker·Exploit Likelihood Watchlist·Original Research·AI Attack Tracker·CVE Remediation Guides — updated daily

How we research, write and correct our reporting — editorial policy

Security Guides

We use cookies to personalize content and ads, and to analyze traffic. By using this site, you agree to our Privacy Policy.