Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,163 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
17,157 results · page 335 of 344
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2001-0986 | SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as the physical path, file attributes, or portions of source code by directly calling sqlqhit.asp with a CiScope parameter set to (1)… | EXPLOIT ✓MEDIUM 5.0EPSS 48.2% | 14 September 2001 |
| CVE-2001-1112 | Buffer overflow in EFTP 2.0.7.337 allows remote attackers to execute arbitrary code by uploading a .lnk file containing a large number of characters. | EXPLOIT ✓HIGH 7.5EPSS 10.6% | 12 September 2001 |
| CVE-2001-1013 | Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid… | EXPLOIT ✓MEDIUM 5.0EPSS 65.6% | 12 September 2001 |
| CVE-2001-0999 | Outlook Express 6.00 allows remote attackers to execute arbitrary script by embedding SCRIPT tags in a message whose MIME content type is text/plain, contrary to the expected behavior that text/plain messages will not run script. | HIGH 7.5EPSS 12.3% | 12 September 2001 |
| CVE-2001-1138 | Directory traversal vulnerability in r.pl (aka r.cgi) of Randy Parker Power Up HTML 0.8033beta allows remote attackers to read arbitrary files and possibly execute arbitrary code via a .. | EXPLOIT ✓HIGH 7.5EPSS 10.3% | 7 September 2001 |
| CVE-2001-1067 | Buffer overflow in AOLserver 3.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via an HTTP request with a long Authorization header. | EXPLOIT ×2 ✓HIGH 10.0EPSS 16.1% | 31 August 2001 |
| CVE-2000-1200 | Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SID to list the users. | MEDIUM 5.0EPSS 48.1% | 31 August 2001 |
| CVE-2001-0561 | Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in (1) a1disp2.cgi, (2) a1disp3.cgi, or (3) a1disp4.cgi. | EXPLOIT ×3 ✓HIGH 7.5EPSS 12.5% | 14 August 2001 |
| CVE-2001-0557 | Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a '..' (dot dot) attack which is URL encoded (%2e%2e). | EXPLOIT ✓MEDIUM 5.0EPSS 10.5% | 14 August 2001 |
| CVE-2001-0555 | ScreamingMedia SITEWare versions 2.5 through 3.1 allows a remote attacker to read world-readable files via a .. | EXPLOIT ✓HIGH 10.0EPSS 15.0% | 14 August 2001 |
| CVE-2001-0554 | Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function. | EXPLOIT ✓HIGH 10.0EPSS 38.7% | 14 August 2001 |
| CVE-2001-0538 | Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page. | EXPLOIT ×2 ✓HIGH 10.0EPSS 52.9% | 14 August 2001 |
| CVE-2001-0522 | Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in the original filename that is stored in an encrypted file. | EXPLOIT ✓HIGH 7.5EPSS 13.7% | 14 August 2001 |
| CVE-2001-0504 | Vulnerability in authentication process for SMTP service in Microsoft Windows 2000 allows remote attackers to use incorrect credentials to gain privileges and conduct activities such as mail relaying. | HIGH 7.5EPSS 21.1% | 14 August 2001 |
| CVE-2001-1130 | Sdbsearch.cgi in SuSE Linux 6.0-7.2 could allow remote attackers to execute arbitrary commands by uploading a keylist.txt file that contains filenames with shell metacharacters, then causing the file to be searched using a .. in the HTTP referer (from… | EXPLOIT ✓HIGH 7.5EPSS 10.8% | 2 August 2001 |
| CVE-2001-0609 | Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed ident reply that is passed to the syslog function. | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 18.2% | 2 August 2001 |
| CVE-2001-0590 | Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. | EXPLOIT ✓MEDIUM 5.0EPSS 11.0% | 2 August 2001 |
| CVE-2001-1055 | The Microsoft Windows network stack allows remote attackers to cause a denial of service (CPU consumption) via a flood of malformed ARP request packets with random source IP and MAC addresses, as demonstrated by ARPNuke. | EXPLOIT ✓MEDIUM 5.0EPSS 22.3% | 30 July 2001 |
| CVE-2001-1022 | Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass the -S option and execute arbitrary commands via format string specifiers in the plot command. | EXPLOIT ✓HIGH 7.5EPSS 11.4% | 26 July 2001 |
| CVE-2001-1021 | Buffer overflows in WS_FTP 2.02 allow remote attackers to execute arbitrary code via long arguments to (1) DELE, (2) MDTM, (3) MLST, (4) MKD, (5) RMD, (6) RNFR, (7) RNTO, (8) SIZE, (9) STAT, (10) XMKD, or (11) XRMD. | EXPLOIT ×2 ✓HIGH 7.5EPSS 42.1% | 26 July 2001 |
| CVE-2001-1370 | prepend.php3 in PHPLib before 7.2d, when register_globals is enabled for PHP, allows remote attackers to execute arbitrary scripts via an HTTP request that modifies $_PHPLIB[libdir] to point to malicious code on another server, as seen in Horde 1.2.5… | EXPLOIT ✓HIGH 10.0EPSS 17.2% | 21 July 2001 |
| CVE-2001-0537 | HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL. | EXPLOIT ×4 ✓HIGH 9.3EPSS 68.5% | 21 July 2001 |
| CVE-2001-0503 | Microsoft NetMeeting 3.01 with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service via a malformed string to the NetMeeting service port, aka a variant of the "NetMeeting Desktop Sharing" vulnerability. | MEDIUM 5.0EPSS 17.3% | 21 July 2001 |
| CVE-2001-0500 | Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data… | EXPLOIT ×5 ✓HIGH 10.0EPSS 96.7% | 21 July 2001 |
| CVE-2001-0499 | Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers to gain privileges via a long argument to the commands (1) STATUS, (2) PING, (3) SERVICES, (4) TRC_FILE, (5) SAVE_CONFIG, or (6) RELOAD. | EXPLOIT ×2 ✓HIGH 10.0EPSS 85.2% | 21 July 2001 |
| CVE-2001-0348 | Microsoft Windows 2000 telnet service allows attackers to cause a denial of service (crash) via a long logon command that contains a backspace. | EXPLOIT ✓MEDIUM 5.0EPSS 17.2% | 21 July 2001 |
| CVE-2001-0347 | Information disclosure vulnerability in Microsoft Windows 2000 telnet service allows remote attackers to determine the existence of user accounts such as Guest, or log in to the server without specifying the domain name, via a malformed userid. | HIGH 7.5EPSS 13.8% | 21 July 2001 |
| CVE-2001-0341 | Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attackers to execute arbitrary commands via a long registration request (URL) to fp30reg.dll. | EXPLOIT ×2 ✓HIGH 7.5EPSS 27.9% | 21 July 2001 |
| CVE-2001-0018 | Windows 2000 domain controller in Windows 2000 Server, Advanced Server, or Datacenter Server allows remote attackers to cause a denial of service via a flood of malformed service requests. | MEDIUM 5.0EPSS 18.3% | 21 July 2001 |
| CVE-2001-0002 | Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs. | HIGH 7.5EPSS 20.2% | 21 July 2001 |
| CVE-2001-1320 | Network Associates PGP Keyserver 7.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via exceptional BER encodings (possibly buffer overflows), as demonstrated by the PROTOS LDAPv3 test suite. | EXPLOIT ✓HIGH 7.5EPSS 68.3% | 16 July 2001 |
| CVE-2001-1319 | Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP filter type field, as demonstrated by the PROTOS LDAPv3 test suite. | MEDIUM 5.0EPSS 33.3% | 16 July 2001 |
| CVE-2001-1244 | Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets… | EXPLOIT ✓MEDIUM 5.0EPSS 22.0% | 7 July 2001 |
| CVE-2001-1243 | Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or… | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 70.5% | 4 July 2001 |
| CVE-2001-0432 | Buffer overflows in various CGI programs in the remote administration service for Trend Micro Interscan VirusWall 3.01 allow remote attackers to execute arbitrary commands. | EXPLOIT ✓HIGH 10.0EPSS 10.7% | 2 July 2001 |
| CVE-2001-0419 | Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute arbitrary commands via a long HTTP request that is passed to the… | EXPLOIT ✓HIGH 7.5EPSS 24.4% | 2 July 2001 |
| CVE-2001-0405 | ip_conntrack_ftp in the IPTables firewall for Linux 2.4 allows remote attackers to bypass access restrictions for an FTP server via a PORT command that lists an arbitrary IP address and port number, which is added to the RELATED table and allowed by the… | EXPLOIT ✓HIGH 7.5EPSS 10.3% | 2 July 2001 |
| CVE-2001-0400 | nph-maillist.pl allows remote attackers to execute arbitrary commands via shell metacharacters ("`") in the email address. | EXPLOIT ✓HIGH 7.5EPSS 16.6% | 2 July 2001 |
| CVE-2001-0239 | Microsoft Internet Security and Acceleration (ISA) Server 2000 Web Proxy allows remote attackers to cause a denial of service via a long web request with a specific type. | EXPLOIT ✓HIGH 7.5EPSS 28.0% | 2 July 2001 |
| CVE-2001-0238 | Microsoft Data Access Component Internet Publishing Provider 8.103.2519.0 and earlier allows remote attackers to bypass Security Zone restrictions via WebDAV requests. | HIGH 7.5EPSS 14.8% | 2 July 2001 |
| CVE-2001-0339 | Internet Explorer 5.5 and earlier allows remote attackers to display a URL in the address bar that is different than the URL that is actually being displayed, which could be used in web site spoofing attacks, aka the "Web page spoofing vulnerability." | HIGH 7.5EPSS 15.0% | 27 June 2001 |
| CVE-2001-0336 | The Microsoft MS00-060 patch for IIS 5.0 and earlier introduces an error which allows attackers to cause a denial of service via a malformed request. | EXPLOIT ✓MEDIUM 5.0EPSS 15.9% | 27 June 2001 |
| CVE-2001-0335 | FTP service in IIS 5.0 and earlier allows remote attackers to enumerate Guest accounts in trusted domains by preceding the username with a special sequence of characters. | MEDIUM 5.0EPSS 21.0% | 27 June 2001 |
| CVE-2001-0334 | FTP service in IIS 5.0 and earlier allows remote attackers to cause a denial of service via a wildcard sequence that generates a long string when it is expanded. | HIGH 7.5EPSS 14.7% | 27 June 2001 |
| CVE-2001-0333 | Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. | EXPLOIT ×9 ✓HIGH 7.5EPSS 90.8% | 27 June 2001 |
| CVE-2001-0328 | TCP implementations that use random increments for initial sequence numbers (ISN) can allow remote attackers to perform session hijacking or disruption by injecting a flood of packets with a range of ISN values, one of which may match the expected ISN. | EXPLOIT ✓MEDIUM 5.0EPSS 18.1% | 27 June 2001 |
| CVE-2001-0245 | Microsoft Index Server 2.0 in Windows NT 4.0, and Indexing Service in Windows 2000, allows remote attackers to read server-side include files via a malformed search request, aka a new variant of the "Malformed Hit-Highlighting" vulnerability. | MEDIUM 5.0EPSS 14.3% | 27 June 2001 |
| CVE-2001-0244 | Buffer overflow in Microsoft Index Server 2.0 allows remote attackers to execute arbitrary commands via a long search parameter. | HIGH 7.5EPSS 14.7% | 27 June 2001 |
| CVE-2001-0243 | Windows Media Player 7 and earlier stores Internet shortcuts in a user's Temporary Files folder with a fixed filename instead of in the Internet Explorer cache, which causes the HTML in those shortcuts to run in the Local Computer Zone instead of the… | MEDIUM 5.0EPSS 17.6% | 27 June 2001 |
| CVE-2001-0242 | Buffer overflows in Microsoft Windows Media Player 7 and earlier allow remote attackers to execute arbitrary commands via (1) a long version tag in an .ASX file, or (2) a long banner tag, a variant of the ".ASX Buffer Overrun" vulnerability as discussed… | HIGH 7.5EPSS 30.0% | 27 June 2001 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.