Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,329 CVEs1,721 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
17,157 results · page 343 of 344
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-1999-0270 | Directory traversal vulnerability in pfdispaly.cgi program (sometimes referred to as "pfdisplay") for SGI's Performer API Search Tool (performer_tools) allows remote attackers to read arbitrary files. | MEDIUM 5.0EPSS 32.1% | 3 April 1998 |
| CVE-1999-0003 | Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd). | EXPLOIT ×2 ✓HIGH 10.0EPSS 24.6% | 1 April 1998 |
| CVE-1999-0502 | A Unix account has a default, null, blank, or missing password. | EXPLOIT ✓HIGH 7.5EPSS 53.3% | 1 March 1998 |
| CVE-1999-0225 | Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data size does not match the specified size. | MEDIUM 5.0EPSS 18.5% | 14 February 1998 |
| CVE-1999-0012 | Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names. | HIGH 7.0EPSS 18.5% | 6 February 1998 |
| CVE-1999-0256 | Buffer overflow in War FTP allows remote execution of commands. | EXPLOIT ×2 ✓HIGH 7.5EPSS 72.9% | 1 February 1998 |
| CVE-1999-0513 | ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service. | EXPLOIT ✓MEDIUM 5.0EPSS 70.9% | 5 January 1998 |
| CVE-1999-0284 | Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command. | EXPLOIT ×3 ✓HIGH 7.5EPSS 11.5% | 1 January 1998 |
| CVE-1999-0107 | Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters. | EXPLOIT ✓MEDIUM 5.0EPSS 19.9% | 30 December 1997 |
| CVE-1999-1581 | Memory leak in Simple Network Management Protocol (SNMP) agent (snmp.exe) for Windows NT 4.0 before Service Pack 4 allows remote attackers to cause a denial of service (memory consumption) via a large number of SNMP packets with Object Identifiers… | MEDIUM 5.0EPSS 20.6% | 23 December 1997 |
| CVE-1999-0015 | Teardrop IP denial of service. | EXPLOIT ✓MEDIUM 5.0EPSS 35.4% | 16 December 1997 |
| CVE-1999-0018 | Buffer overflow in statd allows root privileges. | EXPLOIT ✓HIGH 10.0EPSS 10.5% | 5 December 1997 |
| CVE-1999-0016 | Land IP denial of service. | EXPLOIT ×5 ✓MEDIUM 5.0EPSS 95.7% | 1 December 1997 |
| CVE-1999-0021 | Arbitrary command execution via buffer overflow in Count.cgi (wwwcount) cgi-bin program. | EXPLOIT ✓HIGH 7.5EPSS 26.7% | 5 November 1997 |
| CVE-1999-0192 | Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable. | EXPLOIT ×2 ✓HIGH 10.0EPSS 10.0% | 18 October 1997 |
| CVE-1999-0294 | All records in a WINS database can be deleted through SNMP for a denial of service. | EXPLOIT ✓MEDIUM 5.0EPSS 14.7% | 1 October 1997 |
| CVE-1999-0267 | Buffer overflow in NCSA HTTP daemon v1.3 allows remote command execution. | EXPLOIT ×2 ✓HIGH 7.5EPSS 10.2% | 23 September 1997 |
| CVE-1999-0667 | The ARP protocol allows any host to spoof ARP replies and poison the ARP cache to conduct IP address spoofing or a denial of service. | HIGH 10.0EPSS 15.0% | 19 September 1997 |
| CVE-1999-0191 | IIS newdsn.exe CGI script allows remote users to overwrite files. | EXPLOIT ✓MEDIUM 6.4EPSS 53.3% | 1 September 1997 |
| CVE-1999-0148 | The handler CGI program in IRIX allows arbitrary command execution. | EXPLOIT ✓HIGH 7.5EPSS 10.5% | 1 September 1997 |
| CVE-1999-0524 | ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts. | MEDIUM 4.0EPSS 32.2% | 1 August 1997 |
| CVE-1999-0025 | root privileges via buffer overflow in df command on SGI IRIX systems. | EXPLOIT ✓HIGH 7.2EPSS 12.3% | 16 July 1997 |
| CVE-1999-0146 | The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file. | EXPLOIT ✓HIGH 7.5EPSS 14.9% | 15 July 1997 |
| CVE-1999-1463 | Windows NT 4.0 before SP3 allows remote attackers to bypass firewall restrictions or cause a denial of service (crash) by sending improperly fragmented IP packets without the first fragment, which the TCP/IP stack incorrectly reassembles into a valid… | MEDIUM 5.0EPSS 16.6% | 10 July 1997 |
| CVE-1999-0196 | websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable). | EXPLOIT ✓MEDIUM 5.0EPSS 13.4% | 8 July 1997 |
| CVE-1999-0031 | JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability. | LOW 2.6EPSS 18.3% | 8 July 1997 |
| CVE-1999-0532 | A DNS server allows zone transfers. | LOW 0.0EPSS 69.3% | 1 July 1997 |
| CVE-1999-0526 | An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server. | HIGH 10.0EPSS 20.8% | 1 July 1997 |
| CVE-1999-0153 | Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke. | EXPLOIT ×4 ✓MEDIUM 5.0EPSS 21.1% | 1 July 1997 |
| CVE-1999-0281 | Denial of service in IIS using long URLs. | EXPLOIT ✓MEDIUM 5.0EPSS 12.8% | 1 June 1997 |
| CVE-1999-0039 | webdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers to execute arbitrary commands via shell metacharacters in the distloc parameter. | EXPLOIT ✓HIGH 7.3EPSS 16.2% | 6 May 1997 |
| CVE-1999-0042 | Buffer overflow in University of Washington's implementation of IMAP and POP servers. | EXPLOIT ✓HIGH 10.0EPSS 12.7% | 7 April 1997 |
| CVE-1999-1387 | Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by a Linux smbmount command that was compiled on the Linux 2.0.29 kernel but executed on Linux 2.0.25. | MEDIUM 5.0EPSS 21.2% | 2 April 1997 |
| CVE-1999-0280 | Remote command execution in Microsoft Internet Explorer using .lnk and .url files. | HIGH 7.5EPSS 15.6% | 1 April 1997 |
| CVE-1999-0612 | A version of finger is running that exposes valid user information to any entity on the network. | LOW 0.0EPSS 68.0% | 1 March 1997 |
| CVE-1999-0046 | Buffer overflow of rlogin program using TERM environmental variable. | EXPLOIT ✓HIGH 10.0EPSS 51.9% | 6 February 1997 |
| CVE-1999-0562 | The registry in Windows NT can be accessed remotely by users who are not administrators. | EXPLOIT ✓HIGH 7.5EPSS 10.1% | 1 January 1997 |
| CVE-1999-0517 | An SNMP community name is the default (e.g. public), null, or missing. | MEDIUM 5.9EPSS 27.2% | 1 January 1997 |
| CVE-1999-0504 | A Windows NT local user or administrator account has a default, null, blank, or missing password. | EXPLOIT ✓HIGH 7.5EPSS 64.3% | 1 January 1997 |
| CVE-1999-0236 | ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs. | EXPLOIT ✓HIGH 7.5EPSS 25.8% | 1 January 1997 |
| CVE-1999-0178 | Buffer overflow in the win-c-sample program (win-c-sample.exe) in the WebSite web server 1.1e allows remote attackers to execute arbitrary code via a long query string. | EXPLOIT ✓HIGH 7.5EPSS 12.5% | 1 January 1997 |
| CVE-1999-0170 | Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list. | HIGH 7.5EPSS 18.7% | 1 January 1997 |
| CVE-1999-0128 | Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death. | EXPLOIT ✓MEDIUM 5.0EPSS 74.5% | 18 December 1996 |
| CVE-1999-0045 | List of arbitrary files on Web host via nph-test-cgi script. | EXPLOIT ✓HIGH 7.5EPSS 26.0% | 10 December 1996 |
| CVE-1999-0043 | Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others. | CRITICAL 9.8EPSS 44.6% | 4 December 1996 |
| CVE-1999-0509 | Perl, sh, csh, or other shell interpreters are installed in the cgi-bin directory on a WWW site, which allows remote attackers to execute arbitrary commands. | HIGH 10.0EPSS 33.4% | 29 May 1996 |
| CVE-1999-0070 | test-cgi program allows an attacker to list files on the server. | EXPLOIT ✓MEDIUM 5.0EPSS 29.6% | 1 April 1996 |
| CVE-1999-0067 | phf CGI program allows remote command execution through shell metacharacters. | HIGH 10.0EPSS 86.9% | 20 March 1996 |
| CVE-1999-0233 | IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files. | EXPLOIT ✓HIGH 10.0EPSS 16.3% | 25 February 1996 |
| CVE-1999-0103 | Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. | MEDIUM 5.0EPSS 14.5% | 8 February 1996 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.