SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,163 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

17,157 results · page 336 of 344

CVESummaryPriorityPublished
CVE-2001-0241Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print request that is passed to the extension through IIS 5.0.EXPLOIT ×7HIGH 10.0EPSS 85.7%27 June 2001
CVE-2001-0237Memory leak in Microsoft 2000 domain controller allows remote attackers to cause a denial of service by repeatedly connecting to the Kerberos service and then disconnecting without sending any data.MEDIUM 5.0EPSS 18.3%27 June 2001
CVE-2001-1162Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overwrite certain files via a .. in a NETBIOS name, which is used as the name for a .log file.EXPLOITHIGH 10.0EPSS 12.0%23 June 2001
CVE-2001-1328Buffer overflow in ypbind daemon in Solaris 5.4 through 8 allows remote attackers to execute arbitrary code.HIGH 7.5EPSS 16.9%22 June 2001
CVE-2001-0414Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long readvar argument.EXPLOIT ×3HIGH 10.0EPSS 91.7%18 June 2001
CVE-2001-0375Cisco PIX Firewall 515 and 520 with 5.1.4 OS running aaa authentication to a TACACS+ server allows remote attackers to cause a denial of service via a large number of authentication requests.EXPLOITMEDIUM 5.0EPSS 10.3%18 June 2001
CVE-2001-0249Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings.CRITICAL 9.8EPSS 19.7%18 June 2001
CVE-2001-0248Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT command, which uses glob to generate long strings.CRITICAL 9.8EPSS 11.2%18 June 2001
CVE-2001-0247Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buffer as used in the glob functions…EXPLOIT ×3HIGH 10.0EPSS 19.3%18 June 2001
CVE-2001-1163Buffer overflow in Munica Corporation NetSQL 1.0 allows remote attackers to execute arbitrary code via a long CONNECT argument to port 6500.EXPLOITHIGH 10.0EPSS 11.2%16 June 2001
CVE-2001-1088Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book" option enabled, do not notify the user when the "Reply-To" address is different than the "From" address, which could…EXPLOITHIGH 7.5EPSS 19.7%5 June 2001
CVE-2001-0322MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to cause a denial of service (application crash) via a script that creates and deletes an object that is associated with the browser window object.EXPLOITMEDIUM 5.0EPSS 21.0%2 June 2001
CVE-2001-0318Format string vulnerability in ProFTPD 1.2.0rc2 may allow attackers to execute arbitrary commands by shutting down the FTP server while using a malformed working directory (cwd).HIGH 7.5EPSS 11.4%2 June 2001
CVE-2001-0311Vulnerability in OmniBackII A.03.50 in HP 11.x and earlier allows attackers to gain unauthorized access to an OmniBack client.EXPLOIT ×3MEDIUM 4.6EPSS 11.6%2 June 2001
CVE-2001-0253Directory traversal vulnerability in hsx.cgi program in iWeb Hyperseek 2000 allows remote attackers to read arbitrary files and directories via a ..EXPLOITMEDIUM 5.0EPSS 10.6%2 June 2001
CVE-2001-0212Directory traversal vulnerability in HIS Auktion 1.62 allows remote attackers to read arbitrary files via a ..EXPLOITHIGH 7.5EPSS 17.0%2 June 2001
CVE-2001-0151IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests.EXPLOITMEDIUM 5.0EPSS 67.9%2 June 2001
CVE-2001-0150Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web site, which could allow remote attackers to execute arbitrary commands if the IE client is using the Telnet client provided in Services…EXPLOITMEDIUM 5.1EPSS 17.6%2 June 2001
CVE-2001-0149Windows Scripting Host in Internet Explorer 5.5 and earlier allows remote attackers to read arbitrary files via the GetObject Javascript function and the htmlfile ActiveX object.EXPLOITMEDIUM 5.0EPSS 32.2%2 June 2001
CVE-2001-0148The WMP ActiveX Control in Windows Media Player 7 allows remote attackers to execute commands in Internet Explorer via javascript URLs, a variant of the "Frame Domain Verification" vulnerability.EXPLOITHIGH 7.5EPSS 26.8%2 June 2001
CVE-2001-0146IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's.MEDIUM 5.0EPSS 37.1%2 June 2001
CVE-2001-1342Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null…MEDIUM 5.0EPSS 12.0%12 May 2001
CVE-2001-0324Windows 98 and Windows 2000 Java clients allow remote attackers to cause a denial of service via a Java applet that opens a large number of UDP sockets, which prevents the host from establishing any additional UDP connections, and possibly causes a crash.EXPLOITLOW 2.6EPSS 14.3%3 May 2001
CVE-2001-0280Buffer overflow in MERCUR SMTP server 3.30 allows remote attackers to execute arbitrary commands via a long EXPN command.EXPLOITHIGH 10.0EPSS 13.0%3 May 2001
CVE-2001-0277Buffer overflow in ext.dll in BadBlue 1.02.07 Personal Edition allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP GET request.EXPLOITHIGH 10.0EPSS 11.0%3 May 2001
CVE-2001-0236Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long "indication" event.EXPLOIT ×2HIGH 10.0EPSS 72.0%3 May 2001
CVE-2001-0205Directory traversal vulnerability in AOLserver 3.2 and earlier allows remote attackers to read arbitrary files by inserting "..." into the requested pathname, a modified ..EXPLOITMEDIUM 5.0EPSS 23.6%3 May 2001
CVE-2001-0199Directory traversal vulnerability in SEDUM HTTP Server 2.0 allows remote attackers to read arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 10.8%3 May 2001
CVE-2001-0171Buffer overflow in SlimServe HTTPd 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long GET request.EXPLOITHIGH 10.0EPSS 12.3%3 May 2001
CVE-2001-0168Buffer overflow in AT&T WinVNC (Virtual Network Computing) server 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long HTTP GET request when the DebugLevel registry key is greater than 0.EXPLOITHIGH 10.0EPSS 70.7%3 May 2001
CVE-2001-0167Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long rfbConnFailed packet with a long reason string.EXPLOITHIGH 7.6EPSS 50.8%3 May 2001
CVE-2001-0154HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly.HIGH 7.5EPSS 11.2%3 May 2001
CVE-2001-0153Buffer overflow in VB-TSQL debugger object (vbsdicli.exe) in Visual Studio 6.0 Enterprise Edition allows remote attackers to execute arbitrary commands.HIGH 7.5EPSS 12.4%3 May 2001
CVE-2001-1325Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML stylesheets (XSL) that are referenced using an IFRAME tag, possibly due to a…EXPLOITHIGH 7.5EPSS 27.3%20 April 2001
CVE-2001-0233Buffer overflow in micq client 0.4.6 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Description field.EXPLOITHIGH 10.0EPSS 14.6%26 March 2001
CVE-2001-0197Format string vulnerability in print_client in icecast 1.3.8beta2 and earlier allows remote attackers to execute arbitrary commands.EXPLOITHIGH 10.0EPSS 13.1%26 March 2001
CVE-2001-0925The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1)…EXPLOIT ×4MEDIUM 5.0EPSS 75.2%12 March 2001
CVE-2001-0144CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an integer overflow.EXPLOIT ×2HIGH 10.0EPSS 32.4%12 March 2001
CVE-2001-0137Windows Media Player 7 allows remote attackers to execute malicious Java applets in Internet Explorer clients by enclosing the applet in a skin file named skin.wmz, then referencing that skin in the codebase parameter to an applet tag, aka the Windows…EXPLOITMEDIUM 5.1EPSS 22.2%12 March 2001
CVE-2001-0136Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commands if the server has been improperly installed.EXPLOIT ×3MEDIUM 5.0EPSS 44.9%12 March 2001
CVE-2001-0129Buffer overflow in Tinyproxy HTTP proxy 1.3.3 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long connect request.EXPLOITHIGH 10.0EPSS 13.9%12 March 2001
CVE-2001-0113statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to execute arbitrary commands via the mostbrowsers parameter, whose value is used as part of a generated Perl script.EXPLOITHIGH 10.0EPSS 10.4%12 March 2001
CVE-2001-0017Memory leak in PPTP server in Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed data packet, aka the "Malformed PPTP Packet Stream" vulnerability.MEDIUM 5.0EPSS 17.3%12 March 2001
CVE-1999-0945Buffer overflow in Internet Mail Service (IMS) for Microsoft Exchange 5.5 and 5.0 allows remote attackers to conduct a denial of service via AUTH or AUTHINFO commands.MEDIUM 5.0EPSS 19.5%12 March 2001
CVE-1999-0681Buffer overflow in Microsoft FrontPage Server Extensions (PWS) 3.0.2.926 on Windows 95, and possibly other versions, allows remote attackers to cause a denial of service via a long URL.EXPLOITMEDIUM 5.0EPSS 20.5%12 March 2001
CVE-2001-0092A function in Internet Explorer 5.0 through 5.5 does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a new variant of the "Frame Domain Verification" vulnerability.LOW 2.6EPSS 12.2%16 February 2001
CVE-2001-0089Internet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client via the INPUT TYPE element in an HTML form, aka the "File Upload via Form" vulnerability.EXPLOITLOW 2.6EPSS 14.5%16 February 2001
CVE-2001-0054Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as "/..%20." to a CD command, a variant of a ..EXPLOITMEDIUM 5.0EPSS 12.0%16 February 2001
CVE-2001-0050Buffer overflow in BitchX IRC client allows remote attackers to cause a denial of service and possibly execute arbitrary commands via an IP address that resolves to a long DNS hostname or domain name.EXPLOITHIGH 10.0EPSS 14.6%16 February 2001
CVE-2001-0041Memory leak in Cisco Catalyst 4000, 5000, and 6000 series switches allows remote attackers to cause a denial of service via a series of failed telnet authentication attempts.EXPLOITHIGH 7.8EPSS 12.1%16 February 2001

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.