SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,163 CVEs1,721 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

17,157 results · page 338 of 344

CVESummaryPriorityPublished
CVE-2000-1053Allaire JRun 2.3.3 server allows remote attackers to compile and execute JSP code by inserting it via a cross-site scripting (CSS) attack and directly calling the com.livesoftware.jrun.plugins.JSP JSP servlet.EXPLOITHIGH 10.0EPSS 10.6%11 December 2000
CVE-2000-1035Buffer overflows in TYPSoft FTP Server 0.78 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long USER, PASS, or CWD command.EXPLOITHIGH 10.0EPSS 13.0%11 December 2000
CVE-2000-1034Buffer overflow in the System Monitor ActiveX control in Windows 2000 allows remote attackers to execute arbitrary commands via a long LogFileName parameter in HTML source code, aka the "ActiveX Parameter Validation" vulnerability.HIGH 10.0EPSS 27.2%11 December 2000
CVE-2000-1029Buffer overflow in host command allows a remote attacker to execute arbitrary commands via a long response to an AXFR query.EXPLOITHIGH 10.0EPSS 14.3%11 December 2000
CVE-2000-1014Format string vulnerability in the search97.cgi CGI script in SCO help http server for Unixware 7 allows remote attackers to execute arbitrary commands via format characters in the queryText parameter.EXPLOITHIGH 7.5EPSS 11.5%11 December 2000
CVE-2000-1006Microsoft Exchange Server 5.5 does not properly handle a MIME header with a blank charset specified, which allows remote attackers to cause a denial of service via a charset="" command, aka the "Malformed MIME Header" vulnerability.MEDIUM 5.0EPSS 14.8%11 December 2000
CVE-2000-1003NETBIOS client in Windows 95 and Windows 98 allows a remote attacker to cause a denial of service by changing a file sharing service to return an unknown driver type, which causes the client to crash.LOW 2.6EPSS 12.5%11 December 2000
CVE-2000-0999Format string vulnerabilities in OpenBSD ssh program (and possibly other BSD-based operating systems) allow attackers to gain root privileges.HIGH 10.0EPSS 11.9%11 December 2000
CVE-2000-0869The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method.EXPLOITMEDIUM 5.0EPSS 50.9%14 November 2000
CVE-2000-0868The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.MEDIUM 5.0EPSS 44.7%14 November 2000
CVE-2000-0858Vulnerability in Microsoft Windows NT 4.0 allows remote attackers to cause a denial of service in IIS by sending it a series of malformed requests which cause INETINFO.EXE to fail, aka the "Invalid URL" vulnerability.MEDIUM 5.0EPSS 18.8%14 November 2000
CVE-2000-0854When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same…EXPLOITHIGH 10.0EPSS 37.2%14 November 2000
CVE-2000-0849Race condition in Microsoft Windows Media server allows remote attackers to cause a denial of service in the Windows Media Unicast Service via a malformed request, aka the "Unicast Service Race Condition" vulnerability.LOW 2.6EPSS 15.0%14 November 2000
CVE-2000-0844Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.EXPLOIT ×11HIGH 10.0EPSS 15.6%14 November 2000
CVE-2000-0834The Windows 2000 telnet client attempts to perform NTLM authentication by default, which allows remote attackers to capture and replay the NTLM challenge/response via a telnet:// URL that points to the malicious server, aka the "Windows 2000 Telnet…EXPLOITHIGH 7.5EPSS 39.6%14 November 2000
CVE-2000-0833Buffer overflow in WinSMTP 1.06f and 2.X allows remote attackers to cause a denial of service via a long (1) USER or (2) HELO command.EXPLOITHIGH 10.0EPSS 10.4%14 November 2000
CVE-2000-0830annclist.exe in webTV for Windows allows remote attackers to cause a denial of service by via a large, malformed UDP packet to ports 22701 through 22705.EXPLOITMEDIUM 5.0EPSS 25.9%14 November 2000
CVE-2000-0778IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a "Translate: f" header, aka the "Specialized Header" vulnerability.EXPLOIT ×2MEDIUM 5.0EPSS 87.3%20 October 2000
CVE-2000-0770IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrictive permissions, which could allow remote attackers to bypass access restrictions to some files, aka the "File Permission…MEDIUM 6.4EPSS 15.1%20 October 2000
CVE-2000-0760The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.EXPLOITMEDIUM 6.4EPSS 62.5%20 October 2000
CVE-2000-0759Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path.EXPLOITMEDIUM 6.4EPSS 25.7%20 October 2000
CVE-2000-0746Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks.HIGH 7.5EPSS 10.1%20 October 2000
CVE-2000-0745admin.php3 in PHP-Nuke does not properly verify the PHP-Nuke administrator password, which allows remote attackers to gain privileges by requesting a URL that does not specify the aid or pwd parameter.EXPLOITHIGH 7.5EPSS 12.1%20 October 2000
CVE-2000-0743Buffer overflow in University of Minnesota (UMN) gopherd 2.x allows remote attackers to execute arbitrary commands via a DES key generation request (GDESkey) that contains a long ticket value.EXPLOITHIGH 10.0EPSS 12.6%20 October 2000
CVE-2000-0742The IPX protocol implementation in Microsoft Windows 95 and 98 allows remote attackers to cause a denial of service by sending a ping packet with a source IP address that is a broadcast address, aka the "Malformed IPX Ping Packet" vulnerability.MEDIUM 5.0EPSS 18.8%20 October 2000
CVE-2000-0733Telnetd telnet server in IRIX 5.2 through 6.1 does not properly cleans user-injected format strings, which allows remote attackers to execute arbitrary commands via a long RLD variable in the IAC-SB-TELOPT_ENVIRON request.EXPLOITHIGH 10.0EPSS 12.4%20 October 2000
CVE-2000-0711Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to create a server on the victim's system via a malicious applet, as demonstrated by Brown Orifice.EXPLOITHIGH 7.5EPSS 33.5%20 October 2000
CVE-2000-0710The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS device name.MEDIUM 5.0EPSS 26.4%20 October 2000
CVE-2000-0709The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to cause a denial of service in some components by requesting a URL whose name includes a standard DOS device name.MEDIUM 5.0EPSS 25.4%20 October 2000
CVE-2000-0704Buffer overflow in SGI Omron WorldView Wnn allows remote attackers to execute arbitrary commands via long JS_OPEN, JS_MKDIR, or JS_FILE_INFO commands.EXPLOITHIGH 10.0EPSS 13.1%20 October 2000
CVE-2000-0699Format string vulnerability in ftpd in HP-UX 10.20 allows remote attackers to cause a denial of service or execute arbitrary commands via format strings in the PASS command.EXPLOITHIGH 10.0EPSS 14.3%20 October 2000
CVE-2000-0697The administration interface for the dwhttpd web server in Solaris AnswerBook2 allows interface users to remotely execute commands via shell metacharacters.EXPLOITHIGH 10.0EPSS 11.2%20 October 2000
CVE-2000-0690Auction Weaver CGI script 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the fromfile parameter.EXPLOITHIGH 10.0EPSS 10.5%20 October 2000
CVE-2000-0685BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML code by directly invoking the servlet on any source file.EXPLOITHIGH 10.0EPSS 12.3%20 October 2000
CVE-2000-0684BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on any source file.EXPLOITHIGH 10.0EPSS 12.3%20 October 2000
CVE-2000-0681Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extension.HIGH 10.0EPSS 50.9%20 October 2000
CVE-2000-0676Netscape Communicator and Navigator 4.04 through 4.74 allows remote attackers to read arbitrary files by using a Java applet to open a connection to a URL using the "file", "http", "https", and "ftp" protocols, as demonstrated by Brown Orifice.EXPLOITMEDIUM 5.0EPSS 20.5%20 October 2000
CVE-2000-1204Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root.MEDIUM 5.0EPSS 10.4%13 October 2000
CVE-2000-1079Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast…HIGH 7.5EPSS 15.9%29 August 2000
CVE-2000-0673The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attackers to cause a denial of service by sending a spoofed Name Conflict or Name Release datagram, aka the "NetBIOS Name Server Protocol Spoofing" vulnerability.EXPLOITMEDIUM 5.0EPSS 33.4%27 July 2000
CVE-2000-0655Netscape Communicator 4.73 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a JPEG image containing a comment with an illegal field length of 1.EXPLOITMEDIUM 5.0EPSS 12.7%25 July 2000
CVE-2000-0672The default configuration of Jakarta Tomcat does not restrict access to the /admin context, which allows remote attackers to read arbitrary files by directly calling the administrative servlets to add a context for the root directory.MEDIUM 5.0EPSS 10.0%20 July 2000
CVE-2000-0653Microsoft Outlook Express allows remote attackers to monitor a user's email by creating a persistent browser link to the Outlook Express windows, aka the "Persistent Mail-Browser Link" vulnerability.EXPLOITMEDIUM 5.0EPSS 26.9%20 July 2000
CVE-2000-0621Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache, aka the "Cache Bypass" vulnerability.HIGH 7.5EPSS 22.1%20 July 2000
CVE-2000-0622Buffer overflow in Webfind CGI program in O'Reilly WebSite Professional web server 2.x allows remote attackers to execute arbitrary commands via a URL containing a long "keywords" parameter.EXPLOITHIGH 10.0EPSS 13.0%19 July 2000
CVE-2000-0567Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrary commands via a long Date field in an email header, aka the "Malformed E-mail Header" vulnerability.EXPLOIT ×2MEDIUM 5.0EPSS 32.3%18 July 2000
CVE-2000-0665GAMSoft TelSrv telnet server 1.5 and earlier allows remote attackers to cause a denial of service via a long username.EXPLOITMEDIUM 5.0EPSS 51.0%17 July 2000
CVE-2000-0630IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of the "File Fragment Reading via .HTR" vulnerability.EXPLOITMEDIUM 5.0EPSS 68.2%17 July 2000
CVE-2000-0666rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote attackers to gain root privileges.EXPLOIT ×3HIGH 10.0EPSS 26.3%16 July 2000
CVE-2000-0662Internet Explorer 5.x and Microsoft Outlook allows remote attackers to read arbitrary files by redirecting the contents of an IFRAME using the DHTML Edit Control (DHTMLED).MEDIUM 5.0EPSS 21.3%14 July 2000

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.