SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

395,996 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

17,157 results · page 315 of 344

CVESummaryPriorityPublished
CVE-2005-1628apage.cgi in WebAPP 0.9.9.2.1, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters in the f parameter.EXPLOIT ×2HIGH 7.5EPSS 10.6%17 May 2005
CVE-2005-1598SQL injection vulnerability in Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via a crafted cookie password hash (pass_hash) that modifies the internal $pid variable.EXPLOIT ×3HIGH 7.5EPSS 13.9%16 May 2005
CVE-2005-1365Pico Server (pServ) 3.2 and earlier allows remote attackers to execute arbitrary commands via a URL with multiple leading "/" (slash) characters and ".." sequences.EXPLOITHIGH 10.0EPSS 12.0%16 May 2005
CVE-2005-1193The bbencode_second_pass and make_clickable functions in bbcode.php for phpBB before 2.0.15, as used in viewtopic.php, privmsg.php, and other scripts, allow remote attackers to execute arbitrary script via a BBcode tag with a (1) javascript:, (2)…EXPLOITHIGH 7.5EPSS 16.4%16 May 2005
CVE-2005-1544Stack-based buffer overflow in libTIFF before 3.7.2 allows remote attackers to execute arbitrary code via a TIFF file with a malformed BitsPerSample tag.EXPLOITHIGH 7.5EPSS 14.4%14 May 2005
CVE-2005-1513Integer overflow in the stralloc_readyplus function in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large SMTP request.CRITICAL 9.8EPSS 10.8%11 May 2005
CVE-2005-1496The DBMS_Scheduler in Oracle 10g allows remote attackers with CREATE JOB privileges to gain additional privileges by changing SESSION_USER to the SYS user.MEDIUM 4.6EPSS 38.3%11 May 2005
CVE-2005-1261Stack-based buffer overflow in the URL parsing function in Gaim before 1.3.0 allows remote attackers to execute arbitrary code via an instant message (IM) with a large URL.EXPLOITHIGH 7.5EPSS 12.4%11 May 2005
CVE-2005-1477The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when…EXPLOITMEDIUM 5.1EPSS 15.2%9 May 2005
CVE-2005-1476Firefox 1.0.3 allows remote attackers to execute arbitrary Javascript in other domains by using an IFRAME and causing the browser to navigate to a previous javascript: URL, which can lead to arbitrary code execution when combined with CVE-2005-1477.EXPLOITMEDIUM 5.1EPSS 16.7%9 May 2005
CVE-2005-1825Multiple stack-based buffer overflows in the nvd_exec function in HP Radia Notify Daemon 3.1.2.0 (formerly by Novadigm), and other versions including 2.x, 3.x, and 4.x, allows remote attackers to execute arbitrary code via a command with crafted…HIGH 7.5EPSS 61.5%3 May 2005
CVE-2005-1415Buffer overflow in GlobalSCAPE Secure FTP Server 3.0.2 allows remote authenticated users to execute arbitrary code via a long FTP command.EXPLOIT ×2HIGH 10.0EPSS 60.8%3 May 2005
CVE-2005-1383The OHS component 1.0.2 through 10.x, when UseWebcacheIP is disabled, in Oracle Application Server allows remote attackers to bypass HTTP Server mod_access restrictions via a request to the webcache TCP port 7778.EXPLOITHIGH 7.5EPSS 30.6%3 May 2005
CVE-2005-1381Multiple cross-site scripting (XSS) vulnerabilities in Oracle Webcache 9i allow remote attackers to inject arbitrary web script or HTML via the (1) cache_dump_file or (2) PartialPageErrorPage parameter.EXPLOIT ×2MEDIUM 6.8EPSS 20.2%3 May 2005
CVE-2005-1349Buffer overflow in Convert-UUlib (Convert::UUlib) before 1.051 allows remote attackers to execute arbitrary code via a malformed parameter to a read operation.EXPLOITHIGH 7.5EPSS 12.8%2 May 2005
CVE-2005-1348Buffer overflow in HTTPMail in MailEnable Enterprise 1.04 and earlier and Professional 1.54 and earlier allows remote attackers to execute arbitrary code via a long HTTP Authorization header.EXPLOIT ×2HIGH 7.5EPSS 72.6%2 May 2005
CVE-2005-1344Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument.EXPLOIT ×2HIGH 7.5EPSS 29.1%2 May 2005
CVE-2005-1323Buffer overflow in NetFtpd for NetTerm 5.1.1 and earlier allows remote attackers to execute arbitrary code via a long USER command.EXPLOIT ×2HIGH 7.5EPSS 63.1%2 May 2005
CVE-2005-1280The rsvp_print function in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted RSVP packet of length 4.EXPLOITMEDIUM 5.0EPSS 10.2%2 May 2005
CVE-2005-1279tcpdump 3.8.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted (1) BGP packet, which is not properly handled by RT_ROUTING_INFO, or (2) LDP packet, which is not properly handled by the ldp_print function.EXPLOIT ×2MEDIUM 5.0EPSS 18.7%2 May 2005
CVE-2005-1278The isis_print function, as called by isoclns_print, in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a zero length, as demonstrated using a GRE packet.EXPLOITMEDIUM 5.0EPSS 10.8%2 May 2005
CVE-2005-1191The Web View DLL (webvw.dll), as used in Windows Explorer on Windows 2000 systems, does not properly filter an apostrophe ("'") in the author name in a document, which allows attackers to execute arbitrary script via extra attributes when Web View…EXPLOITMEDIUM 5.0EPSS 17.1%2 May 2005
CVE-2005-1184The TCP/IP stack in multiple operating systems allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the correct sequence number but the wrong Acknowledgement number, which generates a large number of "keep alive"…EXPLOITMEDIUM 5.0EPSS 32.7%2 May 2005
CVE-2005-1163Multiple buffer overflows in Yager 5.24 and earlier allow remote attackers to execute arbitrary code via (1) a crafted nickname or (2) a packet with a large amount of data.EXPLOITMEDIUM 6.4EPSS 12.7%2 May 2005
CVE-2005-1100Format string vulnerability in the ErrorLog function in cnf.c in Greylisting daemon (GLD) 1.3 and 1.4 allows remote attackers to execute arbitrary code via format string specifiers in data that is passed directly to syslog.EXPLOITHIGH 7.5EPSS 11.0%2 May 2005
CVE-2005-1018Buffer overflow in the UniversalAgent for Computer Associates (CA) BrightStor ARCserve Backup allows remote authenticated users to cause a denial of service or execute arbitrary code via an agent request to TCP port 6050 with a large argument before the…EXPLOITHIGH 7.5EPSS 51.8%2 May 2005
CVE-2005-1015Buffer overflow in MailEnable Imapd (MEIMAP.exe) allows remote attackers to execute arbitrary code via a long LOGIN command.HIGH 10.0EPSS 16.2%2 May 2005
CVE-2005-1009Multiple buffer overflows in BakBone NetVault 6.x and 7.x allow (1) remote attackers to execute arbitrary code via a modified computer name and length that leads to a heap-based buffer overflow, or (2) local users to execute arbitrary code via a long…EXPLOIT ×4HIGH 10.0EPSS 57.0%2 May 2005
CVE-2005-0989The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attackers to read portions of heap memory in a Javascript string via the lambda replace method.EXPLOITMEDIUM 5.0EPSS 10.0%2 May 2005
CVE-2005-0954Windows Explorer and Internet Explorer in Windows 2000 SP1 allows remote attackers to cause a denial of service (CPU consumption) via a malformed Windows Metafile (WMF) file.MEDIUM 5.0EPSS 14.7%2 May 2005
CVE-2005-0944Unknown vulnerability in Microsoft Jet DB engine (msjet40.dll) 4.00.8618.0, related to insufficient data validation, allows remote attackers to execute arbitrary code via a crafted mdb file.EXPLOIT ×3HIGH 7.5EPSS 34.0%2 May 2005
CVE-2005-0873Multiple cross-site scripting (XSS) vulnerabilities in test.jsp in Oracle Reports Server 10g (9.0.4.3.3) allow remote attackers to inject arbitrary web script or HTML via the (1) desname or (2) repprod parameter.EXPLOITMEDIUM 4.3EPSS 11.0%2 May 2005
CVE-2005-0862Multiple PHP remote file inclusion vulnerabilities in PHPOpenChat 3.0.1 and earlier allow remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter to (1) poc_loginform.php or (2) phpbb/poc.php, the poc_root_path parameter to (3)…EXPLOIT ×3HIGH 7.5EPSS 10.9%2 May 2005
CVE-2005-0859PHP remote file inclusion vulnerability in CzarNews 1.13b allows remote attackers to execute arbitrary PHP code via the tpath parameter to (1) headlines.php or (2) news.php.EXPLOIT ×2HIGH 7.5EPSS 11.4%2 May 2005
CVE-2005-0815Multiple "range checking flaws" in the ISO9660 filesystem handler in Linux 2.6.11 and earlier may allow attackers to cause a denial of service or corrupt memory via a crafted filesystem.EXPLOITMEDIUM 6.4EPSS 13.4%2 May 2005
CVE-2005-0808Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) via a crafted AJP12 packet to TCP port 8007.MEDIUM 5.0EPSS 23.4%2 May 2005
CVE-2005-0803The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (application crash) via a crafted Enhanced Metafile (EMF) file that causes invalid (1) end, (2) emreof, or (3) palent offsets to be…EXPLOIT ×2MEDIUM 5.0EPSS 67.7%2 May 2005
CVE-2005-0768Buffer overflow in the administration web server for GoodTech Telnet Server 4.0 and 5.0, and possibly all versions before 5.0.7, allows remote attackers to execute arbitrary code via a long string to port 2380.EXPLOIT ×2HIGH 10.0EPSS 59.5%2 May 2005
CVE-2005-0710MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to bypass library path restrictions and execute arbitrary libraries by using INSERT INTO to modify the mysql.func table, which is…EXPLOITMEDIUM 4.6EPSS 12.8%2 May 2005
CVE-2005-0709MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to execute arbitrary code by using CREATE FUNCTION to access libc calls, as demonstrated by using strcat, on_exit, and exit.EXPLOITMEDIUM 4.6EPSS 18.4%2 May 2005
CVE-2005-0643Buffer overflow in McAfee Scan Engine 4320 with DAT version before 4357 allows remote attackers to execute arbitrary code via crafted LHA files.EXPLOITHIGH 7.5EPSS 10.4%2 May 2005
CVE-2005-0634Buffer overflow in Golden FTP Server 1.92 allows remote attackers to execute arbitrary code via a long USER command.EXPLOIT ×3HIGH 7.5EPSS 10.2%2 May 2005
CVE-2005-0595Buffer overflow in ext.dll in BadBlue 2.55 allows remote attackers to execute arbitrary code via a long mfcisapicommand parameter.EXPLOIT ×2HIGH 7.5EPSS 60.1%2 May 2005
CVE-2005-0582Buffer overflow in Computer Associates (CA) License Client 0.1.0.15 allows remote attackers to execute arbitrary code via a long filename in a PUTOLF request.EXPLOITHIGH 10.0EPSS 37.0%2 May 2005
CVE-2005-0581Multiple buffer overflows in Computer Associates (CA) License Client and Server 0.1.0.15 allow remote attackers to execute arbitrary code via (1) certain long fields in the Checksum item in a GCR request, (2) a long IP address, hostname, or netmask…EXPLOIT ×4MEDIUM 4.6EPSS 46.3%2 May 2005
CVE-2005-0560Heap-based buffer overflow in the SvrAppendReceivedChunk function in xlsasink.dll in the SMTP service of Exchange Server 2000 and 2003 allows remote attackers to execute arbitrary code via a crafted X-LINK2STATE extended verb request to the SMTP port.EXPLOITHIGH 7.5EPSS 69.5%2 May 2005
CVE-2005-0558Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document.MEDIUM 5.1EPSS 15.2%2 May 2005
CVE-2005-0554Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption…EXPLOITHIGH 7.5EPSS 57.9%2 May 2005
CVE-2005-0553Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption…EXPLOITMEDIUM 5.1EPSS 50.6%2 May 2005
CVE-2005-0551Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that…EXPLOITHIGH 10.0EPSS 20.3%2 May 2005

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.