SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,329 CVEs1,721 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

17,157 results · page 341 of 344

CVESummaryPriorityPublished
CVE-2000-0073Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word.EXPLOITMEDIUM 5.0EPSS 20.7%17 November 1999
CVE-1999-0793Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet.EXPLOITLOW 2.6EPSS 13.3%17 November 1999
CVE-2000-0165The Delegate application proxy has several buffer overflows which allow a remote attacker to execute commands.EXPLOITHIGH 7.5EPSS 11.5%13 November 1999
CVE-2000-0330The networking software in Windows 95 and Windows 98 allows remote attackers to execute commands via a long file name string, aka the "File Access URL" vulnerability.EXPLOIT ×2HIGH 7.6EPSS 15.0%12 November 1999
CVE-1999-1539Buffer overflow in FTP server in QPC Software's QVT/Term Plus versions 4.2d and 4.3 and QVT/Net 4.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long (1) user name or (2) password.EXPLOITHIGH 7.5EPSS 12.1%10 November 1999
CVE-2001-0679A buffer overflow in InterScan VirusWall 3.23 and 3.3 allows a remote attacker to execute arbitrary code by sending a long HELO command to the server.EXPLOIT ×2HIGH 10.0EPSS 16.0%8 November 1999
CVE-1999-1529A buffer overflow exists in the HELO command in Trend Micro Interscan VirusWall SMTP gateway 3.23/3.3 for NT, which may allow an attacker to execute arbitrary code.EXPLOIT ×2HIGH 7.5EPSS 12.1%7 November 1999
CVE-1999-0896Buffer overflow in RealNetworks RealServer administration utility allows remote attackers to execute arbitrary commands via a long username and password.EXPLOIT ×2HIGH 10.0EPSS 12.8%4 November 1999
CVE-1999-1577Buffer overflow in HHOpen ActiveX control (hhopen.ocx) 1.0.0.1 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands via long arguments to the OpenHelp method.EXPLOITMEDIUM 5.1EPSS 19.5%31 October 1999
CVE-1999-1234LSA (LSASS.EXE) in Windows NT 4.0 allows remote attackers to cause a denial of service via a NULL policy handle in a call to (1) SamrOpenDomain, (2) SamrEnumDomainUsers, and (3) SamrQueryDomainInfo.MEDIUM 5.0EPSS 13.5%26 October 1999
CVE-2000-0327Microsoft Virtual Machine (VM) allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, aka the "Virtual Machine Verifier" vulnerability.HIGH 7.6EPSS 11.8%21 October 1999
CVE-1999-0877Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME.EXPLOITMEDIUM 4.3EPSS 17.7%1 October 1999
CVE-1999-1576Buffer overflow in Adobe Acrobat ActiveX control (pdf.ocx, PDF.PdfCtrl.1) 1.3.188 for Acrobat Reader 4.0 allows remote attackers to execute arbitrary code via the pdf.setview method.EXPLOITHIGH 7.5EPSS 12.9%27 September 1999
CVE-1999-1578Buffer overflow in Registration Wizard ActiveX control (regwizc.dll, InvokeRegWizard) 3.0.0.0 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands.EXPLOITMEDIUM 5.1EPSS 19.4%24 September 1999
CVE-1999-1484Buffer overflow in MSN Setup BBS 4.71.0.10 ActiveX control (setupbbs.ocx) allows a remote attacker to execute arbitrary commands via the methods (1) vAddNewsServer or (2) bIsNewsServerConfigured.EXPLOITHIGH 7.5EPSS 27.0%24 September 1999
CVE-1999-0777IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions.HIGH 7.5EPSS 12.0%23 September 1999
CVE-1999-0909Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability.HIGH 7.5EPSS 12.0%20 September 1999
CVE-1999-0886The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.EXPLOITHIGH 9.0EPSS 21.6%17 September 1999
CVE-1999-1053guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows…EXPLOIT ×2HIGH 7.5EPSS 85.2%13 September 1999
CVE-1999-1575The Kodak/Wang (1) Image Edit (imgedit.ocx), (2) Image Annotation (imgedit.ocx), (3) Image Scan (imgscan.ocx), (4) Thumbnail Image (imgthumb.ocx), (5) Image Admin (imgadmin.ocx), (6) HHOpen (hhopen.ocx), (7) Registration Wizard (regwizc.dll), and (8) IE…EXPLOIT ×3MEDIUM 5.1EPSS 35.6%10 September 1999
CVE-1999-0702Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the "ImportExportFavorites" vulnerability.EXPLOITHIGH 10.0EPSS 24.4%10 September 1999
CVE-1999-0891The "download behavior" in Internet Explorer 5 allows remote attackers to read arbitrary files via a server-side redirect.EXPLOITMEDIUM 5.0EPSS 42.6%1 September 1999
CVE-1999-0911Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories.EXPLOIT ×2HIGH 10.0EPSS 38.1%27 August 1999
CVE-2000-0328Windows NT 4.0 generates predictable random TCP initial sequence numbers (ISN), which allows remote attackers to perform spoofing and session hijacking.MEDIUM 5.0EPSS 25.1%24 August 1999
CVE-1999-1052Microsoft FrontPage stores form results in a default location in /_private/form_results.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive information submitted by other users.MEDIUM 5.0EPSS 14.2%24 August 1999
CVE-1999-0668The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.EXPLOITMEDIUM 5.1EPSS 22.6%21 August 1999
CVE-1999-0725When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page".EXPLOITHIGH 7.1EPSS 24.9%19 August 1999
CVE-1999-0875DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes.EXPLOITHIGH 7.5EPSS 10.2%11 August 1999
CVE-1999-0867Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.EXPLOITMEDIUM 5.0EPSS 21.5%11 August 1999
CVE-1999-0682Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled.MEDIUM 5.0EPSS 26.1%6 August 1999
CVE-1999-0710The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attackers to use it as an intermediary to connect to other systems.EXPLOITHIGH 7.5EPSS 11.6%25 July 1999
CVE-1999-0224Denial of service in Windows NT messenger service through a long username.EXPLOITMEDIUM 5.0EPSS 16.8%23 July 1999
CVE-1999-1011The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.EXPLOIT ×2HIGH 10.0EPSS 77.1%19 July 1999
CVE-1999-1478The Sun HotSpot Performance Engine VM allows a remote attacker to cause a denial of service on any server running HotSpot via a URL that includes the [ character.MEDIUM 5.0EPSS 18.3%6 July 1999
CVE-1999-0918Denial of service in various Windows systems via malformed, fragmented IGMP packets.EXPLOIT ×3HIGH 7.8EPSS 26.4%3 July 1999
CVE-1999-0696Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd).EXPLOIT ×2HIGH 10.0EPSS 12.2%1 July 1999
CVE-1999-0140Denial of service in RAS/PPTP on NT systems.EXPLOITMEDIUM 5.0EPSS 13.6%30 June 1999
CVE-1999-1164Microsoft Outlook client allows remote attackers to cause a denial of service by sending multiple email messages with the same X-UIDL headers, which causes Outlook to hang.MEDIUM 5.0EPSS 13.2%25 June 1999
CVE-1999-0874Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.EXPLOIT ×5HIGH 10.0EPSS 74.7%16 June 1999
CVE-1999-1412A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.EXPLOITMEDIUM 5.0EPSS 35.9%3 June 1999
CVE-1999-1063CDomain whois_raw.cgi whois CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the fqdn parameter.EXPLOITHIGH 10.0EPSS 12.6%1 June 1999
CVE-1999-0802Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon.HIGH 7.6EPSS 10.2%27 May 1999
CVE-1999-0755Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save password" option.EXPLOITMEDIUM 5.0EPSS 15.0%27 May 1999
CVE-1999-0920Buffer overflow in the pop-2d POP daemon in the IMAP package allows remote attackers to gain privileges via the FOLD command.EXPLOITHIGH 10.0EPSS 32.4%26 May 1999
CVE-1999-1510Buffer overflows in Bisonware FTP server prior to 4.1 allow remote attackers to cause a denial of service, and possibly execute arbitrary commands, via long (1) USER, (2) LIST, or (3) CWD commands.EXPLOIT ×3HIGH 7.5EPSS 67.1%17 May 1999
CVE-1999-0489MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013.HIGH 10.0EPSS 12.4%17 May 1999
CVE-1999-1520A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which exposes sensitive SQL database information.EXPLOITMEDIUM 5.0EPSS 11.7%11 May 1999
CVE-1999-1033Microsoft Outlook Express before 4.72.3612.1700 allows a malicious user to send a message that contains a .., which can inadvertently cause Outlook to re-enter POP3 command mode and cause the POP3 session to hang.EXPLOITMEDIUM 5.0EPSS 17.5%11 May 1999
CVE-1999-0739The codebrws.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.MEDIUM 5.0EPSS 28.7%7 May 1999
CVE-1999-0738The code.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.MEDIUM 5.0EPSS 28.7%7 May 1999

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.