SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,329 CVEs1,721 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

17,157 results · page 343 of 344

CVESummaryPriorityPublished
CVE-1999-0270Directory traversal vulnerability in pfdispaly.cgi program (sometimes referred to as "pfdisplay") for SGI's Performer API Search Tool (performer_tools) allows remote attackers to read arbitrary files.MEDIUM 5.0EPSS 32.1%3 April 1998
CVE-1999-0003Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).EXPLOIT ×2HIGH 10.0EPSS 24.6%1 April 1998
CVE-1999-0502A Unix account has a default, null, blank, or missing password.EXPLOITHIGH 7.5EPSS 53.3%1 March 1998
CVE-1999-0225Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data size does not match the specified size.MEDIUM 5.0EPSS 18.5%14 February 1998
CVE-1999-0012Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.HIGH 7.0EPSS 18.5%6 February 1998
CVE-1999-0256Buffer overflow in War FTP allows remote execution of commands.EXPLOIT ×2HIGH 7.5EPSS 72.9%1 February 1998
CVE-1999-0513ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.EXPLOITMEDIUM 5.0EPSS 70.9%5 January 1998
CVE-1999-0284Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command.EXPLOIT ×3HIGH 7.5EPSS 11.5%1 January 1998
CVE-1999-0107Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters.EXPLOITMEDIUM 5.0EPSS 19.9%30 December 1997
CVE-1999-1581Memory leak in Simple Network Management Protocol (SNMP) agent (snmp.exe) for Windows NT 4.0 before Service Pack 4 allows remote attackers to cause a denial of service (memory consumption) via a large number of SNMP packets with Object Identifiers…MEDIUM 5.0EPSS 20.6%23 December 1997
CVE-1999-0015Teardrop IP denial of service.EXPLOITMEDIUM 5.0EPSS 35.4%16 December 1997
CVE-1999-0018Buffer overflow in statd allows root privileges.EXPLOITHIGH 10.0EPSS 10.5%5 December 1997
CVE-1999-0016Land IP denial of service.EXPLOIT ×5MEDIUM 5.0EPSS 95.7%1 December 1997
CVE-1999-0021Arbitrary command execution via buffer overflow in Count.cgi (wwwcount) cgi-bin program.EXPLOITHIGH 7.5EPSS 26.7%5 November 1997
CVE-1999-0192Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.EXPLOIT ×2HIGH 10.0EPSS 10.0%18 October 1997
CVE-1999-0294All records in a WINS database can be deleted through SNMP for a denial of service.EXPLOITMEDIUM 5.0EPSS 14.7%1 October 1997
CVE-1999-0267Buffer overflow in NCSA HTTP daemon v1.3 allows remote command execution.EXPLOIT ×2HIGH 7.5EPSS 10.2%23 September 1997
CVE-1999-0667The ARP protocol allows any host to spoof ARP replies and poison the ARP cache to conduct IP address spoofing or a denial of service.HIGH 10.0EPSS 15.0%19 September 1997
CVE-1999-0191IIS newdsn.exe CGI script allows remote users to overwrite files.EXPLOITMEDIUM 6.4EPSS 53.3%1 September 1997
CVE-1999-0148The handler CGI program in IRIX allows arbitrary command execution.EXPLOITHIGH 7.5EPSS 10.5%1 September 1997
CVE-1999-0524ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.MEDIUM 4.0EPSS 32.2%1 August 1997
CVE-1999-0025root privileges via buffer overflow in df command on SGI IRIX systems.EXPLOITHIGH 7.2EPSS 12.3%16 July 1997
CVE-1999-0146The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file.EXPLOITHIGH 7.5EPSS 14.9%15 July 1997
CVE-1999-1463Windows NT 4.0 before SP3 allows remote attackers to bypass firewall restrictions or cause a denial of service (crash) by sending improperly fragmented IP packets without the first fragment, which the TCP/IP stack incorrectly reassembles into a valid…MEDIUM 5.0EPSS 16.6%10 July 1997
CVE-1999-0196websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable).EXPLOITMEDIUM 5.0EPSS 13.4%8 July 1997
CVE-1999-0031JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability.LOW 2.6EPSS 18.3%8 July 1997
CVE-1999-0532A DNS server allows zone transfers.LOW 0.0EPSS 69.3%1 July 1997
CVE-1999-0526An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server.HIGH 10.0EPSS 20.8%1 July 1997
CVE-1999-0153Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.EXPLOIT ×4MEDIUM 5.0EPSS 21.1%1 July 1997
CVE-1999-0281Denial of service in IIS using long URLs.EXPLOITMEDIUM 5.0EPSS 12.8%1 June 1997
CVE-1999-0039webdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers to execute arbitrary commands via shell metacharacters in the distloc parameter.EXPLOITHIGH 7.3EPSS 16.2%6 May 1997
CVE-1999-0042Buffer overflow in University of Washington's implementation of IMAP and POP servers.EXPLOITHIGH 10.0EPSS 12.7%7 April 1997
CVE-1999-1387Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by a Linux smbmount command that was compiled on the Linux 2.0.29 kernel but executed on Linux 2.0.25.MEDIUM 5.0EPSS 21.2%2 April 1997
CVE-1999-0280Remote command execution in Microsoft Internet Explorer using .lnk and .url files.HIGH 7.5EPSS 15.6%1 April 1997
CVE-1999-0612A version of finger is running that exposes valid user information to any entity on the network.LOW 0.0EPSS 68.0%1 March 1997
CVE-1999-0046Buffer overflow of rlogin program using TERM environmental variable.EXPLOITHIGH 10.0EPSS 51.9%6 February 1997
CVE-1999-0562The registry in Windows NT can be accessed remotely by users who are not administrators.EXPLOITHIGH 7.5EPSS 10.1%1 January 1997
CVE-1999-0517An SNMP community name is the default (e.g. public), null, or missing.MEDIUM 5.9EPSS 27.2%1 January 1997
CVE-1999-0504A Windows NT local user or administrator account has a default, null, blank, or missing password.EXPLOITHIGH 7.5EPSS 64.3%1 January 1997
CVE-1999-0236ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.EXPLOITHIGH 7.5EPSS 25.8%1 January 1997
CVE-1999-0178Buffer overflow in the win-c-sample program (win-c-sample.exe) in the WebSite web server 1.1e allows remote attackers to execute arbitrary code via a long query string.EXPLOITHIGH 7.5EPSS 12.5%1 January 1997
CVE-1999-0170Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list.HIGH 7.5EPSS 18.7%1 January 1997
CVE-1999-0128Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.EXPLOITMEDIUM 5.0EPSS 74.5%18 December 1996
CVE-1999-0045List of arbitrary files on Web host via nph-test-cgi script.EXPLOITHIGH 7.5EPSS 26.0%10 December 1996
CVE-1999-0043Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.CRITICAL 9.8EPSS 44.6%4 December 1996
CVE-1999-0509Perl, sh, csh, or other shell interpreters are installed in the cgi-bin directory on a WWW site, which allows remote attackers to execute arbitrary commands.HIGH 10.0EPSS 33.4%29 May 1996
CVE-1999-0070test-cgi program allows an attacker to list files on the server.EXPLOITMEDIUM 5.0EPSS 29.6%1 April 1996
CVE-1999-0067phf CGI program allows remote command execution through shell metacharacters.HIGH 10.0EPSS 86.9%20 March 1996
CVE-1999-0233IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.EXPLOITHIGH 10.0EPSS 16.3%25 February 1996
CVE-1999-0103Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a.MEDIUM 5.0EPSS 14.5%8 February 1996

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.