Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,329 CVEs1,721 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
17,157 results · page 340 of 344
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2000-0161 | Sample web sites on Microsoft Site Server 3.0 Commerce Edition do not validate an identification number, which allows remote attackers to execute SQL commands. | HIGH 7.5EPSS 10.1% | 18 February 2000 |
| CVE-2000-0156 | Internet Explorer 4.x and 5.x allows remote web servers to access files on the client that are outside of its security domain, aka the "Image Source Redirect" vulnerability. | EXPLOIT ✓MEDIUM 5.1EPSS 12.8% | 16 February 2000 |
| CVE-2000-0222 | The installation for Windows 2000 does not activate the Administrator password until the system has rebooted, which allows remote attackers to connect to the ADMIN$ share without a password until the reboot occurs. | HIGH 10.0EPSS 15.0% | 15 February 2000 |
| CVE-2000-0122 | Frontpage Server Extensions allows remote attackers to determine the physical path of a virtual directory via a GET request to the htimage.exe CGI program. | MEDIUM 5.0EPSS 21.5% | 3 February 2000 |
| CVE-2000-0114 | Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory. | MEDIUM 5.0EPSS 47.6% | 2 February 2000 |
| CVE-2000-1205 | Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the… | MEDIUM 4.3EPSS 23.6% | 1 February 2000 |
| CVE-2000-0105 | Outlook Express 5.01 and Internet Explorer 5.01 allow remote attackers to view a user's email messages via a script that accesses a variable that references subsequent email messages that are read by the client. | EXPLOIT ✓MEDIUM 5.0EPSS 20.7% | 1 February 2000 |
| CVE-2000-0132 | Microsoft Java Virtual Machine allows remote attackers to read files via the getSystemResourceAsStream function. | EXPLOIT ✓LOW 2.6EPSS 19.0% | 31 January 2000 |
| CVE-2000-0126 | Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 45.7% | 26 January 2000 |
| CVE-2000-0098 | Microsoft Index Server allows remote attackers to determine the real path for a web directory via a request to an Internet Data Query file that does not exist. | MEDIUM 5.0EPSS 48.5% | 26 January 2000 |
| CVE-2000-0097 | The WebHits ISAPI filter in Microsoft Index Server allows remote attackers to read arbitrary files, aka the "Malformed Hit-Highlighting Argument" vulnerability. | EXPLOIT ✓MEDIUM 5.0EPSS 35.9% | 26 January 2000 |
| CVE-2000-0115 | IIS allows local users to cause a denial of service via invalid regular expressions in a Visual Basic script in an ASP page. | MEDIUM 5.0EPSS 10.0% | 21 January 2000 |
| CVE-2000-0091 | Buffer overflow in vchkpw/vpopmail POP authentication package allows remote attackers to gain root privileges via a long username or password. | EXPLOIT ✓HIGH 10.0EPSS 12.9% | 21 January 2000 |
| CVE-2000-0065 | Buffer overflow in InetServ 3.0 allows remote attackers to execute commands via a long GET request. | EXPLOIT ✓HIGH 10.0EPSS 12.9% | 17 January 2000 |
| CVE-2000-0071 | IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions. | MEDIUM 5.0EPSS 28.1% | 11 January 2000 |
| CVE-2000-0081 | Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute the code by using hexadecimal codes to specify the javascript: protocol, e.g. jAvascript. | HIGH 10.0EPSS 18.8% | 10 January 2000 |
| CVE-2000-1221 | The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the local machine to the hostname of the print server as returned by gethostname, which allows remote… | EXPLOIT ✓HIGH 10.0EPSS 16.7% | 8 January 2000 |
| CVE-2000-1220 | The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to execute with arbitrary command line arguments, as demonstrated using the -C option to specify a… | EXPLOIT ✓HIGH 10.0EPSS 14.2% | 8 January 2000 |
| CVE-2000-0061 | Internet Explorer 5 does not modify the security zone for a document that is being loaded into a window until after the document has been loaded, which could allow remote attackers to execute Javascript in a different security context while the document… | EXPLOIT ✓HIGH 10.0EPSS 19.8% | 7 January 2000 |
| CVE-2000-0085 | Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute code via the LOWSRC or DYNRC parameters in the IMG tag. | HIGH 7.5EPSS 14.9% | 4 January 2000 |
| CVE-2000-0059 | PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execute commands. | EXPLOIT ✓HIGH 10.0EPSS 10.9% | 4 January 2000 |
| CVE-2000-0053 | Microsoft Commercial Internet System (MCIS) IMAP server allows remote attackers to cause a denial of service via a malformed IMAP request. | HIGH 7.5EPSS 14.7% | 4 January 2000 |
| CVE-2000-0082 | WebTV email client allows remote attackers to force the client to send email without the user's knowledge via HTML. | MEDIUM 5.0EPSS 14.5% | 2 January 2000 |
| CVE-1999-1591 | Microsoft Internet Information Services (IIS) server 4.0 SP4, without certain hotfixes released for SP4, does not require authentication credentials under certain conditions, which allows remote attackers to bypass authentication requirements, as… | HIGH 7.5EPSS 11.3% | 31 December 1999 |
| CVE-1999-1472 | Internet Explorer 4.0 allows remote attackers to read arbitrary text and HTML files on the user's machine via a small IFRAME that uses Dynamic HTML (DHTML) to send the data to the attacker, aka the Freiburg text-viewing issue. | MEDIUM 5.0EPSS 17.1% | 31 December 1999 |
| CVE-1999-1451 | The Winmsdp.exe sample file in IIS 4.0 and Site Server 3.0 allows remote attackers to read arbitrary files. | MEDIUM 5.0EPSS 17.6% | 31 December 1999 |
| CVE-1999-1223 | IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters. | MEDIUM 5.0EPSS 23.1% | 31 December 1999 |
| CVE-1999-1157 | Tcpip.sys in Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service via an ICMP Subnet Mask Address Request packet, when certain multiple IP addresses are bound to the same network interface. | MEDIUM 5.0EPSS 13.3% | 31 December 1999 |
| CVE-1999-1148 | FTP service in IIS 4.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via many passive (PASV) connections at the same time. | MEDIUM 5.0EPSS 17.3% | 31 December 1999 |
| CVE-1999-1132 | Windows NT 4.0 allows remote attackers to cause a denial of service (crash) via extra source routing data such as (1) a Routing Information Field (RIF) field with a hop count greater than 7, or (2) a list containing duplicate Token Ring IDs. | MEDIUM 5.0EPSS 18.3% | 31 December 1999 |
| CVE-1999-1127 | Windows NT 4.0 does not properly shut down invalid named pipe RPC connections, which allows remote attackers to cause a denial of service (resource exhaustion) via a series of connections containing malformed data, aka the "Named Pipes Over RPC"… | HIGH 7.5EPSS 17.7% | 31 December 1999 |
| CVE-1999-1105 | Windows 95, when Remote Administration and File Sharing for NetWare Networks is enabled, creates a share (C$) when an administrator logs in remotely, which allows remote attackers to read arbitrary files by mapping the network drive. | MEDIUM 5.0EPSS 21.6% | 31 December 1999 |
| CVE-1999-1094 | Buffer overflow in Internet Explorer 4.01 and earlier allows remote attackers to execute arbitrary commands via a long URL with the "mk:" protocol, aka the "MK Overrun security issue." | HIGH 7.5EPSS 18.4% | 31 December 1999 |
| CVE-1999-1093 | Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer 4.01 SP1 and earlier allows remote attackers to execute arbitrary commands via a malicious web page. | MEDIUM 5.1EPSS 12.8% | 31 December 1999 |
| CVE-1999-1043 | Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows remote attackers to cause a denial of service (application error). | MEDIUM 5.0EPSS 13.2% | 31 December 1999 |
| CVE-1999-1035 | IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS "GET" vulnerability. | MEDIUM 5.0EPSS 17.3% | 31 December 1999 |
| CVE-1999-0815 | Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries. | MEDIUM 5.0EPSS 17.8% | 31 December 1999 |
| CVE-1999-0154 | IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . | EXPLOIT ✓MEDIUM 5.0EPSS 40.0% | 31 December 1999 |
| CVE-2000-0010 | WebWho+ whois.cgi program allows remote attackers to execute commands via shell metacharacters in the TLD parameter. | EXPLOIT ✓HIGH 10.0EPSS 11.1% | 26 December 1999 |
| CVE-2000-0028 | Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function. | EXPLOIT ✓LOW 2.6EPSS 23.1% | 23 December 1999 |
| CVE-2000-0002 | Buffer overflow in ZBServer Pro 1.50 allows remote attackers to execute commands via a long GET request. | EXPLOIT ×2 ✓HIGH 10.0EPSS 13.9% | 22 December 1999 |
| CVE-2000-0025 | IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the "Virtual Directory Naming" vulnerability. | MEDIUM 5.0EPSS 34.9% | 21 December 1999 |
| CVE-2000-0024 | IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability. | MEDIUM 6.4EPSS 12.2% | 21 December 1999 |
| CVE-1999-0995 | Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaLookupSids function which looks up the SID, aka "Malformed Security Identifier Request." | HIGH 7.8EPSS 21.8% | 16 December 1999 |
| CVE-1999-0977 | Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request. | EXPLOIT ×5 ✓HIGH 10.0EPSS 12.6% | 10 December 1999 |
| CVE-1999-0981 | Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local files via that window, aka "Server-side Page Reference Redirect." | EXPLOIT ✓MEDIUM 5.1EPSS 13.1% | 8 December 1999 |
| CVE-1999-0989 | Buffer overflow in Internet Explorer 5 directshow filter (MSDXM.OCX) allows remote attackers to execute commands via the vnd.ms.radio protocol. | EXPLOIT ✓HIGH 7.5EPSS 11.9% | 6 December 1999 |
| CVE-1999-0858 | Internet Explorer 5 allows a remote attacker to modify the IE client's proxy configuration via a malicious Web Proxy Auto-Discovery (WPAD) server. | MEDIUM 5.0EPSS 13.6% | 2 December 1999 |
| CVE-1999-0819 | NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it. | EXPLOIT ✓MEDIUM 5.0EPSS 14.8% | 1 December 1999 |
| CVE-1999-0999 | Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet. | EXPLOIT ✓MEDIUM 4.3EPSS 21.7% | 19 November 1999 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.