Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,853 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 362 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-6912 | SQL injection vulnerability in phpMyFAQ 1.6.7 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly the userfile or filename parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 31 December 2006 |
| CVE-2006-6911 | SQL injection vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated users to execute arbitrary SQL commands via the ordernum parameter. | EXPLOIT ✓MEDIUM 6.0EPSS 0.90% | 31 December 2006 |
| CVE-2006-6910 | formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with Abfrage, allows remote attackers to cause a denial of service (daemon crash) via multiple requests containing many /../ sequences in the Name parameter. | EXPLOIT ✓HIGH 7.8EPSS 3.17% | 31 December 2006 |
| CVE-2006-6899 | hidd in BlueZ (bluez-utils) before 2.25 allows remote attackers to obtain control of the (1) Mouse and (2) Keyboard Human Interface Device (HID) via a certain configuration of two HID (PSM) endpoints, operating as a server, aka HidAttack. | EXPLOIT ✓MEDIUM 5.4EPSS 3.32% | 31 December 2006 |
| CVE-2006-6891 | Vz (Adp) Forum 2.0.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the administrative account name and password hash via a direct request for users/admin.txt. | EXPLOIT ✓MEDIUM 5.0EPSS 2.34% | 31 December 2006 |
| CVE-2006-6890 | Voodoo chat 1.0RC1b stores sensitive information under the web root with insufficient access control, which allows remote attackers to download passwords via a direct request for data/users.dat. | EXPLOIT ✓HIGH 7.5EPSS 2.19% | 31 December 2006 |
| CVE-2006-6889 | FreeStyle Wiki (fswiki) 3.6.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request for config/user.dat. | EXPLOIT ✓HIGH 7.5EPSS 2.19% | 31 December 2006 |
| CVE-2006-6888 | P-News 1.16 and 1.17 store sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the administrative account name and password hash via a direct request for db/user.dat. | EXPLOIT ✓MEDIUM 5.0EPSS 2.34% | 31 December 2006 |
| CVE-2006-6887 | Unrestricted file upload vulnerability in logahead UNU 1.0 allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors related to plugins/widged/_widged.php (aka the WidgEd plugin), a different vulnerability than… | EXPLOIT ✓MEDIUM 6.8EPSS 1.71% | 31 December 2006 |
| CVE-2006-6885 | An ActiveX control in SwDir.dll in Macromedia Shockwave 10 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long string in the swURL attribute. | EXPLOIT ✓MEDIUM 4.3EPSS 7.59% | 31 December 2006 |
| CVE-2006-6884 | Buffer overflow in the WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 Build 6667 allows remote attackers to execute arbitrary code via a long argument to the CreateNewFolderFromName method, a… | EXPLOIT ×3 ✓HIGH 9.3EPSS 4.52% | 31 December 2006 |
| CVE-2006-6880 | Multiple SQL injection vulnerabilities in code/guestadd.php in PHP-Update 2.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) newmessage, (2) newname, (3) newwebsite, or (4) newemail parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 31 December 2006 |
| CVE-2006-6879 | Unrestricted file upload vulnerability in admin/uploads.php in PHP-Update 2.7 and earlier allows remote authenticated users to upload arbitrary PHP scripts to the gfx/ and files/ directories via the userfile parameter. | EXPLOIT ×2 ✓MEDIUM 6.0EPSS 1.88% | 31 December 2006 |
| CVE-2006-6878 | admin/uploads.php in PHP-Update 2.7 and earlier allows remote attackers to gain privileges by setting the rights[7] parameter to 1 during a login action. | EXPLOIT ✓HIGH 7.5EPSS 2.42% | 31 December 2006 |
| CVE-2006-6877 | Directory traversal vulnerability in index.php in Matteo Lucarelli 3editor CMS 0.42 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 2.17% | 31 December 2006 |
| CVE-2006-6873 | Multiple SQL injection vulnerabilities in mod.php in eNdonesia 8.4 allow remote attackers to execute arbitrary SQL commands via (1) the did parameter in a (a) viewdisk operation (diskusi mod), or the (2) cid parameter in a (b) viewlink (katalog mod) or… | EXPLOIT ✓HIGH 7.5EPSS 1.23% | 31 December 2006 |
| CVE-2006-6872 | Directory traversal vulnerability in mod.php in eNdonesia 8.4 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.11% | 31 December 2006 |
| CVE-2006-6871 | Multiple cross-site scripting (XSS) vulnerabilities in eNdonesia 8.4 allow remote attackers to inject arbitrary web script or HTML via (1) the mod parameter in a viewlink operation in mod.php, (2) the intypeid parameter in a showinfo operation in the… | EXPLOIT ✓MEDIUM 6.8EPSS 2.03% | 31 December 2006 |
| CVE-2006-6869 | Directory traversal vulnerability in includes/search/search_mdforum.php in MAXdev MDForum 2.0.1 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 9.3EPSS 3.32% | 31 December 2006 |
| CVE-2006-6867 | Multiple PHP remote file inclusion vulnerabilities in Vladimir Menshakov buratinable templator (aka bubla) 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the bu_dir parameter to (1) bu/bu_claro.php, (2) bu/bu_cache.php, or (3)… | EXPLOIT ✓HIGH 7.5EPSS 3.46% | 31 December 2006 |
| CVE-2006-6866 | STphp EasyNews PRO 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames, email addresses, and password hashes via a direct request for data/users.txt. | EXPLOIT ✓HIGH 7.8EPSS 3.11% | 31 December 2006 |
| CVE-2006-6865 | Directory traversal vulnerability in SAFileUpSamples/util/viewsrc.asp in SoftArtisans FileUp (SAFileUp) 5.0.14 allows remote attackers to read arbitrary files via a %c0%ae. | EXPLOIT ✓HIGH 7.8EPSS 4.54% | 31 December 2006 |
| CVE-2006-6864 | PHP remote file inclusion vulnerability in E2_header.inc.php in Enigma2 Coppermine Bridge 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the boarddir parameter. | EXPLOIT ✓HIGH 10.0EPSS 5.06% | 31 December 2006 |
| CVE-2006-6863 | PHP remote file inclusion vulnerability in the Enigma2 plugin (Enigma2.php) in Enigma WordPress Bridge allows remote attackers to execute arbitrary PHP code via a URL in the boarddir parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 13.0% | 31 December 2006 |
| CVE-2006-6861 | Multiple SQL injection vulnerabilities in Outfront Spooky Login 2.7 allow remote attackers to execute arbitrary SQL commands via (1) the UserUpdate parameter to login/register.asp or (2) unspecified parameters to includes/a_register.asp. | EXPLOIT ✓HIGH 10.0EPSS 1.41% | 31 December 2006 |
| CVE-2006-6859 | SQL injection vulnerability in coupon_detail.asp in Website Designs For Less Click N' Print Coupons 2005.01 and earlier allows remote attackers to execute arbitrary SQL commands via the key parameter. | EXPLOIT ✓HIGH 10.0EPSS 1.84% | 31 December 2006 |
| CVE-2006-6856 | Direct static code injection vulnerability in WebText CMS 0.4.5.2 and earlier allows remote attackers to inject arbitrary PHP code into a script in wt/users/ via the im parameter during a profile edit (edycja) operation, which is then executed via a… | EXPLOIT ✓HIGH 7.5EPSS 2.51% | 31 December 2006 |
| CVE-2006-6855 | AIDeX Mini-WebServer 1.1 early release 3 allows remote attackers to cause a denial of service (daemon crash) via a flood of HTTP GET requests, possibly related to display of HTTP log data by the GUI. | EXPLOIT ✓MEDIUM 5.0EPSS 3.34% | 31 December 2006 |
| CVE-2006-6853 | Buffer overflow in Durian Web Application Server 3.02 freeware on Windows allows remote attackers to execute arbitrary code via a long string in a crafted packet to TCP port 4002. | EXPLOIT ×2 ✓HIGH 10.0EPSS 8.07% | 31 December 2006 |
| CVE-2006-6851 | Multiple cross-site scripting (XSS) vulnerabilities in contact_us.php in ac4p Mobilelib gold 2 allow remote attackers to inject arbitrary web script or HTML via the (1) email or (2) errr parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.70% | 31 December 2006 |
| CVE-2006-6850 | PHP remote file inclusion vulnerability in include.php in the Roster Module (character_roster) in Shadowed Portal 5.7 allows remote attackers to execute arbitrary PHP code via a URL in the mod_root parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.85% | 31 December 2006 |
| CVE-2006-6849 | administration/index.php in Cahier de texte (CDT) 2.2 does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions. | EXPLOIT ✓HIGH 7.5EPSS 2.54% | 31 December 2006 |
| CVE-2006-6848 | SQL injection vulnerability in admin.asp in ASPTicker 1.0 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO, possibly related to the Password parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.09% | 31 December 2006 |
| CVE-2006-6847 | An ActiveX control in ierpplug.dll for RealNetworks RealPlayer 10.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) by invoking the RealPlayer.OpenURLInPlayerBrowser method with a long second argument. | EXPLOIT ✓MEDIUM 5.0EPSS 6.35% | 31 December 2006 |
| CVE-2006-6846 | Multiple SQL injection vulnerabilities in While You Were Out (WYWO) InOut Board 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the num parameter in (a) phonemessage.asp, (2) the catcode parameter in (b) faqDsp.asp, and the (3)… | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 31 December 2006 |
| CVE-2006-6845 | Cross-site scripting (XSS) vulnerability in index.php in CMS Made Simple 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the cntnt01searchinput parameter in a Search action. | EXPLOIT ✓MEDIUM 6.8EPSS 1.75% | 31 December 2006 |
| CVE-2006-6842 | SQL injection vulnerability in admin/admin_acronyms.php in the Acronym Mod 0.9.5 for phpBB2 Plus 1.53 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 31 December 2006 |
| CVE-2006-6838 | Rediff Bol Downloader ActiveX (OCX) control allows remote attackers to execute arbitrary files, and obtain sensitive information (usernames and pathnames), via a URL in the url vbscript parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.41% | 31 December 2006 |
| CVE-2006-6831 | SQL injection vulnerability in faqDsp.asp in aFAQ 1.0 allows remote attackers to execute arbitrary SQL commands via the catcode parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 31 December 2006 |
| CVE-2006-6830 | PHP remote file inclusion vulnerability in b2verifauth.php in b2 Blog 0.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the index parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.33% | 31 December 2006 |
| CVE-2006-6827 | Flash8b.ocx in Macromedia Flash 8 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long string in the Flash8b.AllowScriptAccess method. | EXPLOIT ✓MEDIUM 5.0EPSS 3.43% | 31 December 2006 |
| CVE-2006-6488 | Stack-based buffer overflow in the DoModal function in the Dialog Wrapper Module ActiveX control (DlgWrapper.dll) before 8.4.166.0, as used by ICONICS OPC Enabled Gauge, Switch, and Vessel ActiveX, allows remote attackers to execute arbitrary code via a… | EXPLOIT ✓HIGH 7.5EPSS 7.84% | 31 December 2006 |
| CVE-2006-4220 | Multiple cross-site scripting (XSS) vulnerabilities in webacc in Novell GroupWise WebAccess before 7 Support Pack 3 Public Beta allow remote attackers to inject arbitrary web script or HTML via the (1) User.html, (2) Error, (3) User.Theme.index, and (4)… | EXPLOIT ✓MEDIUM 4.3EPSS 1.93% | 31 December 2006 |
| CVE-2006-6824 | Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) getdate parameter in (a) day.php, (b) month.php, (c) year.php, (d)… | EXPLOIT ×8 ✓MEDIUM 4.3EPSS 2.58% | 29 December 2006 |
| CVE-2006-6823 | PHP remote file inclusion vulnerability in plugins/metasearch/plug.inc.php in Yrch! | EXPLOIT ✓HIGH 7.5EPSS 2.43% | 29 December 2006 |
| CVE-2006-6822 | myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a… | EXPLOIT ✓LOW 3.5EPSS 1.80% | 29 December 2006 |
| CVE-2006-6821 | myprofile.asp in Enthrallweb eNews does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a… | EXPLOIT ✓LOW 3.5EPSS 1.81% | 29 December 2006 |
| CVE-2006-6820 | myprofile.asp in Enthrallweb eCoupons does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a… | EXPLOIT ✓LOW 3.5EPSS 1.81% | 29 December 2006 |
| CVE-2006-6819 | AlstraSoft Web Host Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a backup database via a direct request for admin/backup/db. | EXPLOIT ✓MEDIUM 6.4EPSS 1.98% | 29 December 2006 |
| CVE-2006-6816 | Multiple SQL injection vulnerabilities in DMXReady Secure Login Manager 1.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) set_preferences.asp, (2) send_password_preferences.asp, and (3)… | EXPLOIT ×4 ✓HIGH 7.5EPSS 3.77% | 29 December 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.