SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,015 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

17,157 results · page 318 of 344

CVESummaryPriorityPublished
CVE-2004-1135Multiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service crash) via long (1) SITE, (2) XMKD, (3) MKD, and (4) RNFR commands.EXPLOIT ×2MEDIUM 5.0EPSS 49.6%10 January 2005
CVE-2004-1134Buffer overflow in the Microsoft W3Who ISAPI (w3who.dll) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long query string.EXPLOITHIGH 10.0EPSS 72.3%10 January 2005
CVE-2004-1127Buffer overflow in Open Dc Hub 0.7.14 allows remote attackers, with administrator privileges, to execute arbitrary code via a long RedirectAll command.EXPLOITHIGH 10.0EPSS 14.6%10 January 2005
CVE-2004-1120Multiple buffer overflows in (1) http.c, (2) http-retr.c, (3) main.c and other code that handles network protocols in ProZilla 1.3.6-r2 and earlier allow remote servers to execute arbitrary code via a long Location header.EXPLOITHIGH 10.0EPSS 14.6%10 January 2005
CVE-2004-1119Stack-based buffer overflow in IN_CDDA.dll in Winamp 5.05, and possibly other versions including 5.06, allows remote attackers to execute arbitrary code via a certain .m3u playlist file.EXPLOITHIGH 10.0EPSS 17.3%10 January 2005
CVE-2004-1099Cisco Secure Access Control Server for Windows (ACS Windows) and Cisco Secure Access Control Server Solution Engine (ACS Solution Engine) 3.3.1, when the EAP-TLS protocol is enabled, does not properly handle expired or untrusted certificates, which…HIGH 10.0EPSS 10.2%10 January 2005
CVE-2004-1096Archive::Zip Perl module before 1.14, when used by antivirus programs such as amavisd-new, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed…EXPLOITHIGH 7.5EPSS 18.8%10 January 2005
CVE-2004-1080The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS…EXPLOIT ×2HIGH 10.0EPSS 79.8%10 January 2005
CVE-2004-1065Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary code via a long section name in an image file.HIGH 10.0EPSS 10.0%10 January 2005
CVE-2004-1018Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypass safe mode restrictions, cause a denial of service, or execute arbitrary code via (1) a negative offset value to the shmop_write function, (2) an "integer overflow/underflow"…EXPLOIT ×2HIGH 10.0EPSS 16.2%10 January 2005
CVE-2004-0993Buffer overflow in hpsockd before 0.6 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code.HIGH 10.0EPSS 10.2%10 January 2005
CVE-2004-0953Buffer overflow in the C2S module in the open source Jabber 2.x server (Jabberd) allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long username.EXPLOITHIGH 10.0EPSS 10.7%10 January 2005
CVE-2004-0946rquotad in nfs-utils (rquota_server.c) before 1.0.6-r6 on 64-bit architectures does not properly perform an integer conversion, which leads to a stack-based buffer overflow and allows remote attackers to execute arbitrary code via a crafted NFS request.HIGH 10.0EPSS 11.3%10 January 2005
CVE-2004-0901Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site,…HIGH 10.0EPSS 31.9%10 January 2005
CVE-2004-0900The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition does not properly validate the length of certain messages, which allows remote attackers to execute arbitrary code via a malformed DHCP message, aka the "DHCP…HIGH 10.0EPSS 26.0%10 January 2005
CVE-2004-0899The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition, with DHCP logging enabled, does not properly validate the length of certain messages, which allows remote attackers to cause a denial of service (application crash)…MEDIUM 5.0EPSS 72.6%10 January 2005
CVE-2004-0571Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability,"…HIGH 10.0EPSS 30.9%10 January 2005
CVE-2004-0568HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious…HIGH 10.0EPSS 35.3%10 January 2005
CVE-2004-2691Unspecified vulnerability in 3Com SuperStack 3 4400 switches with firmware version before 3.31 allows remote attackers to cause a denial of service (device reset) via a crafted request to the web management interface.HIGH 7.1EPSS 39.1%31 December 2004
CVE-2004-2687distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed by the server without authorization checks.EXPLOITHIGH 9.3EPSS 88.2%31 December 2004
CVE-2004-2685Buffer overflow in YoungZSoft CCProxy 6.2 and earlier allows remote attackers to execute arbitrary code via a long address in a ping (p) command to the Telnet proxy service, a different vector than CVE-2004-2416.EXPLOIT ×2HIGH 7.5EPSS 10.7%31 December 2004
CVE-2004-2652The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows remote attackers to cause a denial of service (crash) via packets with invalid TCP/IP options, which trigger a null…EXPLOIT ×2HIGH 7.8EPSS 11.2%31 December 2004
CVE-2004-2549Nortel Wireless LAN (WLAN) Access Point (AP) 2220, 2221, and 2225 allow remote attackers to cause a denial of service (service crash) via a TCP request with a large string, followed by 8 newline characters, to (1) the Telnet service on TCP port 23 and…EXPLOITMEDIUM 5.0EPSS 10.5%31 December 2004
CVE-2004-2532Serv-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary commands by connecting to the server using the default administrator account, creating a new user, logging in as…EXPLOITHIGH 10.0EPSS 15.3%31 December 2004
CVE-2004-2501Buffer overflow in the IMAP service of MailEnable Professional Edition 1.52 and Enterprise Edition 1.01 allows remote attackers to execute arbitrary code via (1) a long command string or (2) a long string to the MEIMAP service and then terminating the…EXPLOITHIGH 7.5EPSS 14.1%31 December 2004
CVE-2004-2482Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail editor and when forwarding e-mail, does not properly handle an opening OBJECT tag that does not have a closing OBJECT tag, which causes Outlook to…MEDIUM 5.0EPSS 12.8%31 December 2004
CVE-2004-2466chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username parameter, possibly due to a buffer overflow.EXPLOIT ×4MEDIUM 5.0EPSS 74.7%31 December 2004
CVE-2004-2442Multiple interpretation error in various F-Secure Anti-Virus products, including Workstation 5.43 and earlier, Windows Servers 5.50 and earlier, MIMEsweeper 5.50 and earlier, Anti-Virus for Linux Servers and Gateways 4.61 and earlier, and other…EXPLOITMEDIUM 5.0EPSS 10.6%31 December 2004
CVE-2004-2434Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (browser crash) via a link with "::{" (colon colon left brace), which triggers a null dereference when the user attempts to save the link using "Save As" and…EXPLOITMEDIUM 5.0EPSS 32.8%31 December 2004
CVE-2004-2425Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent (`) and possibly other shell metacharacters in the query string to virtualinput.cgi.EXPLOITHIGH 7.5EPSS 13.5%31 December 2004
CVE-2004-2416Buffer overflow in the logging component of CCProxy allows remote attackers to execute arbitrary code via a long HTTP GET request.EXPLOITHIGH 7.5EPSS 60.6%31 December 2004
CVE-2004-2383Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to bypass cross-frame scripting restrictions and capture keyboard events from other domains via an HTML document with Javascript that is outside a frameset that includes the target…EXPLOITMEDIUM 5.1EPSS 20.0%31 December 2004
CVE-2004-2364Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary commands via URLs that are automatically executed on behalf of the administrator, as demonstrated using (1) admin/page.php, (2)…EXPLOIT ×6MEDIUM 5.0EPSS 10.7%31 December 2004
CVE-2004-2307Microsoft Internet Explorer 6.0.2600 on Windows XP allows remote attackers to cause a denial of service (browser crash) via a shell: URI with double backslashes (\\) in an HTML tag such as IFRAME or A.MEDIUM 5.0EPSS 14.5%31 December 2004
CVE-2004-2299Buffer overflow in Omnicron OmniHTTPd 3.0a and earlier allows remote attackers to execute arbitrary code via an HTTP GET request with a long Range header.EXPLOITHIGH 7.5EPSS 10.2%31 December 2004
CVE-2004-2292Buffer overflow in Alt-N MDaemon 7.0.1 allows remote attackers to cause a denial of service (application crash) via a long STATUS command to the IMAP server.MEDIUM 5.0EPSS 12.2%31 December 2004
CVE-2004-2291Microsoft Windows Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via an embedded script that uses Shell Helper objects and a shortcut (link) to execute the target script.EXPLOITHIGH 7.5EPSS 10.9%31 December 2004
CVE-2004-2289Microsoft Windows XP Explorer allows local users to execute arbitrary code via a system folder with a Desktop.ini file containing a .ShellClassInfo specifier with a CLSID value that is associated with an executable file.EXPLOITHIGH 10.0EPSS 23.3%31 December 2004
CVE-2004-2275i-mall.cgi in I-Mall Commerce allows remote attackers to execute arbitrary commands via shell metacharacters via the p parameter.EXPLOITHIGH 10.0EPSS 12.8%31 December 2004
CVE-2004-2271Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.EXPLOIT ×3HIGH 7.5EPSS 71.9%31 December 2004
CVE-2004-2262ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the upload parameter to images.php.EXPLOITHIGH 7.5EPSS 14.9%31 December 2004
CVE-2004-2221Buffer overflow in SoftCart.exe in Mercantec SoftCart 4.00b allows remote attackers to execute arbitrary code via a long parameter in an HTTP GET request.EXPLOIT ×2HIGH 7.5EPSS 34.8%31 December 2004
CVE-2004-2179asycpict.dll, as used in Microsoft products such as Front Page 97 and 98, allows remote attackers to cause a denial of service (hang) via a JPEG image with maximum height and width values.MEDIUM 5.0EPSS 12.0%31 December 2004
CVE-2004-2167Multiple buffer overflows in LaTeX2rtf 1.9.15, and possibly other versions, allow remote attackers to execute arbitrary code via (1) the expandmacro function, and possibly (2) Environments and (3) TranslateCommand.EXPLOITHIGH 7.5EPSS 14.3%31 December 2004
CVE-2004-2137Outlook Express 6.0, when sending multipart e-mail messages using the "Break apart messages larger than" setting, leaks the BCC recipients of the message to the addresses listed in the To and CC fields, which may allow remote attackers to obtain…MEDIUM 5.0EPSS 26.1%31 December 2004
CVE-2004-2115Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attackers to execute arbitrary script as other users via the (1) action, (2) username, or (3) password parameters in an isqlplus request.EXPLOITMEDIUM 6.8EPSS 58.4%31 December 2004
CVE-2004-2111Stack-based buffer overflow in the site chmod command in Serv-U FTP Server before 4.2 allows remote attackers to execute arbitrary code via a long filename.EXPLOIT ×5HIGH 8.5EPSS 86.9%31 December 2004
CVE-2004-2104Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, including the internal IP address, via a direct request to (1) snoop.jsp, (2) SnoopServlet, (3) env.bas, or (4) lcgitest.nlm.EXPLOIT ×3MEDIUM 5.0EPSS 11.9%31 December 2004
CVE-2004-2074Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string specifiers in the (1) PASS or (2) RETR commands.EXPLOIT ×2MEDIUM 5.0EPSS 35.8%31 December 2004
CVE-2004-1898Stack-based buffer overflow in the administration interface in Monit 1.4 through 4.2 allows remote attackers to execute arbitrary code via a long username.EXPLOITHIGH 10.0EPSS 16.6%31 December 2004

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.