Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,329 CVEs1,721 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
17,157 results · page 339 of 344
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2000-0631 | An administrative script from IIS 3.0, later included in IIS 4.0 and 5.0, allows remote attackers to cause a denial of service by accessing the script without a particular argument, aka the "Absent Directory Browser Argument" vulnerability. | MEDIUM 5.0EPSS 24.7% | 14 July 2000 |
| CVE-2000-0649 | IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined. | EXPLOIT ✓LOW 2.6EPSS 76.6% | 13 July 2000 |
| CVE-2000-0574 | FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitle function (sometimes called by set_proc_title), which allows remote attackers to cause a denial of… | EXPLOIT ✓MEDIUM 5.0EPSS 58.9% | 7 July 2000 |
| CVE-2000-0573 | The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to execute arbitrary commands via the SITE EXEC command. | EXPLOIT ×7 ✓HIGH 10.0EPSS 96.2% | 7 July 2000 |
| CVE-2000-0581 | Windows 2000 Telnet Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros, which causes the server to crash. | EXPLOIT ✓MEDIUM 5.0EPSS 22.4% | 30 June 2000 |
| CVE-2000-0580 | Windows 2000 Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros to various TCP and UDP ports, which significantly increases the CPU utilization. | EXPLOIT ✓MEDIUM 5.0EPSS 16.3% | 30 June 2000 |
| CVE-2000-0597 | Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, which allows remote attackers to force Internet Explorer or some email clients to save files to arbitrary locations via the Visual Basic for Applications… | HIGH 7.5EPSS 12.1% | 27 June 2000 |
| CVE-2000-0596 | Internet Explorer 5.x does not warn a user before opening a Microsoft Access database file that is referenced within ActiveX OBJECT tags in an HTML document, which could allow remote attackers to execute arbitrary commands, aka the "IE Script"… | HIGH 7.5EPSS 24.8% | 27 June 2000 |
| CVE-2000-0506 | The "capabilities" feature in Linux before 2.2.16 allows local users to cause a denial of service or gain privileges by setting the capabilities to prevent a setuid program from dropping privileges, aka the "Linux kernel setuid/setcap vulnerability." | EXPLOIT ×2 ✓HIGH 10.0EPSS 11.4% | 9 June 2000 |
| CVE-2000-0377 | The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malformed request, which causes the winlogon process to fail, aka the "Remote Registry Access Authentication" vulnerability. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 19.2% | 8 June 2000 |
| CVE-2000-0544 | Windows NT and Windows 2000 hosts allow a remote attacker to cause a denial of service via malformed DCE/RPC SMBwriteX requests that contain an invalid data length. | MEDIUM 5.0EPSS 17.8% | 5 June 2000 |
| CVE-2000-0524 | Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending email messages with blank fields such as BCC, Reply-To, Return-Path, or From. | MEDIUM 5.0EPSS 14.6% | 5 June 2000 |
| CVE-2000-0474 | Real Networks RealServer 7.x allows remote attackers to cause a denial of service via a malformed request for a page in the viewsource directory. | EXPLOIT ✓HIGH 7.8EPSS 10.2% | 1 June 2000 |
| CVE-2000-0505 | The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters. | EXPLOIT ✓MEDIUM 5.0EPSS 46.7% | 31 May 2000 |
| CVE-2000-0495 | Microsoft Windows Media Encoder allows remote attackers to cause a denial of service via a malformed request, aka the "Malformed Windows Media Encoder Request" vulnerability. | EXPLOIT ✓MEDIUM 5.0EPSS 32.3% | 30 May 2000 |
| CVE-2000-0402 | The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the "SQL Server 7.0 Service Pack Password" vulnerability. | EXPLOIT ×2 ✓LOW 2.1EPSS 90.6% | 30 May 2000 |
| CVE-2000-0404 | The CIFS Computer Browser service allows remote attackers to cause a denial of service by sending a ResetBrowser frame to the Master Browser, aka the "ResetBrowser Frame" vulnerability. | MEDIUM 5.0EPSS 17.9% | 25 May 2000 |
| CVE-2000-0403 | The CIFS Computer Browser service on Windows NT 4.0 allows a remote attacker to cause a denial of service by sending a large number of host announcement requests to the master browse tables, aka the "HostAnnouncement Flooding" or "HostAnnouncement… | MEDIUM 5.0EPSS 17.9% | 25 May 2000 |
| CVE-2000-0491 | Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of service via a long FORWARD_QUERY request. | EXPLOIT ×2 ✓HIGH 10.0EPSS 17.8% | 24 May 2000 |
| CVE-2000-0443 | The web interface server in HP Web JetAdmin 5.6 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 10.0% | 24 May 2000 |
| CVE-2000-0305 | Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a large number of identical fragmented IP packets, aka jolt2 or the "IP Fragment Reassembly" vulnerability. | EXPLOIT ✓HIGH 7.8EPSS 38.4% | 19 May 2000 |
| CVE-2000-0465 | Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files via the frame, aka the "Frame Domain Verification" vulnerability. | EXPLOIT ✓MEDIUM 5.1EPSS 20.8% | 17 May 2000 |
| CVE-2000-0464 | Internet Explorer 4.x and 5.x allows remote attackers to execute arbitrary commands via a buffer overflow in the ActiveX parameter parsing capability, aka the "Malformed Component Attribute" vulnerability. | HIGH 7.6EPSS 13.3% | 17 May 2000 |
| CVE-2000-0389 | Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges. | EXPLOIT ×3 ✓HIGH 10.0EPSS 16.5% | 16 May 2000 |
| CVE-1999-0980 | Windows NT Service Control Manager (SCM) allows remote attackers to cause a denial of service via a malformed argument in a resource enumeration request. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 23.2% | 16 May 2000 |
| CVE-2000-0457 | ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) and terminated with a .htr extension, aka the ".HTR File Fragment Reading" or "File Fragment Reading via… | EXPLOIT ✓HIGH 7.5EPSS 52.8% | 11 May 2000 |
| CVE-2000-0419 | The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers to conduct unauthorized activities via the "Show Me" function in Office Help, aka the "Office 2000 UA Control" vulnerability. | HIGH 7.5EPSS 21.4% | 11 May 2000 |
| CVE-2000-0408 | IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the "Malformed Extension Data in URL" vulnerability. | EXPLOIT ✓MEDIUM 5.0EPSS 58.0% | 11 May 2000 |
| CVE-2000-0304 | Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the "Undelimited .HTR Request" vulnerability. | MEDIUM 5.0EPSS 29.1% | 10 May 2000 |
| CVE-2000-0413 | The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that… | EXPLOIT ✓MEDIUM 5.0EPSS 43.9% | 6 May 2000 |
| CVE-2000-0347 | Windows 95 and Windows 98 allow a remote attacker to cause a denial of service via a NetBIOS session request packet with a NULL source name. | EXPLOIT ✓MEDIUM 5.0EPSS 17.6% | 2 May 2000 |
| CVE-2000-0380 | The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a denial of service by requesting a URL that contains a %% string. | EXPLOIT ✓HIGH 7.1EPSS 35.0% | 26 April 2000 |
| CVE-2000-0322 | The passwd.php3 CGI script in the Red Hat Piranha Virtual Server Package allows local users to execute arbitrary commands via shell metacharacters. | EXPLOIT ✓HIGH 10.0EPSS 41.6% | 24 April 2000 |
| CVE-2000-0248 | The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor password that allows remote attackers to execute arbitrary commands. | EXPLOIT ×2 ✓HIGH 10.0EPSS 73.7% | 24 April 2000 |
| CVE-2000-0272 | RealNetworks RealServer allows remote attackers to cause a denial of service by sending malformed input to the server at port 7070. | EXPLOIT ✓HIGH 7.8EPSS 10.1% | 20 April 2000 |
| CVE-2000-0256 | Buffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a user to conduct activities that are not otherwise available through the web site, aka the "Server-Side Image Map Components" vulnerability. | EXPLOIT ✓HIGH 7.5EPSS 11.7% | 19 April 2000 |
| CVE-2000-0266 | Internet Explorer 5.01 allows remote attackers to bypass the cross frame security policy via a malicious applet that interacts with the Java JSObject to modify the DOM properties to set the IFRAME to an arbitrary Javascript URL. | LOW 2.6EPSS 16.2% | 18 April 2000 |
| CVE-2000-0284 | Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via LIST or other commands. | EXPLOIT ×8 ✓HIGH 7.5EPSS 68.3% | 16 April 2000 |
| CVE-2000-0260 | Buffer overflow in the dvwssr.dll DLL in Microsoft Visual Interdev 1.0 allows users to cause a denial of service or execute commands, aka the "Link View Server-Side Component" vulnerability. | EXPLOIT ×2 ✓HIGH 7.5EPSS 13.9% | 14 April 2000 |
| CVE-2000-0287 | The BizDB CGI script bizdb-search.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the dbname parameter. | EXPLOIT ✓HIGH 10.0EPSS 10.6% | 12 April 2000 |
| CVE-2000-0258 | IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the "Myriad Escaped Characters" Vulnerability. | HIGH 7.5EPSS 17.8% | 12 April 2000 |
| CVE-2000-0302 | Microsoft Index Server allows remote attackers to view the source code of ASP files by appending a %20 to the filename in the CiWebHitsFile argument to the null.htw URL. | EXPLOIT ✓MEDIUM 5.0EPSS 78.6% | 31 March 2000 |
| CVE-2000-0246 | IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability. | EXPLOIT ✓MEDIUM 5.0EPSS 80.0% | 30 March 2000 |
| CVE-2000-0245 | Vulnerability in SGI IRIX objectserver daemon allows remote attackers to create user accounts. | EXPLOIT ✓HIGH 10.0EPSS 11.7% | 27 March 2000 |
| CVE-2000-0228 | Microsoft Windows Media License Manager allows remote attackers to cause a denial of service by sending a malformed request that causes the manager to halt, aka the "Malformed Media License Request" Vulnerability. | MEDIUM 5.0EPSS 13.7% | 17 March 2000 |
| CVE-2000-0169 | Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes '?&'. | EXPLOIT ✓HIGH 7.5EPSS 27.4% | 15 March 2000 |
| CVE-2000-0200 | Buffer overflow in Microsoft Clip Art Gallery allows remote attackers to cause a denial of service or execute commands via a malformed CIL (clip art library) file, aka the "Clip Art Buffer Overrun" vulnerability. | EXPLOIT ✓MEDIUM 5.1EPSS 15.7% | 6 March 2000 |
| CVE-2000-0168 | Microsoft Windows 9x operating systems allow an attacker to cause a denial of service via a pathname that includes file device names, aka the "DOS Device in Path Name" vulnerability. | EXPLOIT ✓MEDIUM 5.0EPSS 19.6% | 4 March 2000 |
| CVE-2000-0191 | Axis StorPoint CD allows remote attackers to access administrator URLs without authentication via a .. | EXPLOIT ✓HIGH 10.0EPSS 10.9% | 29 February 2000 |
| CVE-2000-0211 | The Windows Media server allows remote attackers to cause a denial of service via a series of client handshake packets that are sent in an improper sequence, aka the "Misordered Windows Media Services Handshake" vulnerability. | EXPLOIT ✓MEDIUM 5.0EPSS 21.3% | 23 February 2000 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.