Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,163 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
17,157 results · page 333 of 344
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2002-0078 | The zone determination function in Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to run scripts in the Local Computer zone by embedding the script in a cookie, aka the "Cookie-based Script Execution" vulnerability. | HIGH 7.5EPSS 21.9% | 29 March 2002 |
| CVE-2002-0163 | Heap-based buffer overflow in Squid before 2.4 STABLE4, and Squid 2.5 and 2.6 until March 12, 2002 distributions, allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via compressed DNS responses. | EXPLOIT ✓HIGH 7.5EPSS 15.1% | 26 March 2002 |
| CVE-2002-0128 | cgitest.exe in Sambar Server 5.1 before Beta 4 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long argument. | EXPLOIT ✓HIGH 7.5EPSS 10.1% | 25 March 2002 |
| CVE-2002-0101 | Microsoft Internet Explorer 6.0 and earlier allows local users to cause a denial of service via an infinite loop for modeless dialogs showModelessDialog, which causes CPU usage while the focus for the dialog is not released. | MEDIUM 5.0EPSS 12.4% | 25 March 2002 |
| CVE-2002-0061 | Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe character) provided as arguments to batch (.bat) or .cmd scripts, which are sent unfiltered to the… | EXPLOIT ✓HIGH 7.5EPSS 50.4% | 21 March 2002 |
| CVE-2002-0076 | Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, as seen in (1) Microsoft VM build 3802 and earlier as used in Internet Explorer… | HIGH 7.5EPSS 26.9% | 19 March 2002 |
| CVE-2002-0084 | Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument. | HIGH 7.2EPSS 20.7% | 15 March 2002 |
| CVE-2002-0083 | Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges. | EXPLOIT ✓CRITICAL 9.8EPSS 14.7% | 15 March 2002 |
| CVE-2002-0082 | The dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly initialize memory using the i2d_SSL_SESSION function, which allows remote attackers to use a buffer overflow to execute arbitrary… | EXPLOIT ×3 ✓HIGH 7.5EPSS 29.7% | 15 March 2002 |
| CVE-2002-0070 | Buffer overflow in Windows Shell (used as the Windows Desktop) allows local and possibly remote attackers to execute arbitrary code via a custom URL handler that has not been removed for an application that has been improperly uninstalled. | HIGH 7.6EPSS 18.5% | 15 March 2002 |
| CVE-2002-0081 | Buffer overflows in (1) php_mime_split in PHP 4.1.0, 4.1.1, and 4.0.6 and earlier, and (2) php3_mime_split in PHP 3.0.x allows remote attackers to execute arbitrary code via a multipart/form-data HTTP POST request when file_uploads is enabled. | HIGH 7.5EPSS 24.3% | 8 March 2002 |
| CVE-2002-0057 | XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remote attackers to read arbitrary files by specifying a local file as an XML Data Source. | MEDIUM 5.0EPSS 19.2% | 8 March 2002 |
| CVE-2002-0056 | Buffer overflow in SQL Server 7.0 and 2000 allows remote attackers to execute arbitrary code via a long OLE DB provider name to (1) OpenDataSource or (2) OpenRowset in an ad hoc connection. | HIGH 7.5EPSS 24.9% | 8 March 2002 |
| CVE-2002-0055 | SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote attackers to cause a denial of service via a command with a malformed data transfer (BDAT) request. | MEDIUM 5.0EPSS 34.7% | 8 March 2002 |
| CVE-2002-0054 | SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle responses to NTLM authentication, which allows remote attackers to perform mail relaying via an SMTP AUTH command using null… | HIGH 7.5EPSS 22.4% | 8 March 2002 |
| CVE-2002-0053 | Buffer overflow in SNMP agent service in Windows 95/98/98SE, Windows NT 4.0, Windows 2000, and Windows XP allows remote attackers to cause a denial of service or execute arbitrary code via a malformed management request. | HIGH 7.5EPSS 35.0% | 8 March 2002 |
| CVE-2002-0052 | Internet Explorer 6.0 and earlier does not properly handle VBScript in certain domain security checks, which allows remote attackers to read arbitrary files. | MEDIUM 5.0EPSS 18.2% | 8 March 2002 |
| CVE-2002-0050 | Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 allows remote attackers to execute arbitrary code via long authentication data. | HIGH 7.5EPSS 13.2% | 8 March 2002 |
| CVE-2002-0049 | Microsoft Exchange Server 2000 System Attendant gives "Everyone" group privileges to the WinReg key, which could allow remote attackers to read or modify registry keys. | MEDIUM 6.4EPSS 13.3% | 8 March 2002 |
| CVE-2002-0027 | Internet Explorer 5.5 and 6.0 allows remote attackers to read certain files and spoof the URL in the address bar by using the Document.open function to pass information between two frames from different domains, a new variant of the "Frame Domain… | HIGH 7.5EPSS 19.3% | 8 March 2002 |
| CVE-2002-0026 | Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made. | HIGH 7.5EPSS 13.3% | 8 March 2002 |
| CVE-2002-0025 | Internet Explorer 5.01, 5.5 and 6.0 does not properly handle the Content-Type HTML header field, which allows remote attackers to modify which application is used to process a document. | MEDIUM 5.0EPSS 14.2% | 8 March 2002 |
| CVE-2002-0023 | Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks. | EXPLOIT ✓MEDIUM 5.0EPSS 37.0% | 8 March 2002 |
| CVE-2002-0022 | Buffer overflow in the implementation of an HTML directive in mshtml.dll in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via a web page that specifies embedded ActiveX controls in a way that causes 2 Unicode strings to… | HIGH 7.5EPSS 39.8% | 8 March 2002 |
| CVE-2002-0021 | X for Mac allows remote attackers to cause a denial of service (crash) via a malformed product announcement. | MEDIUM 5.0EPSS 14.2% | 8 March 2002 |
| CVE-2002-0020 | Buffer overflow in telnet server in Windows 2000 and Interix 2.2 allows remote attackers to execute arbitrary code via malformed protocol options. | HIGH 7.5EPSS 16.9% | 8 March 2002 |
| CVE-2002-0018 | In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which allows remote attackers to gain Domain… | HIGH 10.0EPSS 16.4% | 8 March 2002 |
| CVE-2002-0048 | Multiple signedness errors (mixed signed and unsigned numbers) in the I/O functions of rsync 2.4.6, 2.3.2, and other versions allow remote attackers to cause a denial of service and execute arbitrary code in the rsync client or server. | EXPLOIT ×3 ✓HIGH 10.0EPSS 34.0% | 27 February 2002 |
| CVE-2002-1603 | GoAhead Web Server 2.1.7 and earlier allows remote attackers to obtain the source code of ASP files via a URL terminated with a /, \, %2f (encoded /), %20 (encoded space), or %00 (encoded null) character, which returns the ASP source code unparsed. | EXPLOIT ✓MEDIUM 5.0EPSS 13.7% | 13 February 2002 |
| CVE-2002-0013 | Vulnerabilities in the SNMPv1 request handling of a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via (1) GetRequest, (2) GetNextRequest, and (3) SetRequest messages, as demonstrated by the… | EXPLOIT ✓HIGH 10.0EPSS 51.1% | 13 February 2002 |
| CVE-2002-0012 | Vulnerabilities in a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via SNMPv1 trap handling, as demonstrated by the PROTOS c06-SNMPv1 test suite. | HIGH 10.0EPSS 24.1% | 13 February 2002 |
| CVE-2001-1371 | The default configuration of Oracle Application Server 9iAS 1.0.2.2 enables SOAP and allows anonymous users to deploy applications by default via urn:soap-service-manager and urn:soap-provider-manager. | HIGH 7.5EPSS 12.3% | 6 February 2002 |
| CVE-2002-0005 | Buffer overflow in AOL Instant Messenger (AIM) 4.7.2480, 4.8.2616, and other versions allows remote attackers to execute arbitrary code via a long argument in a game request (AddGame). | EXPLOIT ✓HIGH 10.0EPSS 15.5% | 31 January 2002 |
| CVE-2002-0077 | Microsoft Internet Explorer 5.01, 5.5 and 6.0 treats objects invoked on an HTML page with the codebase property as part of Local Computer zone, which allows remote attackers to invoke executables present on the local system through objects such as the… | HIGH 7.5EPSS 11.5% | 13 January 2002 |
| CVE-2001-1583 | lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request with a crafted control file that is not properly handled when lpd invokes a mail program. | EXPLOIT ×4 ✓HIGH 10.0EPSS 83.4% | 31 December 2001 |
| CVE-2001-1571 | The Remote Desktop client in Windows XP sends the most recent user account name in cleartext, which could allow remote attackers to obtain terminal server user account names via sniffing. | MEDIUM 5.0EPSS 13.1% | 31 December 2001 |
| CVE-2001-1552 | ssdpsrv.exe in Windows ME allows remote attackers to cause a denial of service by sending multiple newlines in a Simple Service Discovery Protocol (SSDP) message. | MEDIUM 5.0EPSS 13.9% | 31 December 2001 |
| CVE-2001-1547 | Outlook Express 6.0, with "Do not allow attachments to be saved or opened that could potentially be a virus" enabled, does not block email attachments from forwarded messages, which could allow remote attackers to execute arbitrary code. | HIGH 7.5EPSS 13.7% | 31 December 2001 |
| CVE-2001-1539 | Stack consumption vulnerability in Internet Explorer The JavaScript settimeout function in Internet Explorer allows remote attackers to cause a denial of service (crash) via the JavaScript settimeout function. | MEDIUM 5.0EPSS 13.9% | 31 December 2001 |
| CVE-2001-1533 | Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. | MEDIUM 5.3EPSS 18.0% | 31 December 2001 |
| CVE-2001-1501 | The glob functionality in ProFTPD 1.2.1, and possibly other versions allows remote attackers to cause a denial of service (CPU and memory consumption) via commands with large numbers of wildcard and other special characters, as demonstrated using an ls… | EXPLOIT ✓MEDIUM 5.0EPSS 38.4% | 31 December 2001 |
| CVE-2001-1500 | ProFTPD 1.2.2rc2, and possibly other versions, does not properly verify reverse-resolved hostnames by performing forward resolution, which allows remote attackers to bypass ACLs or cause an incorrect client hostname to be logged. | HIGH 7.5EPSS 12.4% | 31 December 2001 |
| CVE-2001-1489 | Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images. | EXPLOIT ✓MEDIUM 5.0EPSS 17.7% | 31 December 2001 |
| CVE-2001-1217 | Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitive information via a double encoded URL with .. | MEDIUM 5.0EPSS 54.4% | 21 December 2001 |
| CVE-2001-0877 | Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to cause a denial of service via (1) a spoofed SSDP advertisement that causes the client to connect to a service on another machine that generates a large amount of… | MEDIUM 5.0EPSS 43.8% | 20 December 2001 |
| CVE-2001-0876 | Buffer overflow in Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to execute arbitrary code via a NOTIFY directive with a long Location URL. | EXPLOIT ×2 ✓HIGH 7.5EPSS 49.5% | 20 December 2001 |
| CVE-2001-0542 | Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf. | HIGH 7.5EPSS 13.6% | 20 December 2001 |
| CVE-2001-0727 | Internet Explorer 6.0 allows remote attackers to execute arbitrary code by modifying the Content-Disposition and Content-Type header fields in a way that causes Internet Explorer to believe that the file is safe to open without prompting the user, aka… | HIGH 7.5EPSS 31.0% | 14 December 2001 |
| CVE-2001-0874 | Internet Explorer 5.5 and 6.0 allow remote attackers to read certain files via HTML that passes information from a frame in the client's domain to a frame in the web site's domain, a variant of the "Frame Domain Verification" vulnerability. | MEDIUM 5.0EPSS 21.8% | 13 December 2001 |
| CVE-2001-0797 | Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin. | EXPLOIT ×8 ✓HIGH 10.0EPSS 94.7% | 12 December 2001 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.