Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,996 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
17,157 results · page 312 of 344
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2005-3560 | Zone Labs (1) ZoneAlarm Pro 6.0, (2) ZoneAlarm Internet Security Suite 6.0, (3) ZoneAlarm Anti-Virus 6.0, (4) ZoneAlarm Anti-Spyware 6.0 through 6.1, and (5) ZoneAlarm 6.0 allow remote attackers to bypass the "Advanced Program Control and OS Firewall… | EXPLOIT ✓HIGH 7.5EPSS 15.5% | 16 November 2005 |
| CVE-2005-3559 | Directory traversal vulnerability in vmail.cgi in Asterisk 1.0.9 through 1.2.0-beta1 allows remote attackers to access WAV files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 20.2% | 16 November 2005 |
| CVE-2005-3524 | Buffer overflow in the SSL-ready version of linux-ftpd (linux-ftpd-ssl) 0.17 allows remote attackers to execute arbitrary code by creating a long directory name, then executing the XPWD command. | EXPLOIT ✓HIGH 10.0EPSS 21.5% | 7 November 2005 |
| CVE-2005-3507 | Directory traversal vulnerability in CuteNews 1.4.1 allows remote attackers to include arbitrary files, execute code, and gain privileges via "../" sequences in the template parameter to (1) show_archives.php and (2) show_news.php. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 12.4% | 6 November 2005 |
| CVE-2005-3498 | IBM WebSphere Application Server 5.0.x before 5.02.15, 5.1.x before 5.1.1.8, and 6.x before fixpack V6.0.2.5, when session trace is enabled, records a full URL including the queryString in the trace logs when an application encodes a URL, which could… | MEDIUM 4.3EPSS 11.2% | 4 November 2005 |
| CVE-2005-3488 | Scorched 3D 39.1 (bf) and earlier allows remote attackers to cause a denial of service (long loop and server hang) via a negative numplayers value that bypasses a signed check in ServerConnectHandler.cpp. | EXPLOIT ✓HIGH 7.8EPSS 10.1% | 3 November 2005 |
| CVE-2005-3486 | Multiple format string vulnerabilities in Scorched 3D 39.1 (bf) and earlier allow remote attackers to execute arbitrary code via various (1) GLConsole::addLine, (2) ServerCommon::sendString, (3) ServerCommon::serverLog functions, and possibly other… | EXPLOIT ✓HIGH 7.5EPSS 11.5% | 3 November 2005 |
| CVE-2005-3404 | Multiple PHP file inclusion vulnerabilities in ATutor 1.4.1 through 1.5.1-pl1 allow remote attackers to include arbitrary files via the section parameter followed by a null byte (%00) in (1) body_header.inc.php and (2) print.php. | EXPLOIT ×2 ✓HIGH 7.5EPSS 10.3% | 1 November 2005 |
| CVE-2005-3398 | The default configuration of the web server for the Solaris Management Console (SMC) in Solaris 8, 9, and 10 enables the HTTP TRACE method, which could allow remote attackers to obtain sensitive information such as cookies and authentication data from… | MEDIUM 4.3EPSS 13.1% | 1 November 2005 |
| CVE-2005-3390 | The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows remote attackers to modify the GLOBALS array and bypass security protections of PHP applications via a multipart/form-data POST request… | EXPLOIT ✓HIGH 7.5EPSS 65.5% | 1 November 2005 |
| CVE-2005-3388 | Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a "stacked array assignment." | EXPLOIT ✓MEDIUM 4.3EPSS 48.9% | 1 November 2005 |
| CVE-2005-3330 | The _httpsrequest function in Snoopy 1.2, as used in products such as (1) MagpieRSS, (2) WordPress, (3) Ampache, and (4) Jinzora, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTPS URL to an SSL protected web… | EXPLOIT ✓HIGH 7.5EPSS 17.2% | 27 October 2005 |
| CVE-2005-3243 | Multiple buffer overflows in Ethereal 0.10.12 and earlier might allow remote attackers to execute arbitrary code via unknown vectors in the (1) SLIMP3 and (2) AgentX dissector. | EXPLOIT ✓HIGH 7.5EPSS 10.8% | 27 October 2005 |
| CVE-2005-3312 | The HTML rendering engine in Microsoft Internet Explorer 6.0 allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML in corrupted images and other files such as .GIF, JPG, and WAV, which is rendered as HTML when the user clicks on… | MEDIUM 4.3EPSS 11.9% | 26 October 2005 |
| CVE-2005-2970 | Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for… | MEDIUM 5.0EPSS 14.2% | 25 October 2005 |
| CVE-2005-3299 | PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array. | EXPLOIT ✓MEDIUM 5.0EPSS 15.9% | 23 October 2005 |
| CVE-2005-3277 | The LPD service in HP-UX 10.20 11.11 (11i) and earlier allows remote attackers to execute arbitrary code via shell metacharacters ("`" or single backquote) in a request that is not properly handled when an error occurs, as demonstrated by killing the… | EXPLOIT ✓HIGH 10.0EPSS 19.4% | 21 October 2005 |
| CVE-2005-2126 | The FTP client in Windows XP SP1 and Server 2003, and Internet Explorer 6 SP1 on Windows 2000 SP4, when "Enable Folder View for FTP Sites" is enabled and the user manually initiates a file transfer, allows user-assisted, remote FTP servers to overwrite… | LOW 2.6EPSS 14.3% | 21 October 2005 |
| CVE-2005-2122 | Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server… | HIGH 10.0EPSS 43.8% | 21 October 2005 |
| CVE-2005-2118 | Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote user-assisted attackers to execute arbitrary commands via a crafted shortcut (.lnk) file with long font properties that lead to a buffer overflow when the user… | MEDIUM 5.1EPSS 47.4% | 21 October 2005 |
| CVE-2005-2117 | Web View in Windows Explorer on Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 does not properly handle certain HTML characters in preview fields, which allows remote user-assisted attackers to execute arbitrary code. | MEDIUM 5.1EPSS 37.0% | 21 October 2005 |
| CVE-2005-3252 | Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to execute arbitrary code via a crafted UDP packet. | EXPLOIT ×5 ✓HIGH 7.5EPSS 83.6% | 18 October 2005 |
| CVE-2005-3120 | Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escape (ESC) characters. | EXPLOIT ✓CRITICAL 9.8EPSS 23.3% | 17 October 2005 |
| CVE-2005-3231 | Multiple interpretation error in unspecified versions of CAT Quick Heal allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by… | MEDIUM 5.1EPSS 14.2% | 14 October 2005 |
| CVE-2005-3207 | The forms servlet (f90servlet) in Oracle Forms 4.5.10.22 allows remote attackers to cause a denial of service (TNS listener stop) via a userid parameter that contains a STOP command. | EXPLOIT ✓MEDIUM 5.0EPSS 19.8% | 14 October 2005 |
| CVE-2005-3206 | iSQL*Plus (isqlplus) for Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to cause a denial of service (TNS listener stop) via an HTTP request with an sid parameter that contains a STOP command. | EXPLOIT ✓MEDIUM 5.0EPSS 21.5% | 14 October 2005 |
| CVE-2005-3204 | Cross-site scripting (XSS) vulnerability in Oracle XML DB 9iR2 allows remote attackers to inject arbitrary web script or HTML via the query string in an HTTP request. | EXPLOIT ✓MEDIUM 4.3EPSS 20.7% | 14 October 2005 |
| CVE-2005-3202 | Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTML DB (HTMLDB) 1.3 through 1.3.6 allow remote attackers to inject arbitrary web script or HTML, and subsequently execute SQL statements via the (1) p or (2) p_t02 parameters. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 11.0% | 14 October 2005 |
| CVE-2005-2661 | Format string vulnerability in the ParseBannerAndCapability function in main.c for up-imapproxy 1.2.3 and 1.2.4 allows remote IMAP servers to execute arbitrary code via format string specifiers in a banner or capability line. | EXPLOIT ✓HIGH 7.5EPSS 12.1% | 14 October 2005 |
| CVE-2005-3190 | Buffer overflow in Computer Associates (CA) iGateway 3.0 and 4.0 before 4.0.050623, when running in debug mode, allows remote attackers to execute arbitrary code via HTTP GET requests. | EXPLOIT ×2 ✓HIGH 7.5EPSS 64.8% | 13 October 2005 |
| CVE-2005-2943 | Stack-based buffer overflow in sendmail in XMail before 1.22 allows remote attackers to execute arbitrary code via a long -t command line option. | EXPLOIT ✓HIGH 7.5EPSS 15.3% | 13 October 2005 |
| CVE-2005-2120 | Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in… | EXPLOIT ×2 ✓MEDIUM 6.5EPSS 62.0% | 13 October 2005 |
| CVE-2005-1987 | Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated… | HIGH 7.5EPSS 44.5% | 13 October 2005 |
| CVE-2005-1985 | The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages. | HIGH 7.5EPSS 37.3% | 13 October 2005 |
| CVE-2005-2715 | Format string vulnerability in the Java user interface service (bpjava-msvc) daemon for VERITAS NetBackup Data and Business Center 4.5FP and 4.5MP, and NetBackup Enterprise/Server/Client 5.0, 5.1, and 6.0, allows remote attackers to execute arbitrary… | EXPLOIT ×3 ✓HIGH 10.0EPSS 60.4% | 12 October 2005 |
| CVE-2005-2128 | QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value. | MEDIUM 5.0EPSS 40.5% | 12 October 2005 |
| CVE-2005-2119 | The MIDL_user_allocate function in the Microsoft Distributed Transaction Coordinator (MSDTC) proxy (MSDTCPRX.DLL) allocates a 4K page of memory regardless of the required size, which allows attackers to overwrite arbitrary memory locations using an… | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 35.5% | 12 October 2005 |
| CVE-2005-1980 | Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transaction Internet Protocol (TIP) message that causes DTC to repeatedly connect to a target IP and port… | EXPLOIT ✓MEDIUM 5.0EPSS 33.3% | 12 October 2005 |
| CVE-2005-1979 | Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "unexpected protocol command during the reconnection request," which is not properly handled by the… | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 32.8% | 12 October 2005 |
| CVE-2005-1978 | COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code. | EXPLOIT ✓HIGH 7.5EPSS 53.4% | 12 October 2005 |
| CVE-2005-3155 | Buffer overflow in the W3C logging for MailEnable Enterprise 1.1 and Professional 1.6 allows remote attackers to execute arbitrary code. | EXPLOIT ×2 ✓HIGH 7.5EPSS 63.7% | 5 October 2005 |
| CVE-2005-3142 | Heap-based buffer overflow in Kaspersky Antivirus (KAV) 5.0 and Kaspersky Personal Security Suite 1.1 allows remote attackers to execute arbitrary code via a CAB file with large records after the header. | HIGH 10.0EPSS 41.7% | 5 October 2005 |
| CVE-2005-2758 | Integer signedness error in the administrative interface for Symantec AntiVirus Scan Engine 4.0 and 4.3 allows remote attackers to execute arbitrary code via crafted HTTP headers with negative values, which lead to a heap-based buffer overflow. | HIGH 10.0EPSS 13.4% | 5 October 2005 |
| CVE-2005-3081 | wzdftpd 0.5.4 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the SITE command. | EXPLOIT ×2 ✓MEDIUM 4.6EPSS 76.6% | 27 September 2005 |
| CVE-2005-3077 | Microsoft Internet Explorer 5.2.3 for Mac OS allows remote attackers to cause a denial of service (crash) via a web page with malformed attributes in a BGSOUND tag, possibly involving double-quotes in an about: URI. | EXPLOIT ✓MEDIUM 5.0EPSS 13.9% | 27 September 2005 |
| CVE-2005-2710 | Format string vulnerability in Real HelixPlayer and RealPlayer 10 allows remote attackers to execute arbitrary code via the (1) image handle or (2) timeformat attribute in a RealPix (.rp) or RealText (.rt) file. | EXPLOIT ✓MEDIUM 5.1EPSS 13.2% | 27 September 2005 |
| CVE-2005-2968 | Firefox 1.0.6 and Mozilla 1.7.10 allows attackers to execute arbitrary commands via shell metacharacters in a URL that is provided to the browser on the command line, which is sent unfiltered to bash. | EXPLOIT ✓HIGH 7.5EPSS 10.7% | 20 September 2005 |
| CVE-2005-2877 | The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary code via shell metacharacters, as demonstrated via the rev parameter to TWikiUsers. | EXPLOIT ×3 ✓HIGH 7.5EPSS 70.9% | 16 September 2005 |
| CVE-2005-2799 | Buffer overflow in apply.cgi in Linksys WRT54G 3.01.03, 3.03.6, and possibly other versions before 4.20.7, allows remote attackers to execute arbitrary code via a long HTTP POST request. | EXPLOIT ×2 ✓HIGH 7.5EPSS 70.8% | 15 September 2005 |
| CVE-2005-2878 | Format string vulnerability in search.c in the imap4d server in GNU Mailutils 0.6 allows remote authenticated users to execute arbitrary code via format string specifiers in the SEARCH command. | EXPLOIT ×3 ✓HIGH 7.5EPSS 14.6% | 13 September 2005 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.