SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,163 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

17,157 results · page 335 of 344

CVESummaryPriorityPublished
CVE-2001-0986SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as the physical path, file attributes, or portions of source code by directly calling sqlqhit.asp with a CiScope parameter set to (1)…EXPLOITMEDIUM 5.0EPSS 48.2%14 September 2001
CVE-2001-1112Buffer overflow in EFTP 2.0.7.337 allows remote attackers to execute arbitrary code by uploading a .lnk file containing a large number of characters.EXPLOITHIGH 7.5EPSS 10.6%12 September 2001
CVE-2001-1013Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid…EXPLOITMEDIUM 5.0EPSS 65.6%12 September 2001
CVE-2001-0999Outlook Express 6.00 allows remote attackers to execute arbitrary script by embedding SCRIPT tags in a message whose MIME content type is text/plain, contrary to the expected behavior that text/plain messages will not run script.HIGH 7.5EPSS 12.3%12 September 2001
CVE-2001-1138Directory traversal vulnerability in r.pl (aka r.cgi) of Randy Parker Power Up HTML 0.8033beta allows remote attackers to read arbitrary files and possibly execute arbitrary code via a ..EXPLOITHIGH 7.5EPSS 10.3%7 September 2001
CVE-2001-1067Buffer overflow in AOLserver 3.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via an HTTP request with a long Authorization header.EXPLOIT ×2HIGH 10.0EPSS 16.1%31 August 2001
CVE-2000-1200Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SID to list the users.MEDIUM 5.0EPSS 48.1%31 August 2001
CVE-2001-0561Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in (1) a1disp2.cgi, (2) a1disp3.cgi, or (3) a1disp4.cgi.EXPLOIT ×3HIGH 7.5EPSS 12.5%14 August 2001
CVE-2001-0557Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a '..' (dot dot) attack which is URL encoded (%2e%2e).EXPLOITMEDIUM 5.0EPSS 10.5%14 August 2001
CVE-2001-0555ScreamingMedia SITEWare versions 2.5 through 3.1 allows a remote attacker to read world-readable files via a ..EXPLOITHIGH 10.0EPSS 15.0%14 August 2001
CVE-2001-0554Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.EXPLOITHIGH 10.0EPSS 38.7%14 August 2001
CVE-2001-0538Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page.EXPLOIT ×2HIGH 10.0EPSS 52.9%14 August 2001
CVE-2001-0522Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in the original filename that is stored in an encrypted file.EXPLOITHIGH 7.5EPSS 13.7%14 August 2001
CVE-2001-0504Vulnerability in authentication process for SMTP service in Microsoft Windows 2000 allows remote attackers to use incorrect credentials to gain privileges and conduct activities such as mail relaying.HIGH 7.5EPSS 21.1%14 August 2001
CVE-2001-1130Sdbsearch.cgi in SuSE Linux 6.0-7.2 could allow remote attackers to execute arbitrary commands by uploading a keylist.txt file that contains filenames with shell metacharacters, then causing the file to be searched using a .. in the HTTP referer (from…EXPLOITHIGH 7.5EPSS 10.8%2 August 2001
CVE-2001-0609Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed ident reply that is passed to the syslog function.EXPLOIT ×2CRITICAL 9.8EPSS 18.2%2 August 2001
CVE-2001-0590Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e.EXPLOITMEDIUM 5.0EPSS 11.0%2 August 2001
CVE-2001-1055The Microsoft Windows network stack allows remote attackers to cause a denial of service (CPU consumption) via a flood of malformed ARP request packets with random source IP and MAC addresses, as demonstrated by ARPNuke.EXPLOITMEDIUM 5.0EPSS 22.3%30 July 2001
CVE-2001-1022Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass the -S option and execute arbitrary commands via format string specifiers in the plot command.EXPLOITHIGH 7.5EPSS 11.4%26 July 2001
CVE-2001-1021Buffer overflows in WS_FTP 2.02 allow remote attackers to execute arbitrary code via long arguments to (1) DELE, (2) MDTM, (3) MLST, (4) MKD, (5) RMD, (6) RNFR, (7) RNTO, (8) SIZE, (9) STAT, (10) XMKD, or (11) XRMD.EXPLOIT ×2HIGH 7.5EPSS 42.1%26 July 2001
CVE-2001-1370prepend.php3 in PHPLib before 7.2d, when register_globals is enabled for PHP, allows remote attackers to execute arbitrary scripts via an HTTP request that modifies $_PHPLIB[libdir] to point to malicious code on another server, as seen in Horde 1.2.5…EXPLOITHIGH 10.0EPSS 17.2%21 July 2001
CVE-2001-0537HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL.EXPLOIT ×4HIGH 9.3EPSS 68.5%21 July 2001
CVE-2001-0503Microsoft NetMeeting 3.01 with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service via a malformed string to the NetMeeting service port, aka a variant of the "NetMeeting Desktop Sharing" vulnerability.MEDIUM 5.0EPSS 17.3%21 July 2001
CVE-2001-0500Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data…EXPLOIT ×5HIGH 10.0EPSS 96.7%21 July 2001
CVE-2001-0499Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers to gain privileges via a long argument to the commands (1) STATUS, (2) PING, (3) SERVICES, (4) TRC_FILE, (5) SAVE_CONFIG, or (6) RELOAD.EXPLOIT ×2HIGH 10.0EPSS 85.2%21 July 2001
CVE-2001-0348Microsoft Windows 2000 telnet service allows attackers to cause a denial of service (crash) via a long logon command that contains a backspace.EXPLOITMEDIUM 5.0EPSS 17.2%21 July 2001
CVE-2001-0347Information disclosure vulnerability in Microsoft Windows 2000 telnet service allows remote attackers to determine the existence of user accounts such as Guest, or log in to the server without specifying the domain name, via a malformed userid.HIGH 7.5EPSS 13.8%21 July 2001
CVE-2001-0341Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attackers to execute arbitrary commands via a long registration request (URL) to fp30reg.dll.EXPLOIT ×2HIGH 7.5EPSS 27.9%21 July 2001
CVE-2001-0018Windows 2000 domain controller in Windows 2000 Server, Advanced Server, or Datacenter Server allows remote attackers to cause a denial of service via a flood of malformed service requests.MEDIUM 5.0EPSS 18.3%21 July 2001
CVE-2001-0002Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs.HIGH 7.5EPSS 20.2%21 July 2001
CVE-2001-1320Network Associates PGP Keyserver 7.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via exceptional BER encodings (possibly buffer overflows), as demonstrated by the PROTOS LDAPv3 test suite.EXPLOITHIGH 7.5EPSS 68.3%16 July 2001
CVE-2001-1319Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP filter type field, as demonstrated by the PROTOS LDAPv3 test suite.MEDIUM 5.0EPSS 33.3%16 July 2001
CVE-2001-1244Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets…EXPLOITMEDIUM 5.0EPSS 22.0%7 July 2001
CVE-2001-1243Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or…EXPLOIT ×2MEDIUM 5.0EPSS 70.5%4 July 2001
CVE-2001-0432Buffer overflows in various CGI programs in the remote administration service for Trend Micro Interscan VirusWall 3.01 allow remote attackers to execute arbitrary commands.EXPLOITHIGH 10.0EPSS 10.7%2 July 2001
CVE-2001-0419Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute arbitrary commands via a long HTTP request that is passed to the…EXPLOITHIGH 7.5EPSS 24.4%2 July 2001
CVE-2001-0405ip_conntrack_ftp in the IPTables firewall for Linux 2.4 allows remote attackers to bypass access restrictions for an FTP server via a PORT command that lists an arbitrary IP address and port number, which is added to the RELATED table and allowed by the…EXPLOITHIGH 7.5EPSS 10.3%2 July 2001
CVE-2001-0400nph-maillist.pl allows remote attackers to execute arbitrary commands via shell metacharacters ("`") in the email address.EXPLOITHIGH 7.5EPSS 16.6%2 July 2001
CVE-2001-0239Microsoft Internet Security and Acceleration (ISA) Server 2000 Web Proxy allows remote attackers to cause a denial of service via a long web request with a specific type.EXPLOITHIGH 7.5EPSS 28.0%2 July 2001
CVE-2001-0238Microsoft Data Access Component Internet Publishing Provider 8.103.2519.0 and earlier allows remote attackers to bypass Security Zone restrictions via WebDAV requests.HIGH 7.5EPSS 14.8%2 July 2001
CVE-2001-0339Internet Explorer 5.5 and earlier allows remote attackers to display a URL in the address bar that is different than the URL that is actually being displayed, which could be used in web site spoofing attacks, aka the "Web page spoofing vulnerability."HIGH 7.5EPSS 15.0%27 June 2001
CVE-2001-0336The Microsoft MS00-060 patch for IIS 5.0 and earlier introduces an error which allows attackers to cause a denial of service via a malformed request.EXPLOITMEDIUM 5.0EPSS 15.9%27 June 2001
CVE-2001-0335FTP service in IIS 5.0 and earlier allows remote attackers to enumerate Guest accounts in trusted domains by preceding the username with a special sequence of characters.MEDIUM 5.0EPSS 21.0%27 June 2001
CVE-2001-0334FTP service in IIS 5.0 and earlier allows remote attackers to cause a denial of service via a wildcard sequence that generates a long string when it is expanded.HIGH 7.5EPSS 14.7%27 June 2001
CVE-2001-0333Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding ..EXPLOIT ×9HIGH 7.5EPSS 90.8%27 June 2001
CVE-2001-0328TCP implementations that use random increments for initial sequence numbers (ISN) can allow remote attackers to perform session hijacking or disruption by injecting a flood of packets with a range of ISN values, one of which may match the expected ISN.EXPLOITMEDIUM 5.0EPSS 18.1%27 June 2001
CVE-2001-0245Microsoft Index Server 2.0 in Windows NT 4.0, and Indexing Service in Windows 2000, allows remote attackers to read server-side include files via a malformed search request, aka a new variant of the "Malformed Hit-Highlighting" vulnerability.MEDIUM 5.0EPSS 14.3%27 June 2001
CVE-2001-0244Buffer overflow in Microsoft Index Server 2.0 allows remote attackers to execute arbitrary commands via a long search parameter.HIGH 7.5EPSS 14.7%27 June 2001
CVE-2001-0243Windows Media Player 7 and earlier stores Internet shortcuts in a user's Temporary Files folder with a fixed filename instead of in the Internet Explorer cache, which causes the HTML in those shortcuts to run in the Local Computer Zone instead of the…MEDIUM 5.0EPSS 17.6%27 June 2001
CVE-2001-0242Buffer overflows in Microsoft Windows Media Player 7 and earlier allow remote attackers to execute arbitrary commands via (1) a long version tag in an .ASX file, or (2) a long banner tag, a variant of the ".ASX Buffer Overrun" vulnerability as discussed…HIGH 7.5EPSS 30.0%27 June 2001

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.