58.127 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.127 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-1999-0504 | HIGH 7.5 | microsoft windows_2000 A Windows NT local user or administrator account has a default, null, blank, or missing password. | 64.3% | — |
| CVE-1999-0499 | HIGH 7.5 | microsoft windows_2000 NETBIOS share information may be published through SNMP registry keys in NT. | 4.8% | — |
| CVE-1999-0490 | HIGH 7.5 | microsoft internet_explorer MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to learn information about a local user's files via an IMG SRC tag. | 9.9% | — |
| CVE-1999-0488 | HIGH 7.5 | microsoft internet_explorer Internet Explorer 4.0 and 5.0 allows a remote attacker to execute security scripts in a different security context using malicious URLs, a variant of the "cross frame" vulnerability. | 11.8% | — |
| CVE-1999-0450 | HIGH 7.5 | microsoft internet_information_server In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe). | 19.0% | — |
| CVE-1999-0415 | HIGH 7.5 | cisco cisco_7xx_routers The HTTP server in Cisco 7xx series routers 3.2 through 4.2 is enabled by default, which allows remote attackers to change the router's configuration. | 1.4% | — |
| CVE-1999-0412 | HIGH 7.5 | microsoft internet_information_server In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension. | 10.2% | — |
| CVE-1999-0391 | HIGH 7.5 | microsoft terminal_server The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user. | 4.9% | — |
| CVE-1999-0379 | HIGH 7.5 | microsoft backoffice_resource_kit Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting. | 5.8% | — |
| CVE-1999-0366 | HIGH 7.5 | microsoft windows_nt In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value. | 3.7% | — |
| CVE-1999-0354 | HIGH 7.5 | microsoft internet_explorer Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content. Also applies to Outlook when the client vie | 5.2% | — |
| CVE-1999-0349 | HIGH 7.5 | microsoft internet_information_server A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands. | 17.9% | — |
| CVE-1999-0332 | HIGH 7.5 | microsoft netmeeting Buffer overflow in NetMeeting allows denial of service and remote command execution. | 12.8% | — |
| CVE-1999-0331 | HIGH 7.5 | microsoft internet_explorer Buffer overflow in Internet Explorer 4.0(1). | 5.0% | — |
| CVE-1999-0293 | HIGH 7.5 | cisco ios AAA authentication on Cisco systems allows attackers to execute commands without authorization. | 2.6% | — |
| CVE-1999-0284 | HIGH 7.5 | ibm lotus_domino_mail_server Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command. | 11.5% | — |
| CVE-1999-0280 | HIGH 7.5 | microsoft internet_explorer Remote command execution in Microsoft Internet Explorer using .lnk and .url files. | 15.6% | — |
| CVE-1999-0256 | HIGH 7.5 | jgaa warftpd Buffer overflow in War FTP allows remote execution of commands. | 72.9% | — |
| CVE-1999-0253 | HIGH 7.5 | microsoft internet_information_server IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL. | 8.0% | — |
| CVE-1999-0236 | HIGH 7.5 | apache http_server ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs. | 25.8% | — |
| CVE-1999-0161 | HIGH 7.5 | cisco ios In Cisco IOS 10.3, with the tacacs-ds or tacacs keyword, an extended IP access control list could bypass filtering. | 1.7% | — |
| CVE-1999-0160 | HIGH 7.5 | cisco ios Some classic Cisco IOS devices have a vulnerability in the PPP CHAP authentication to establish unauthorized PPP connections. | 1.2% | — |
| CVE-1999-0071 | HIGH 7.5 | apache http_server Apache httpd cookie buffer overflow for versions 1.1.1 and earlier. | 3.6% | — |
| CVE-1999-0045 | HIGH 7.5 | apache http_server List of arbitrary files on Web host via nph-test-cgi script. | 26.0% | — |
| CVE-2026-91734 | HIGH 7.4 | google chrome Incorrect authorization in Core in Google Chrome on on Windows prior to 153.0.8010.47 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) | 0.1% | — |