Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,329 CVEs1,721 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
17,157 results · page 342 of 344
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-1999-0737 | The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | MEDIUM 5.0EPSS 28.1% | 7 May 1999 |
| CVE-1999-0736 | The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | EXPLOIT ✓MEDIUM 5.0EPSS 44.8% | 7 May 1999 |
| CVE-1999-1241 | Internet Explorer, with a security setting below Medium, allows remote attackers to execute arbitrary commands via a malicious web page that uses the FileSystemObject ActiveX object. | HIGH 10.0EPSS 14.4% | 6 May 1999 |
| CVE-1999-0487 | The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files. | EXPLOIT ✓LOW 2.6EPSS 13.3% | 1 May 1999 |
| CVE-1999-0488 | Internet Explorer 4.0 and 5.0 allows a remote attacker to execute security scripts in a different security context using malicious URLs, a variant of the "cross frame" vulnerability. | HIGH 7.5EPSS 11.8% | 21 April 1999 |
| CVE-1999-0444 | Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files. | MEDIUM 5.0EPSS 16.5% | 12 April 1999 |
| CVE-1999-0469 | Internet Explorer 5.0 allows window spoofing, allowing a remote attacker to spoof a legitimate web site and capture information from the client. | MEDIUM 5.0EPSS 17.5% | 1 April 1999 |
| CVE-2000-0153 | FrontPage Personal Web Server (PWS) allows remote attackers to read files via a .... | MEDIUM 5.0EPSS 13.7% | 26 March 1999 |
| CVE-1999-1397 | Index Server 2.0 on IIS 4.0 stores physical path information in the ContentIndex\Catalogs subkey of the AllowedPaths registry key, whose permissions allows local and remote users to obtain the physical paths of directories that are being indexed. | HIGH 7.5EPSS 11.7% | 23 March 1999 |
| CVE-1999-1254 | Windows 95, 98, and NT 4.0 allow remote attackers to cause a denial of service by spoofing ICMP redirect messages from a router, which causes Windows to change its routing tables. | MEDIUM 5.0EPSS 13.3% | 8 March 1999 |
| CVE-1999-1551 | Buffer overflow in Ipswitch IMail Service 5.0 allows an attacker to cause a denial of service (crash) and possibly execute arbitrary commands via a long URL. | EXPLOIT ✓MEDIUM 5.0EPSS 71.8% | 2 March 1999 |
| CVE-1999-1046 | Buffer overflow in IMonitor in IMail 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 8181. | EXPLOIT ✓HIGH 10.0EPSS 14.8% | 1 March 1999 |
| CVE-1999-0426 | The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing. | EXPLOIT ✓CRITICAL 9.8EPSS 10.8% | 1 March 1999 |
| CVE-1999-0386 | Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL. | EXPLOIT ✓MEDIUM 5.0EPSS 19.1% | 1 March 1999 |
| CVE-1999-0412 | In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension. | EXPLOIT ✓HIGH 7.5EPSS 10.2% | 19 February 1999 |
| CVE-1999-1375 | FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 30.5% | 11 February 1999 |
| CVE-1999-0368 | Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto. | EXPLOIT ×2 ✓HIGH 10.0EPSS 39.8% | 9 February 1999 |
| CVE-1999-1201 | Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) packet, which causes all stacks to… | MEDIUM 5.0EPSS 13.9% | 6 February 1999 |
| CVE-1999-1453 | Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object. | EXPLOIT ✓LOW 2.6EPSS 11.2% | 2 February 1999 |
| CVE-1999-0349 | A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands. | HIGH 7.5EPSS 17.9% | 27 January 1999 |
| CVE-1999-0348 | IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory. | MEDIUM 5.0EPSS 10.6% | 27 January 1999 |
| CVE-1999-0450 | In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe). | EXPLOIT ✓HIGH 7.5EPSS 19.0% | 26 January 1999 |
| CVE-1999-0449 | The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts. | HIGH 7.8EPSS 49.3% | 26 January 1999 |
| CVE-1999-0357 | Windows 98 and other operating systems allows remote attackers to cause a denial of service via crafted "oshare" packets, possibly involving invalid fragmentation offsets. | MEDIUM 5.0EPSS 16.5% | 25 January 1999 |
| CVE-1999-1544 | Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command. | MEDIUM 5.0EPSS 13.6% | 24 January 1999 |
| CVE-1999-0678 | A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server. | EXPLOIT ✓MEDIUM 5.0EPSS 31.4% | 17 January 1999 |
| CVE-1999-1538 | When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's… | EXPLOIT ✓LOW 2.1EPSS 25.3% | 14 January 1999 |
| CVE-1999-1376 | Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands. | HIGH 10.0EPSS 24.0% | 14 January 1999 |
| CVE-1999-0661 | A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP Wrappers 7.6, (2) util-linux 2.9g, (3) wuarchive ftpd (wuftpd) 2.2 and 2.1f, (4) IRC client (ircII) ircII 2.2.9, (5)… | EXPLOIT ✓HIGH 10.0EPSS 54.2% | 1 January 1999 |
| CVE-1999-0651 | The rsh/rlogin service is running. | HIGH 7.5EPSS 11.9% | 1 January 1999 |
| CVE-1999-0554 | NFS exports system-critical data to the world, e.g. / or a password file. | HIGH 10.0EPSS 11.1% | 1 January 1999 |
| CVE-1999-0512 | A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers. | HIGH 10.0EPSS 12.4% | 1 January 1999 |
| CVE-1999-0448 | IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request. | EXPLOIT ✓MEDIUM 5.0EPSS 24.6% | 1 January 1999 |
| CVE-1999-0869 | Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing. | EXPLOIT ✓LOW 2.6EPSS 17.3% | 1 December 1998 |
| CVE-1999-0385 | The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands. | HIGH 10.0EPSS 18.2% | 1 December 1998 |
| CVE-1999-0332 | Buffer overflow in NetMeeting allows denial of service and remote command execution. | HIGH 7.5EPSS 12.8% | 1 December 1998 |
| CVE-1999-0002 | Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems. | EXPLOIT ✓HIGH 10.0EPSS 27.9% | 12 October 1998 |
| CVE-1999-1291 | TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target's last sequence number from the resulting… | MEDIUM 5.0EPSS 13.3% | 5 October 1998 |
| CVE-1999-0870 | Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste. | LOW 2.6EPSS 12.8% | 1 October 1998 |
| CVE-1999-0506 | A Windows NT domain user or administrator account has a default, null, blank, or missing password. | HIGH 7.2EPSS 17.2% | 1 October 1998 |
| CVE-1999-0969 | The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which generate an error message that is sent to the spoofed host, potentially setting up a loop, aka Snork. | MEDIUM 5.0EPSS 13.3% | 29 September 1998 |
| CVE-1999-0871 | Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE's cross frame security, aka the "Cross Frame Navigate" vulnerability. | LOW 2.6EPSS 12.1% | 4 September 1998 |
| CVE-1999-0516 | An SNMP community name is guessable. | HIGH 7.5EPSS 10.5% | 1 August 1998 |
| CVE-1999-0288 | The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets. | EXPLOIT ✓MEDIUM 5.0EPSS 21.3% | 1 August 1998 |
| CVE-1999-1447 | Internet Explorer 4.0 allows remote attackers to cause a denial of service (crash) via HTML code that contains a long CLASSID parameter in an OBJECT tag. | MEDIUM 5.0EPSS 13.3% | 28 July 1998 |
| CVE-1999-0005 | Arbitrary command execution via IMAP buffer overflow in authenticate command. | EXPLOIT ✓HIGH 10.0EPSS 18.4% | 20 July 1998 |
| CVE-1999-0006 | Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command. | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 12.1% | 14 July 1998 |
| CVE-1999-1479 | The textcounter.pl by Matt Wright allows remote attackers to execute arbitrary commands via shell metacharacters. | EXPLOIT ✓HIGH 10.0EPSS 12.0% | 24 June 1998 |
| CVE-1999-0278 | In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL. | EXPLOIT ✓MEDIUM 5.0EPSS 64.8% | 1 June 1998 |
| CVE-1999-0009 | Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases. | EXPLOIT ×2 ✓HIGH 10.0EPSS 29.0% | 8 April 1998 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.