Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,088 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
17,157 results · page 331 of 344
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2002-0749 | CGIscript.net csMailto.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the form-attachment field. | EXPLOIT ✓HIGH 7.5EPSS 11.0% | 12 August 2002 |
| CVE-2002-0748 | LabVIEW Web Server 5.1.1 through 6.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET request that ends in two newline characters, instead of the expected carriage return/newline combinations. | EXPLOIT ✓MEDIUM 5.0EPSS 10.3% | 12 August 2002 |
| CVE-2002-0736 | Microsoft BackOffice 4.0 and 4.5, when configured to be accessible by other systems, allows remote attackers to bypass authentication and access the administrative ASP pages via an HTTP request with an authorization type (auth_type) that is not blank. | HIGH 10.0EPSS 31.6% | 12 August 2002 |
| CVE-2002-0729 | Microsoft SQL Server 2000 allows remote attackers to cause a denial of service via a malformed 0x08 packet that is missing a colon separator. | MEDIUM 5.0EPSS 10.7% | 12 August 2002 |
| CVE-2002-0719 | SQL injection vulnerability in the function that services for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary commands via an MCMS resource request for image files or other files. | HIGH 7.5EPSS 10.4% | 12 August 2002 |
| CVE-2002-0698 | Buffer overflow in Internet Mail Connector (IMC) for Microsoft Exchange Server 5.5 allows remote attackers to execute arbitrary code via an EHLO request from a system with a long name as obtained through a reverse DNS lookup, which triggers the overflow… | HIGH 7.5EPSS 20.3% | 12 August 2002 |
| CVE-2002-0697 | Microsoft Metadirectory Services (MMS) 2.2 allows remote attackers to bypass authentication and modify sensitive data by using an LDAP client to directly connect to MMS and bypass the checks for MMS credentials. | HIGH 10.0EPSS 18.0% | 12 August 2002 |
| CVE-2002-0695 | Buffer overflow in the Transact-SQL (T-SQL) OpenRowSet component of Microsoft Data Access Components (MDAC) 2.5 through 2.7 for SQL Server 7.0 or 2000 allows remote attackers to execute arbitrary code via a query that calls the OpenRowSet command. | HIGH 7.5EPSS 16.9% | 12 August 2002 |
| CVE-2002-0661 | Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to read arbitrary files and execute commands via .. | EXPLOIT ✓HIGH 7.5EPSS 69.7% | 12 August 2002 |
| CVE-2002-0659 | The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodings. | EXPLOIT ✓MEDIUM 5.0EPSS 36.2% | 12 August 2002 |
| CVE-2002-0656 | Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SSL3. | EXPLOITHIGH 7.5EPSS 89.8% | 12 August 2002 |
| CVE-2002-0650 | The keep-alive mechanism for Microsoft SQL Server 2000 allows remote attackers to cause a denial of service (bandwidth consumption) via a "ping" style packet to the Resolution Service (UDP port 1434) with a spoofed IP address of another SQL Server… | MEDIUM 5.0EPSS 18.3% | 12 August 2002 |
| CVE-2002-0649 | Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04… | EXPLOIT ×2 ✓HIGH 7.5EPSS 84.8% | 12 August 2002 |
| CVE-2002-0644 | Buffer overflow in several Database Consistency Checkers (DBCCs) for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows members of the db_owner and db_ddladmin roles to execute arbitrary code. | EXPLOIT ✓HIGH 7.5EPSS 11.4% | 12 August 2002 |
| CVE-2002-0619 | The Mail Merge Tool in Microsoft Word 2002 for Windows, when Microsoft Access is present on a system, allows remote attackers to execute Visual Basic (VBA) scripts within a mail merge document that is saved in HTML format, aka a "Variant of MS00-071,… | HIGH 7.5EPSS 16.1% | 12 August 2002 |
| CVE-2002-0618 | The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code in the Local Computer zone by embedding HTML scripts within an Excel workbook that contains an XSL stylesheet, aka "Excel XSL Stylesheet Script… | HIGH 7.5EPSS 14.5% | 12 August 2002 |
| CVE-2002-0617 | The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by creating a hyperlink on a drawing shape in a source workbook that points to a destination workbook containing an autoexecute macro, aka… | MEDIUM 5.1EPSS 10.8% | 12 August 2002 |
| CVE-2002-0516 | SquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the THEME variable in a cookie. | EXPLOIT ✓HIGH 10.0EPSS 11.0% | 12 August 2002 |
| CVE-2002-0500 | Internet Explorer 5.0 through 6.0 allows remote attackers to determine the existence of files on the client via an IMG tag with a dynsrc property that references the target file, which sets certain elements of the image object such as file size. | MEDIUM 5.0EPSS 15.3% | 12 August 2002 |
| CVE-2002-0495 | csSearch.cgi in csSearch 2.3 and earlier allows remote attackers to execute arbitrary Perl code via the savesetup command and the setup parameter, which overwrites the setup.cgi configuration file that is loaded by csSearch.cgi. | EXPLOIT ✓HIGH 10.0EPSS 13.3% | 12 August 2002 |
| CVE-2002-0481 | An interaction between Windows Media Player (WMP) and Outlook 2002 allows remote attackers to bypass Outlook security settings and execute Javascript via an IFRAME in an HTML email message that references .WMS (Windows Media Skin) or other WMP media… | MEDIUM 5.1EPSS 10.1% | 12 August 2002 |
| CVE-2002-0472 | MSN Messenger Service 3.6, and possibly other versions, uses weak authentication when exchanging messages between clients, which allows remote attackers to spoof messages from other users. | MEDIUM 5.0EPSS 11.9% | 12 August 2002 |
| CVE-2002-0461 | Internet Explorer 5.01 through 6 allows remote attackers to cause a denial of service (application crash) via Javascript in a web page that calls location.replace on itself, causing a loop. | EXPLOIT ✓MEDIUM 5.0EPSS 22.6% | 12 August 2002 |
| CVE-2002-0422 | IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (which may be obscured by NAT) via (1) a PROPFIND HTTP request with a blank Host header, which leaks the address in an HREF property in a… | LOW 2.6EPSS 44.1% | 12 August 2002 |
| CVE-2002-0421 | IIS 4.0 allows local users to bypass the "User cannot change password" policy for Windows NT by directly calling .htr password changing programs in the /iisadmpwd directory, including (1) aexp2.htr, (2) aexp2b.htr, (3) aexp3.htr , or (4) aexp4.htr. | MEDIUM 5.0EPSS 20.0% | 12 August 2002 |
| CVE-2002-0419 | Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily conduct brute force attacks via responses from the server in which (2) in certain configurations, the server IP address is provided… | EXPLOIT ✓MEDIUM 5.0EPSS 38.2% | 12 August 2002 |
| CVE-2002-0391 | Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array… | CRITICAL 9.8EPSS 58.1% | 12 August 2002 |
| CVE-2000-1209 | The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq… | EXPLOIT ×2 ✓HIGH 10.0EPSS 87.3% | 12 August 2002 |
| CVE-2002-0717 | PHP 4.2.0 and 4.2.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an HTTP POST request with certain arguments in a multipart/form-data form, which generates an error condition that is not properly handled… | HIGH 7.5EPSS 11.0% | 26 July 2002 |
| CVE-2002-0702 | Format string vulnerabilities in the logging routines for dynamic DNS code (print.c) of ISC DHCP daemon (DHCPD) 3 to 3.0.1rc8, with the NSUPDATE option enabled, allow remote malicious DNS servers to execute arbitrary code via format strings in a DNS… | EXPLOIT ✓HIGH 10.0EPSS 31.1% | 26 July 2002 |
| CVE-2002-0448 | Xerver Free Web Server 2.10 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request that contains many "C:/" sequences. | EXPLOIT ✓MEDIUM 5.0EPSS 14.9% | 26 July 2002 |
| CVE-2002-0444 | Microsoft Windows 2000 running the Terminal Server 90-day trial version, and possibly other versions, does not apply group policies to incoming users when the number of connections to the SYSVOL share exceeds the maximum, e.g. with a maximum number of… | HIGH 7.5EPSS 12.0% | 26 July 2002 |
| CVE-2002-0436 | sscd_suncourier.pl CGI script in the Sun Sunsolve CD pack allows remote attackers to execute arbitrary commands via shell metacharacters in the email address parameter. | EXPLOIT ✓HIGH 10.0EPSS 11.9% | 26 July 2002 |
| CVE-2002-0409 | orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter. | MEDIUM 5.0EPSS 19.3% | 26 July 2002 |
| CVE-2002-0369 | Buffer overflow in ASP.NET Worker Process allows remote attackers to cause a denial of service (restart) and possibly execute arbitrary code via a routine that processes cookies while in StateServer mode. | HIGH 10.0EPSS 24.3% | 26 July 2002 |
| CVE-2002-0682 | Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet. | EXPLOIT ✓HIGH 7.5EPSS 13.6% | 23 July 2002 |
| CVE-2002-0642 | The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka "Incorrect… | HIGH 7.2EPSS 49.7% | 23 July 2002 |
| CVE-2002-0641 | Buffer overflow in bulk insert procedure of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows attackers with database administration privileges to execute arbitrary code via a long filename in the BULK INSERT… | HIGH 7.5EPSS 11.2% | 23 July 2002 |
| CVE-2002-0624 | Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server… | EXPLOIT ✓HIGH 7.5EPSS 22.8% | 23 July 2002 |
| CVE-2002-0665 | Macromedia JRun Administration Server allows remote attackers to bypass authentication on the login form via an extra slash (/) in the URL. | EXPLOIT ✓HIGH 10.0EPSS 10.7% | 11 July 2002 |
| CVE-2002-0651 | Buffer overflow in the DNS resolver code used in libc, glibc, and libbind, as derived from ISC BIND, allows remote malicious DNS servers to cause a denial of service and possibly execute arbitrary code via the stub resolvers. | HIGH 7.5EPSS 13.5% | 3 July 2002 |
| CVE-2002-0640 | Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses during challenge response authentication when OpenBSD is using PAM modules with interactive keyboard authentication… | EXPLOIT ×2 ✓HIGH 10.0EPSS 27.3% | 3 July 2002 |
| CVE-2002-0639 | Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentication (ChallengeResponseAuthentication) when OpenSSH is using SKEY or BSD_AUTH authentication. | CRITICAL 9.8EPSS 18.3% | 3 July 2002 |
| CVE-2002-0623 | Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 and 2002 allows remote attackers to execute arbitrary code via long authentication data, aka "New Variant of the ISAPI Filter Buffer Overrun". | HIGH 7.5EPSS 19.6% | 3 July 2002 |
| CVE-2002-0622 | The Office Web Components (OWC) package installer for Microsoft Commerce Server 2000 allows remote attackers to execute commands by passing the commands as input to the OWC package installer, aka "OWC Package Command Execution". | HIGH 7.5EPSS 19.4% | 3 July 2002 |
| CVE-2002-0621 | Buffer overflow in the Office Web Components (OWC) package installer used by Microsoft Commerce Server 2000 allows remote attackers to cause the process to fail or run arbitrary code in the LocalSystem security context via certain input to the OWC… | MEDIUM 5.0EPSS 16.9% | 3 July 2002 |
| CVE-2002-0620 | Buffer overflow in the Profile Service of Microsoft Commerce Server 2000 allows remote attackers to cause the server to fail or run arbitrary code in the LocalSystem security context via an input field using an affected API. | MEDIUM 5.0EPSS 12.2% | 3 July 2002 |
| CVE-2002-0569 | Oracle 9i Application Server allows remote attackers to bypass access restrictions for configuration files via a direct request to the XSQL Servlet (XSQLServlet). | HIGH 7.5EPSS 18.9% | 3 July 2002 |
| CVE-2002-0568 | Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requesting (1) XSQLConfig.xml or (2) soapConfig.xml through a virtual… | LOW 2.1EPSS 75.2% | 3 July 2002 |
| CVE-2002-0563 | The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2) dms/DMSDump, (3) servlet/DMSDump, (4) servlet/Spy,… | MEDIUM 5.0EPSS 51.1% | 3 July 2002 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.