Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,163 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
17,157 results · page 334 of 344
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2001-1186 | Microsoft IIS 5.0 allows remote attackers to cause a denial of service via an HTTP request with a content-length value that is larger than the size of the request, which prevents IIS from timing out the connection. | EXPLOIT ✓MEDIUM 5.0EPSS 34.7% | 11 December 2001 |
| CVE-2001-0951 | Windows 2000 allows remote attackers to cause a denial of service (CPU consumption) by flooding Internet Key Exchange (IKE) UDP port 500 with packets that contain a large number of dot characters. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 27.4% | 7 December 2001 |
| CVE-2001-0846 | Lotus Domino 5.x allows remote attackers to read files or execute arbitrary code by requesting the ReplicaID of the Web Administrator template file (webadmin.ntf). | HIGH 10.0EPSS 41.2% | 6 December 2001 |
| CVE-2001-0836 | Buffer overflow in Oracle9iAS Web Cache 2.0.0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request. | EXPLOIT ✓HIGH 7.5EPSS 14.7% | 6 December 2001 |
| CVE-2001-0829 | A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message. | MEDIUM 5.1EPSS 12.2% | 6 December 2001 |
| CVE-2001-0820 | Buffer overflows in GazTek ghttpd 1.4 allows a remote attacker to execute arbitrary code via long arguments that are passed to (1) the Log function in util.c, or (2) serveconnection in protocol.c. | EXPLOIT ×2 ✓HIGH 7.5EPSS 12.7% | 6 December 2001 |
| CVE-2001-0817 | Vulnerability in HP-UX line printer daemon (rlpdaemon) in HP-UX 10.01 through 11.11 allows remote attackers to modify arbitrary files and gain root privileges via a certain print request. | HIGH 10.0EPSS 10.2% | 6 December 2001 |
| CVE-2001-0815 | Buffer overflow in PerlIS.dll in Activestate ActivePerl 5.6.1.629 and earlier allows remote attackers to execute arbitrary code via an HTTP request for a long filename that ends in a .pl extension. | EXPLOIT ×3 ✓HIGH 7.5EPSS 14.4% | 6 December 2001 |
| CVE-2001-0803 | Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands. | EXPLOIT ×2 ✓HIGH 10.0EPSS 85.6% | 6 December 2001 |
| CVE-2001-0800 | lpsched in IRIX 6.5.13f and earlier allows remote attackers to execute arbitrary commands via shell metacharacters. | EXPLOIT ✓HIGH 10.0EPSS 54.1% | 6 December 2001 |
| CVE-2001-0726 | Outlook Web Access (OWA) in Microsoft Exchange 5.5 Server, when used with Internet Explorer, does not properly detect certain inline script, which can allow remote attackers to perform arbitrary actions on a user's Exchange mailbox via an HTML e-mail… | HIGH 7.5EPSS 16.1% | 6 December 2001 |
| CVE-2001-0722 | Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript in an about: URL, aka the "First Cookie Handling Vulnerability." | EXPLOIT ✓MEDIUM 6.4EPSS 27.6% | 6 December 2001 |
| CVE-2001-0721 | Universal Plug and Play (UPnP) in Windows 98, 98SE, ME, and XP allows remote attackers to cause a denial of service (memory consumption or crash) via a malformed UPnP request. | MEDIUM 5.0EPSS 17.3% | 6 December 2001 |
| CVE-2001-0719 | Buffer overflow in Microsoft Windows Media Player 6.4 allows remote attackers to execute arbitrary code via a malformed Advanced Streaming Format (ASF) file. | HIGH 7.5EPSS 17.5% | 6 December 2001 |
| CVE-2001-0663 | Terminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service via a sequence of invalid Remote Desktop Protocol (RDP) packets. | EXPLOIT ✓MEDIUM 5.0EPSS 31.6% | 6 December 2001 |
| CVE-2001-0945 | Buffer overflow in Outlook Express 5.0 through 5.02 for Macintosh allows remote attackers to cause a denial of service via an e-mail message that contains a long line. | MEDIUM 5.0EPSS 19.8% | 3 December 2001 |
| CVE-2001-0550 | wu-ftpd 2.6.1 allows remote attackers to execute arbitrary commands via a "~{" argument to commands such as CWD, which is not properly handled by the glob function (ftpglob). | EXPLOIT ×2 ✓HIGH 7.5EPSS 74.8% | 30 November 2001 |
| CVE-2001-0932 | Buffer overflow in Cooolsoft PowerFTP Server 2.03 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long command. | EXPLOIT ×2 ✓HIGH 7.5EPSS 22.6% | 28 November 2001 |
| CVE-2001-0875 | Internet Explorer 5.5 and 6.0 allows remote attackers to cause the File Download dialogue box to misrepresent the name of the file in the dialogue in a way that could fool users into thinking that the file type is safe to download. | EXPLOIT ×2 ✓HIGH 7.5EPSS 28.1% | 26 November 2001 |
| CVE-2001-0909 | Buffer overflow in helpctr.exe program in Microsoft Help Center for Windows XP allows remote attackers to execute arbitrary code via a long hcp: URL. | EXPLOIT ✓HIGH 7.5EPSS 19.7% | 21 November 2001 |
| CVE-2001-0902 | Microsoft IIS 5.0 allows remote attackers to spoof web log entries via an HTTP request that includes hex-encoded newline or form-feed characters. | HIGH 7.5EPSS 18.6% | 20 November 2001 |
| CVE-2001-0724 | Internet Explorer 5.5 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security restrictions, aka… | HIGH 7.5EPSS 12.3% | 14 November 2001 |
| CVE-2001-0723 | Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript, aka the "Second Cookie Handling Vulnerability." | MEDIUM 6.4EPSS 11.4% | 14 November 2001 |
| CVE-2001-0730 | split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slash) in the Host: header. | MEDIUM 5.0EPSS 11.9% | 30 October 2001 |
| CVE-2001-0718 | Vulnerability in (1) Microsoft Excel 2002 and earlier and (2) Microsoft PowerPoint 2002 and earlier allows attackers to bypass macro restrictions and execute arbitrary commands by modifying the data stream in the document. | HIGH 7.5EPSS 11.1% | 30 October 2001 |
| CVE-2001-0667 | Internet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0, allows remote attackers to execute commands by spawning Telnet with a log file option on the command line and writing arbitrary code into an executable… | HIGH 7.3EPSS 14.7% | 30 October 2001 |
| CVE-2001-0665 | Internet Explorer 6 and earlier allows remote attackers to cause certain HTTP requests to be automatically executed and appear to come from the user, which could allow attackers to gain privileges or execute operations within web-based services, aka the… | HIGH 7.5EPSS 12.1% | 30 October 2001 |
| CVE-2001-0664 | Internet Explorer 5.5 and 5.01 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security… | EXPLOIT ✓HIGH 7.5EPSS 18.2% | 30 October 2001 |
| CVE-2001-0662 | RPC endpoint mapper in Windows NT 4.0 allows remote attackers to cause a denial of service (loss of RPC services) via a malformed request. | MEDIUM 5.0EPSS 22.6% | 30 October 2001 |
| CVE-2001-0660 | Outlook Web Access (OWA) in Microsoft Exchange 5.5, SP4 and earlier, allows remote attackers to identify valid user email addresses by directly accessing a back-end function that processes the global address list (GAL). | MEDIUM 5.0EPSS 22.0% | 30 October 2001 |
| CVE-2001-0545 | IIS 4.0 with URL redirection enabled allows remote attackers to cause a denial of service (crash) via a malformed request that specifies a length that is different than the actual length. | MEDIUM 5.0EPSS 18.3% | 30 October 2001 |
| CVE-2001-0540 | Memory leak in Terminal servers in Windows NT and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed Remote Desktop Protocol (RDP) requests to port 3389. | MEDIUM 5.0EPSS 71.2% | 30 October 2001 |
| CVE-2001-0505 | Multiple memory leaks in Microsoft Services for Unix 2.0 allow remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed requests to (1) the Telnet service, or (2) the NFS service. | MEDIUM 5.0EPSS 33.4% | 30 October 2001 |
| CVE-2001-0779 | Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username. | EXPLOIT ✓HIGH 10.0EPSS 62.2% | 18 October 2001 |
| CVE-2001-0775 | Buffer overflow in xloadimage 4.1 (aka xli 1.16 and 1.17) in Linux allows remote attackers to execute arbitrary code via a FACES format image containing a long (1) Firstname or (2) Lastname field. | EXPLOIT ✓HIGH 7.5EPSS 16.3% | 18 October 2001 |
| CVE-2001-0763 | Buffer overflow in Linux xinetd 2.1.8.9pre11-1 and earlier may allow remote attackers to execute arbitrary code via a long ident response, which is not properly handled by the svc_logprint function. | EXPLOIT ✓HIGH 7.5EPSS 17.2% | 18 October 2001 |
| CVE-2001-0746 | Buffer overflow in Web Publisher in iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request for a long URI with (1) GETPROPERTIES, (2)… | EXPLOIT ×2 ✓HIGH 10.0EPSS 15.2% | 18 October 2001 |
| CVE-2001-0731 | Apache 1.3.20 with Multiviews enabled allows remote attackers to view directory contents and bypass the index page via a URL containing the "M=D" query string. | EXPLOIT ✓MEDIUM 5.0EPSS 56.8% | 1 October 2001 |
| CVE-2001-0709 | Microsoft IIS 4.0 and before, when installed on a FAT partition, allows a remote attacker to obtain source code of ASP files via a URL encoded with Unicode. | MEDIUM 5.0EPSS 35.6% | 20 September 2001 |
| CVE-2001-0700 | Buffer overflow in w3m 0.2.1 and earlier allows a remote attacker to execute arbitrary code via a long base64 encoded MIME header. | EXPLOIT ✓HIGH 7.5EPSS 12.6% | 20 September 2001 |
| CVE-2001-0690 | Format string vulnerability in exim (3.22-10 in Red Hat, 3.12 in Debian and 3.16 in Conectiva) in batched SMTP mode allows a remote attacker to execute arbitrary code via format strings in SMTP mail headers. | EXPLOIT ✓HIGH 7.5EPSS 11.9% | 20 September 2001 |
| CVE-2001-0658 | Cross-site scripting (CSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause other clients to execute certain script or read cookies via malicious script in an invalid URL that is not… | HIGH 7.5EPSS 14.2% | 20 September 2001 |
| CVE-2001-0643 | Internet Explorer 5.5 does not display the Class ID (CLSID) when it is at the end of the file name, which could allow attackers to trick the user into executing dangerous programs by making it appear that the document is of a safe file type. | EXPLOIT ✓MEDIUM 5.0EPSS 11.4% | 20 September 2001 |
| CVE-2001-0552 | ovactiond in HP OpenView Network Node Manager (NNM) 6.1 and Tivoli Netview 5.x and 6.x allows remote attackers to execute arbitrary commands via shell metacharacters in a certain SNMP trap message. | EXPLOIT ✓HIGH 10.0EPSS 26.2% | 20 September 2001 |
| CVE-2001-0546 | Memory leak in H.323 Gatekeeper Service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (resource exhaustion) via a large amount of malformed H.323 data. | MEDIUM 5.0EPSS 17.3% | 20 September 2001 |
| CVE-2001-0543 | Memory leak in NNTP service in Windows NT 4.0 and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed posts. | MEDIUM 5.0EPSS 18.8% | 20 September 2001 |
| CVE-2001-0541 | Buffer overflow in Microsoft Windows Media Player 7.1 and earlier allows remote attackers to execute arbitrary commands via a malformed Windows Media Station (.NSC) file. | HIGH 7.5EPSS 15.6% | 20 September 2001 |
| CVE-2001-0509 | Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs. | MEDIUM 5.0EPSS 17.0% | 20 September 2001 |
| CVE-2001-0508 | Vulnerability in IIS 5.0 allows remote attackers to cause a denial of service (restart) via a long, invalid WebDAV request. | MEDIUM 5.0EPSS 27.1% | 20 September 2001 |
| CVE-2001-0506 | Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation"… | EXPLOIT ✓HIGH 7.2EPSS 68.9% | 20 September 2001 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.