Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,163 CVEs1,721 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
17,157 results · page 337 of 344
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2001-0021 | MailMan Webmail 3.0.25 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the alternate_template parameter. | EXPLOIT ✓HIGH 10.0EPSS 13.5% | 16 February 2001 |
| CVE-2001-0100 | bslist.cgi mailing list script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address. | EXPLOIT ✓HIGH 10.0EPSS 15.6% | 12 February 2001 |
| CVE-2001-0099 | bsguest.cgi guestbook script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address. | EXPLOIT ✓HIGH 10.0EPSS 13.3% | 12 February 2001 |
| CVE-2001-0098 | Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".." string. | EXPLOIT ✓HIGH 10.0EPSS 78.4% | 12 February 2001 |
| CVE-2001-0096 | FrontPage Server Extensions (FPSE) in IIS 4.0 and 5.0 allows remote attackers to cause a denial of service via a malformed form, aka the "Malformed Web Form Submission" vulnerability. | MEDIUM 5.0EPSS 20.3% | 12 February 2001 |
| CVE-2001-0083 | Windows Media Unicast Service in Windows Media Services 4.0 and 4.1 does not properly shut down some types of connections, producing a memory leak that allows remote attackers to cause a denial of service via a series of severed connections, aka the… | MEDIUM 5.0EPSS 17.3% | 12 February 2001 |
| CVE-2001-0053 | One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges. | EXPLOIT ×2 ✓HIGH 10.0EPSS 17.9% | 12 February 2001 |
| CVE-2001-0025 | ad.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter. | EXPLOIT ✓HIGH 10.0EPSS 12.3% | 12 February 2001 |
| CVE-2001-0023 | everythingform.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter. | EXPLOIT ✓HIGH 10.0EPSS 14.4% | 12 February 2001 |
| CVE-2001-0022 | simplestguest.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the guestbook parameter. | EXPLOIT ✓HIGH 10.0EPSS 12.6% | 12 February 2001 |
| CVE-2001-0014 | Remote Data Protocol (RDP) in Windows 2000 Terminal Service does not properly handle certain malformed packets, which allows remote attackers to cause a denial of service, aka the "Invalid RDP Data" vulnerability. | MEDIUM 5.0EPSS 13.3% | 12 February 2001 |
| CVE-2001-0013 | Format string vulnerability in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges. | HIGH 10.0EPSS 10.8% | 12 February 2001 |
| CVE-2001-0010 | Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges. | EXPLOIT ×4 ✓HIGH 10.0EPSS 31.6% | 12 February 2001 |
| CVE-2001-0008 | Backdoor account in Interbase database server allows remote attackers to overwrite arbitrary files using stored procedures. | EXPLOIT ✓HIGH 10.0EPSS 13.3% | 12 February 2001 |
| CVE-2001-0004 | IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Reading… | MEDIUM 5.0EPSS 28.2% | 12 February 2001 |
| CVE-2000-1090 | Microsoft IIS for Far East editions 4.0 and 5.0 allows remote attackers to read source code for parsed pages via a malformed URL that uses the lead-byte of a double-byte character. | MEDIUM 5.0EPSS 16.7% | 12 February 2001 |
| CVE-2001-1453 | Buffer overflow in libmysqlclient.so in MySQL 3.23.33 and earlier allows remote attackers to execute arbitrary code via a long host parameter. | HIGH 7.5EPSS 11.3% | 9 February 2001 |
| CVE-2000-1149 | Buffer overflow in RegAPI.DLL used by Windows NT 4.0 Terminal Server allows remote attackers to execute arbitrary commands via a long username, aka the "Terminal Server Login Buffer Overflow" vulnerability. | HIGH 7.5EPSS 16.1% | 9 January 2001 |
| CVE-2000-1113 | Buffer overflow in Microsoft Windows Media Player allows remote attackers to execute arbitrary commands via a malformed Active Stream Redirector (.ASX) file, aka the ".ASX Buffer Overrun" vulnerability. | EXPLOIT ✓HIGH 7.5EPSS 19.4% | 9 January 2001 |
| CVE-2000-1112 | Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gain privileges via a skin that contains a malicious script, aka the ".WMS Script Execution" vulnerability. | EXPLOIT ✓MEDIUM 4.6EPSS 14.0% | 9 January 2001 |
| CVE-2000-1111 | Telnet Service for Windows 2000 Professional does not properly terminate incomplete connection attempts, which allows remote attackers to cause a denial of service by connecting to the server and not providing any input. | MEDIUM 5.0EPSS 13.1% | 9 January 2001 |
| CVE-2000-1105 | The ixsso.query ActiveX Object is marked as safe for scripting, which allows malicious web site operators to embed a script that remotely determines the existence of files on visiting Windows 2000 systems that have Indexing Services enabled. | EXPLOIT ✓MEDIUM 4.3EPSS 10.8% | 9 January 2001 |
| CVE-2000-1089 | Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Service Buffer Overflow" vulnerability. | EXPLOIT ×2 ✓HIGH 10.0EPSS 74.6% | 9 January 2001 |
| CVE-2000-1039 | Various TCP/IP stacks and network applications allow remote attackers to cause a denial of service by flooding a target host with TCP connection attempts and completing the TCP/IP handshake without maintaining the connection state on the attacker host,… | MEDIUM 5.0EPSS 45.8% | 9 January 2001 |
| CVE-2001-0162 | WinCE 3.0.9348 generates predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections. | EXPLOIT ✓HIGH 7.5EPSS 15.2% | 1 January 2001 |
| CVE-2000-1227 | Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending multiple SMB SMBnegprots requests but not reading the response that is sent back. | MEDIUM 5.0EPSS 13.0% | 31 December 2000 |
| CVE-2000-0983 | Microsoft NetMeeting with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service (CPU utilization) via a sequence of null bytes to the NetMeeting port, aka the "NetMeeting Desktop Sharing" vulnerability. | EXPLOIT ✓MEDIUM 5.0EPSS 20.6% | 19 December 2000 |
| CVE-2000-0982 | Internet Explorer before 5.5 forwards cached user credentials for a secure web site to insecure pages on the same web site, which could allow remote attackers to obtain the credentials by monitoring connections to the web server, aka the "Cached Web… | HIGH 7.5EPSS 12.6% | 19 December 2000 |
| CVE-2000-0980 | NMPI (Name Management Protocol on IPX) listener in Microsoft NWLink does not properly filter packets from a broadcast address, which allows remote attackers to cause a broadcast storm and flood the network. | MEDIUM 5.0EPSS 13.2% | 19 December 2000 |
| CVE-2000-0979 | File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access controls by sending a 1-byte password that matches the first character… | EXPLOIT ×2 ✓MEDIUM 6.4EPSS 45.0% | 19 December 2000 |
| CVE-2000-0973 | Buffer overflow in curl earlier than 6.0-1.1, and curl-ssl earlier than 6.0-1.2, allows remote attackers to execute arbitrary commands by forcing a long error message to be generated. | EXPLOIT ×2 ✓HIGH 10.0EPSS 18.1% | 19 December 2000 |
| CVE-2000-0970 | IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie… | HIGH 7.5EPSS 45.7% | 19 December 2000 |
| CVE-2000-0967 | PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs. | EXPLOIT ×2 ✓HIGH 10.0EPSS 20.6% | 19 December 2000 |
| CVE-2000-0951 | A misconfiguration in IIS 5.0 with Index Server enabled and the Index property set allows remote attackers to list directories in the web root via a Web Distributed Authoring and Versioning (WebDAV) search. | EXPLOIT ✓MEDIUM 5.0EPSS 44.1% | 19 December 2000 |
| CVE-2000-0945 | The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands without authentication when the enable password is not set, via a URL containing the /exec/ directory. | EXPLOIT ✓HIGH 10.0EPSS 72.6% | 19 December 2000 |
| CVE-2000-0944 | CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, which allows remote attackers to modify the password without knowing the original password. | EXPLOIT ✓CRITICAL 9.8EPSS 11.3% | 19 December 2000 |
| CVE-2000-0942 | The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting"… | EXPLOIT ✓MEDIUM 5.1EPSS 22.4% | 19 December 2000 |
| CVE-2000-0941 | Kootenay Web KW Whois 1.0 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "whois" parameter. | EXPLOIT ✓HIGH 10.0EPSS 13.5% | 19 December 2000 |
| CVE-2000-0929 | Microsoft Windows Media Player 7 allows attackers to cause a denial of service in RTF-enabled email clients via an embedded OCX control that is not closed properly, aka the "OCX Attachment" vulnerability. | EXPLOIT ✓MEDIUM 5.0EPSS 14.4% | 19 December 2000 |
| CVE-2000-0917 | Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands. | EXPLOIT ×4 ✓HIGH 10.0EPSS 78.7% | 19 December 2000 |
| CVE-2000-0913 | mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression. | MEDIUM 5.0EPSS 35.6% | 19 December 2000 |
| CVE-2000-0909 | Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arbitrary commands via a long From: header. | EXPLOIT ✓HIGH 7.5EPSS 11.5% | 19 December 2000 |
| CVE-2000-0887 | named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by making a compressed zone transfer (ZXFR) request and performing a name service query on an authoritative record that is not cached, aka the "zxfr bug." | EXPLOIT ✓MEDIUM 5.0EPSS 22.9% | 19 December 2000 |
| CVE-2000-0886 | IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability. | EXPLOIT ✓HIGH 7.5EPSS 68.7% | 19 December 2000 |
| CVE-2000-0885 | Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse Frame, a long SNMP community name, or a long username or filename in an SMB session, aka the "Netmon… | HIGH 7.5EPSS 12.8% | 19 December 2000 |
| CVE-2000-0884 | IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability. | EXPLOIT ×9 ✓HIGH 7.5EPSS 72.1% | 19 December 2000 |
| CVE-2000-0817 | Buffer overflow in the HTTP protocol parser for Microsoft Network Monitor (Netmon) allows remote attackers to execute arbitrary commands via malformed data, aka the "Netmon Protocol Parsing" vulnerability. | HIGH 7.5EPSS 15.1% | 19 December 2000 |
| CVE-1999-1579 | The Cenroll ActiveX control (xenroll.dll) for Terminal Server Editions of Windows NT 4.0 and Windows NT Server 4.0 before SP6 allows remote attackers to cause a denial of service (resource consumption) by creating a large number of arbitrary files on… | MEDIUM 5.0EPSS 21.8% | 14 December 2000 |
| CVE-2000-1061 | Microsoft Virtual Machine (VM) in Internet Explorer 4.x and 5.x allows an unsigned applet to create and use ActiveX controls, which allows a remote attacker to bypass Internet Explorer's security settings and execute arbitrary commands via a malicious… | EXPLOIT ✓MEDIUM 5.1EPSS 10.5% | 11 December 2000 |
| CVE-2000-1058 | Buffer overflow in OverView5 CGI program in HP OpenView Network Node Manager (NNM) 6.1 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, in the SNMP service (snmp.exe), aka the "Java SNMP MIB… | EXPLOIT ✓MEDIUM 5.0EPSS 16.2% | 11 December 2000 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.