SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,329 CVEs1,721 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

17,157 results · page 344 of 344

CVESummaryPriorityPublished
CVE-1999-0208rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.EXPLOIT ×2HIGH 10.0EPSS 12.9%12 December 1995
CVE-1999-0066AnyForm CGI remote execution.EXPLOITCRITICAL 9.8EPSS 12.3%31 July 1995
CVE-1999-0077Predictable TCP sequence numbers allow spoofing.EXPLOITMEDIUM 5.0EPSS 31.4%1 January 1995
CVE-1999-0113Some implementations of rlogin allow root access if given a -froot parameter.EXPLOITHIGH 10.0EPSS 17.2%23 May 1994
CVE-1999-0209The SunView (SunTools) selection_svc facility allows remote users to read files.EXPLOIT ×3MEDIUM 5.0EPSS 48.5%14 August 1990
CVE-1999-1467Vulnerability in rcp on SunOS 4.0.x allows remote attackers from trusted hosts to execute arbitrary commands as root, possibly related to the configuration of the nobody user.HIGH 10.0EPSS 10.2%26 October 1989
CVE-1999-0095The debug command in Sendmail is enabled, allowing attackers to execute commands as root.EXPLOITHIGH 10.0EPSS 16.3%1 October 1988

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.