Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,996 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
17,157 results · page 314 of 344
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2005-1219 | Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC profile format tags. | EXPLOIT ×2 ✓HIGH 7.5EPSS 49.9% | 12 July 2005 |
| CVE-2005-0564 | Stack-based buffer overflow in Microsoft Word 2000 and Word 2002, and Microsoft Works Suites 2000 through 2004, might allow remote attackers to execute arbitrary code via a .doc file with long font information. | HIGH 7.5EPSS 25.7% | 12 July 2005 |
| CVE-2005-2199 | PHP remote file inclusion vulnerability in inc/functions.inc.php in PPA web photo gallery 0.5.6 allows remote attackers to execute arbitrary code via the config[ppa_root_path] variable. | EXPLOIT ×2 ✓HIGH 7.5EPSS 10.1% | 11 July 2005 |
| CVE-2005-2150 | Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain alternate named pipes, which allows remote attackers to (1) list Windows services via svcctl or (2) read eventlogs via… | MEDIUM 5.0EPSS 19.4% | 11 July 2005 |
| CVE-2005-2090 | Jakarta Tomcat 5.0.19 (Coyote/1.1) and Tomcat 4.1.24 (Coyote/1.0) allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header… | MEDIUM 4.3EPSS 29.8% | 5 July 2005 |
| CVE-2005-2089 | Microsoft IIS 5.0 and 6.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes… | MEDIUM 4.3EPSS 31.0% | 5 July 2005 |
| CVE-2005-2088 | The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a… | MEDIUM 4.3EPSS 20.5% | 5 July 2005 |
| CVE-2005-2087 | Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded… | EXPLOIT ✓MEDIUM 5.0EPSS 61.4% | 5 July 2005 |
| CVE-2005-2086 | PHP remote file inclusion vulnerability in viewtopic.php in phpBB 2.0.15 and earlier allows remote attackers to execute arbitrary PHP code. | EXPLOIT ×2 ✓HIGH 7.5EPSS 85.4% | 5 July 2005 |
| CVE-2005-1921 | Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5)… | EXPLOIT ×5 ✓HIGH 7.5EPSS 79.1% | 5 July 2005 |
| CVE-2005-0360 | The Microsoft Log Sink Class ActiveX control in pkmcore.dll is marked as "safe for scripting" for Internet Explorer, which allows remote attackers to create or append to arbitrary files. | MEDIUM 5.0EPSS 12.3% | 5 July 2005 |
| CVE-2005-0772 | VERITAS Backup Exec 9.0 through 10.0 for Windows Servers, and 9.0.4019 through 9.1.307 for Netware, allows remote attackers to cause a denial of service (Remote Agent crash) via (1) a crafted packet in NDMLSRVR.DLL or (2) a request packet with an… | HIGH 7.5EPSS 35.7% | 28 June 2005 |
| CVE-2005-0771 | VERITAS Backup Exec Server (beserver.exe) 9.0 through 10.0 for Windows allows remote unauthenticated attackers to modify the registry by calling methods to the RPC interface on TCP port 6106. | HIGH 10.0EPSS 54.2% | 23 June 2005 |
| CVE-2005-1526 | PHP remote file inclusion vulnerability in config_settings.php in Cacti before 0.8.6e allows remote attackers to execute arbitrary PHP code via the config[include_path] parameter. | EXPLOIT ✓HIGH 7.5EPSS 16.6% | 22 June 2005 |
| CVE-2005-1524 | PHP file inclusion vulnerability in top_graph_header.php in Cacti 0.8.6d and possibly earlier versions allows remote attackers to execute arbitrary PHP code via the config[library_path] parameter. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 15.9% | 22 June 2005 |
| CVE-2005-1250 | SQL injection vulnerability in the logon screen of the web front end (NmConsole/Login.asp) for IpSwitch WhatsUp Professional 2005 SP1 allows remote attackers to execute arbitrary SQL commands via the (1) User Name field (sUserName parameter) or (2)… | EXPLOIT ✓HIGH 7.5EPSS 20.9% | 22 June 2005 |
| CVE-2005-0773 | Stack-based buffer overflow in VERITAS Backup Exec Remote Agent 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.307 for Netware allows remote attackers to execute arbitrary code via a CONNECT_CLIENT_AUTH request with authentication method type 3… | EXPLOIT ✓HIGH 7.5EPSS 86.4% | 18 June 2005 |
| CVE-2005-1306 | The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the "XML External Entity vulnerability." | EXPLOIT ✓HIGH 7.5EPSS 14.5% | 15 June 2005 |
| CVE-2005-1216 | Microsoft ISA Server 2000 allows remote attackers to connect to services utilizing the NetBIOS protocol via a NetBIOS connection with an ISA Server that uses the NetBIOS (all) predefined packet filter. | HIGH 7.5EPSS 25.8% | 14 June 2005 |
| CVE-2005-1215 | Microsoft ISA Server 2000 allows remote attackers to poison the ISA cache or bypass content restriction policies via a malformed HTTP request packet containing multiple Content-Length headers. | HIGH 7.5EPSS 19.0% | 14 June 2005 |
| CVE-2005-1214 | Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page. | MEDIUM 5.1EPSS 12.8% | 14 June 2005 |
| CVE-2005-1213 | Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field. | EXPLOIT ×2 ✓HIGH 7.5EPSS 74.0% | 14 June 2005 |
| CVE-2005-1212 | Buffer overflow in Microsoft Step-by-Step Interactive Training (orun32.exe) allows remote attackers to execute arbitrary code via a bookmark link file (.cbo, cbl, or .cbm extension) with a long User field. | HIGH 7.5EPSS 24.9% | 14 June 2005 |
| CVE-2005-1211 | Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file. | MEDIUM 5.1EPSS 28.7% | 14 June 2005 |
| CVE-2005-1208 | Integer overflow in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via a crafted compiled Help (.CHM) file with a large size field that triggers a heap-based buffer… | HIGH 10.0EPSS 47.3% | 14 June 2005 |
| CVE-2005-1206 | Buffer overflow in the Server Message Block (SMB) functionality for Microsoft Windows 2000, XP SP1 and SP2, and Server 2003 and SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka the "Server Message Block Vulnerability." | HIGH 7.5EPSS 70.3% | 14 June 2005 |
| CVE-2005-1205 | The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command. | MEDIUM 5.0EPSS 33.0% | 14 June 2005 |
| CVE-2005-0563 | Cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA) component in Exchange Server 5.5 allows remote attackers to inject arbitrary web script or HTML via an email message with an encoded javascript: URL… | MEDIUM 4.3EPSS 14.2% | 14 June 2005 |
| CVE-2005-0488 | Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malicious Telnet servers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command. | MEDIUM 5.0EPSS 17.1% | 14 June 2005 |
| CVE-2005-1935 | Heap-based buffer overflow in the BERDecBitString function in Microsoft ASN.1 library (MSASN1.DLL) allows remote attackers to execute arbitrary code via nested constructed bit strings, which leads to a realloc of a non-null pointer and causes the… | HIGH 7.5EPSS 26.6% | 13 June 2005 |
| CVE-2005-1267 | The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted BGP packet. | EXPLOIT ✓MEDIUM 5.0EPSS 13.5% | 10 June 2005 |
| CVE-2005-1758 | Buffer overflow in the IMAP command continuation function in Novell NetMail 3.52 before 3.52C may allow remote attackers to execute arbitrary code. | HIGH 7.5EPSS 16.1% | 8 June 2005 |
| CVE-2005-1815 | Multiple buffer overflows in Hummingbird Connectivity inetD 10.0.0.1 and 9.0.0.4 allows attackers to cause a denial of service and possibly execute arbitrary code via (1) an FTP command with a long argument to FTPD (ftpdw.exe) or (2) a large amount of… | EXPLOIT ✓MEDIUM 5.0EPSS 47.2% | 1 June 2005 |
| CVE-2005-1812 | Multiple stack-based buffer overflows in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allow remote attackers to execute arbitrary code via a long (1) filename or (2) transfer mode string in a Read Request (RRQ) or Write Request (WRQ) packet. | EXPLOIT ×2 ✓HIGH 10.0EPSS 62.9% | 1 June 2005 |
| CVE-2005-1794 | Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks. | HIGH 7.4EPSS 16.3% | 1 June 2005 |
| CVE-2005-1790 | Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka… | EXPLOIT ✓LOW 2.6EPSS 83.5% | 1 June 2005 |
| CVE-2005-1907 | The ISA Firewall service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (Wspsrv.exe crash) via a large amount of SecureNAT network traffic. | MEDIUM 5.0EPSS 19.3% | 31 May 2005 |
| CVE-2005-0356 | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the… | EXPLOIT ✓MEDIUM 5.0EPSS 82.8% | 31 May 2005 |
| CVE-2005-1829 | Microsoft Internet Explorer 6 SP2 allows remote attackers to cause a denial of service (infinite loop and application crash) via two embedded files that call each other. | MEDIUM 5.0EPSS 12.7% | 28 May 2005 |
| CVE-2005-1806 | Format string vulnerability in PeerCast 0.1211 and earlier allows remote attackers to execute arbitrary code via format strings in the URL. | EXPLOIT ×2 ✓HIGH 7.5EPSS 11.9% | 28 May 2005 |
| CVE-2005-1787 | setup.php in phpStat 1.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the $check variable. | EXPLOIT ×3 ✓HIGH 7.5EPSS 12.3% | 27 May 2005 |
| CVE-2005-1827 | D-Link DSL-504T allows remote attackers to bypass authentication and gain privileges, such as upgrade firmware, restart the router or restore a saved configuration, via a direct request to firmwarecfg. | EXPLOIT ✓HIGH 7.5EPSS 19.5% | 26 May 2005 |
| CVE-2005-1543 | Multiple stack-based and heap-based buffer overflows in Remote Management authentication (zenrem32.exe) on Novell ZENworks 6.5 Desktop and Server Management, ZENworks for Desktops 4.x, ZENworks for Servers 3.x, and Remote Management allows remote… | EXPLOIT ×2 ✓HIGH 7.5EPSS 66.1% | 25 May 2005 |
| CVE-2005-1256 | Stack-based buffer overflow in the IMAP daemon (IMAPD32.EXE) in IMail 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allows remote authenticated users to execute arbitrary code via a STATUS command with… | HIGH 10.0EPSS 58.9% | 25 May 2005 |
| CVE-2005-1255 | Multiple stack-based buffer overflows in the IMAP server in IMail 8.12 and 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allow remote attackers to execute arbitrary code via a LOGIN command with (1) a… | EXPLOIT ×3 ✓HIGH 10.0EPSS 42.8% | 25 May 2005 |
| CVE-2005-1252 | Directory traversal vulnerability in the Web Calendaring server in Ipswitch Imail 8.13, and other versions before IMail Server 8.2 Hotfix 2, allows remote attackers to read arbitrary files via "..\" (dot dot backslash) sequences in the query string… | MEDIUM 5.0EPSS 12.5% | 25 May 2005 |
| CVE-2005-1683 | Buffer overflow in winword.exe 10.2627.6714 and earlier in Microsoft Word for the Macintosh, before SP3 for Word 2002, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted mcw file. | LOW 2.6EPSS 14.6% | 20 May 2005 |
| CVE-2005-1665 | The __VIEWSTATE functionality in Microsoft ASP.NET 1.x, when not cryptographically signed, allows remote attackers to cause a denial of service (CPU consumption) via deeply nested markup. | MEDIUM 5.0EPSS 40.3% | 18 May 2005 |
| CVE-2005-1664 | The __VIEWSTATE functionality in Microsoft ASP.NET 1.x allows remote attackers to conduct replay attacks to (1) apply a ViewState generated from one view to a different view, (2) reuse ViewState information after the application's state has changed, or… | MEDIUM 6.4EPSS 18.8% | 18 May 2005 |
| CVE-2005-1649 | The IPv6 support in Windows XP SP2, 2003 Server SP1, and Longhorn, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the SYN flag set and the same destination and source… | EXPLOIT ✓MEDIUM 5.0EPSS 21.8% | 18 May 2005 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.