SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-29 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,853 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026

25,049 results · page 363 of 501

CVESummaryPriorityPublished
CVE-2006-6814Directory traversal vulnerability in FolderManager/FolderManager.aspx in Hosting Controller 7c allows remote authenticated users to read and modify arbitrary files, and list arbitrary directories via ..\ (dot dot backslash) sequences in the BrowsePath…EXPLOIT ✓MEDIUM 6.3EPSS 2.05%29 December 2006
CVE-2006-6813SQL injection vulnerability in detail.asp in Mxmania File Upload Manager (FUM) 1.0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.24%29 December 2006
CVE-2006-6812Multiple PHP remote file inclusion vulnerabilities in myPHPCalendar 10.1 allow remote attackers to execute arbitrary PHP code via a URL in the cal_dir parameter to (1) admin.php, (2) contacts.php, or (3) convert-date.php.EXPLOIT ✓HIGH 7.5EPSS 2.38%29 December 2006
CVE-2006-6811KsIRC 1.3.12 allows remote attackers to cause a denial of service (crash) via a long PRIVMSG string when connecting to an Internet Relay Chat (IRC) server, which causes an assertion failure and results in a NULL pointer dereference.EXPLOIT ✓MEDIUM 6.5EPSS 10.6%29 December 2006
CVE-2006-6810Unspecified vulnerability in the clear_user_list function in src/main.c in DB Hub 0.3 allows remote attackers to cause a denial of service (application crash) via crafted network traffic, which triggers memory corruption.EXPLOIT ✓MEDIUM 5.0EPSS 3.93%29 December 2006
CVE-2006-6809Multiple PHP remote file inclusion vulnerabilities in process.php in Vladimir Menshakov buratinable templator (aka bubla) 1.0.0rc2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) bu_dir or (2) bu_config[dir]…EXPLOIT ✓HIGH 7.5EPSS 2.43%29 December 2006
CVE-2006-6808Cross-site scripting (XSS) vulnerability in wp-admin/templates.php in WordPress 2.0.5 allows remote attackers to inject arbitrary web script or HTML via the file parameter.EXPLOIT ✓MEDIUM 6.8EPSS 6.88%28 December 2006
CVE-2006-6807SQL injection vulnerability in list.asp in Softwebs Nepal (aka Ananda Raj Pandey) Ananda Real Estate 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the agent parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.10%28 December 2006
CVE-2006-6806SQL injection vulnerability in newsdetail.asp in Enthrallweb eMates 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.11%28 December 2006
CVE-2006-6805SQL injection vulnerability in newsdetail.asp in Enthrallweb eJobs allows remote attackers to execute arbitrary SQL commands via the ID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.11%28 December 2006
CVE-2006-6804SQL injection vulnerability in bus_details.asp in Dragon Business Directory - Pro (aka Dragon Internet Business Search Directory - Pro) 3.01.12 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.09%28 December 2006
CVE-2006-6803SQL injection vulnerability in Types.asp in Enthrallweb eCars 1.0 allows remote attackers to execute arbitrary SQL commands via the Type_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.08%28 December 2006
CVE-2006-6802SQL injection vulnerability in actualpic.asp in Enthrallweb ePages allows remote attackers to execute arbitrary SQL commands via the Biz_ID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.09%28 December 2006
CVE-2006-6801PHP remote file inclusion vulnerability in misc.php in SH-News 0.93, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the news_cfg[path] parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.13%28 December 2006
CVE-2006-6800PHP remote file inclusion in eventcal/mod_eventcal.php in the event module 1.0 for Limbo CMS allows remote attackers to execute arbitrary PHP code via a URL in the lm_absolute_path parameter.EXPLOIT ✓MEDIUM 6.8EPSS 3.47%28 December 2006
CVE-2006-6797The Client Server Run-Time Subsystem (CSRSS) in Microsoft Windows allows local users to cause a denial of service (crash) or read arbitrary memory from csrss.exe via crafted arguments to the NtRaiseHardError function with status 0x50000018, a different…EXPLOIT ✓MEDIUM 6.6EPSS 7.18%28 December 2006
CVE-2006-6796PHP remote file inclusion vulnerability in admin/admin_settings.php in MTCMS 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ins_file parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.13%28 December 2006
CVE-2006-6795PHP remote file inclusion vulnerability in gallery/displayCategory.php in the My_eGallery 2.5.6 module in myPHPNuke (MPN) allows remote attackers to execute arbitrary PHP code via a URL in the basepath parameter.EXPLOIT ✓HIGH 7.5EPSS 2.43%28 December 2006
CVE-2006-6794SQL injection vulnerability in default.asp in Efkan Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the grup parameter.EXPLOIT ✓HIGH 7.5EPSS 1.07%28 December 2006
CVE-2006-6793PHP remote file inclusion vulnerability in ataturk.php in Okul Merkezi Portal 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.EXPLOIT ✓HIGH 7.5EPSS 2.50%28 December 2006
CVE-2006-6792SQL injection vulnerability in calendar_detail.asp in Calendar MX BASIC 1.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.13%28 December 2006
CVE-2006-6791SQL injection vulnerability in SelGruFra.asp in chatwm 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) txtUse and (2) txtPas parameters.EXPLOIT ✓HIGH 7.5EPSS 1.08%28 December 2006
CVE-2006-6790Direct static code injection vulnerability in chat/login.php in Ultimate PHP Board (UPB) 2.0b1 and earlier allows remote attackers to inject arbitrary PHP code via the username parameter, which is injected into chat/text.php.EXPLOIT ✓HIGH 7.5EPSS 2.42%28 December 2006
CVE-2006-6789PHP remote file inclusion vulnerability in includes/archive/archive_topic.php in Phpbbxtra 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.EXPLOIT ✓HIGH 7.5EPSS 3.25%28 December 2006
CVE-2006-6788Multiple PHP remote file inclusion vulnerabilities in LuckyBot 3 allow remote attackers to execute arbitrary PHP code via a URL in the dir parameter to (1) run.php or (2) ircbot.class.php.EXPLOIT ✓HIGH 7.5EPSS 2.50%28 December 2006
CVE-2006-6787SQL injection vulnerability in admin/admin_mail_adressee.asp in Newsletter MX 1.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.18%28 December 2006
CVE-2006-6786Open Newsletter 2.5 and earlier allows remote authenticated administrators to execute arbitrary PHP code by inserting the code into the email parameter to (1) subscribe.php or (2) unsubscribe.php.EXPLOIT ✓MEDIUM 6.5EPSS 1.88%28 December 2006
CVE-2006-6785The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, or execute arbitrary code in conjunction with…EXPLOIT ✓HIGH 7.5EPSS 4.35%28 December 2006
CVE-2006-6781HLstats 1.20 through 1.34 allows remote attackers to obtain sensitive information via playinfo mode, with certain values of the player and playerdata[lastName][] parameters, which reveals the path in an error message.EXPLOIT ✓MEDIUM 5.0EPSS 2.93%28 December 2006
CVE-2006-6780SQL injection vulnerability in the login form in HLstats 1.20 through 1.34 allows remote attackers to execute arbitrary SQL commands via the killLimit parameter.EXPLOIT ✓HIGH 7.5EPSS 1.22%28 December 2006
CVE-2006-6779Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin allows remote attackers to inject arbitrary web script or HTML via an SWF file that uses ActionScript to trigger execution of JavaScript.EXPLOIT ✓MEDIUM 6.8EPSS 3.51%28 December 2006
CVE-2006-6778Cross-site scripting (XSS) vulnerability in shownews.php in TimberWolf 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the nid parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.09%28 December 2006
CVE-2006-6777Cross-site scripting (XSS) vulnerability in index.cfm in Future Internet allows remote attackers to inject arbitrary web script or HTML via the categoryId parameter in a Portal.ShowPage action.EXPLOIT ✓MEDIUM 6.8EPSS 1.85%28 December 2006
CVE-2006-6776Multiple SQL injection vulnerabilities in Future Internet allow remote attackers to execute arbitrary SQL commands via the (1) newsId or (2) categoryid parameter in a Portal.Showpage action in index.cfm, or (3) the langId parameter in index.cfm.EXPLOIT ✓HIGH 7.5EPSS 1.07%28 December 2006
CVE-2006-6775acFTP 1.5 allows remote authenticated users to cause a denial of service via a crafted argument to the (1) REST or (2) PBSZ command.EXPLOIT ✓LOW 3.5EPSS 1.97%27 December 2006
CVE-2006-6774PHP remote file inclusion vulnerability in socios/maquetacion_socio.php (members/maquetacion_member.php) in Ciberia Content Federator 1.0 allows remote attackers to execute arbitrary PHP code via the path parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.13%27 December 2006
CVE-2006-6773pages/register/register.php in Fishyshoop 0.930 beta allows remote attackers to create arbitrary administrative users by setting the is_admin HTTP POST parameter to 1.EXPLOIT ✓HIGH 7.5EPSS 2.57%27 December 2006
CVE-2006-6771Multiple PHP remote file inclusion vulnerabilities in Irokez CMS 0.7.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[PTH][func] parameter in (a) scripts/gallery.scr.php;…EXPLOIT ×2 ✓MEDIUM 6.8EPSS 2.27%27 December 2006
CVE-2006-6770Multiple PHP remote file inclusion vulnerabilities in Jinzora Media Jukebox 2.7 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter in (1) popup.php, (2) rss.php,…EXPLOIT ✓MEDIUM 6.8EPSS 4.53%27 December 2006
CVE-2006-6768Multiple cross-site scripting (XSS) vulnerabilities in default.asp in PWP Technologies The Classified Ad System allow remote attackers to inject arbitrary web script or HTML via the (1) cat or (2) main parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.76%27 December 2006
CVE-2006-6765Multiple PHP file inclusion vulnerabilities in src/admin/pt_upload.php in Pagetool 1.07 allow remote attackers to execute arbitrary PHP code via (1) a local filename or FTP/share URI in the config_file parameter or (2) a URL in the ptconf[src] parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.13%27 December 2006
CVE-2006-6764PHP remote file inclusion vulnerability in authenticate.php in Keep It Simple Guest Book (KISGB), when executing PHP through CGI, allows remote attackers to execute arbitrary PHP code via a URL in the default_path_to_themes parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.13%27 December 2006
CVE-2006-6763Multiple PHP remote file inclusion vulnerabilities in the Keep It Simple Guest Book (KISGB) allow remote attackers to execute arbitrary PHP code via a URL in the (1) path_to_themes parameter in (a) authenticate.php, and the (2) default_path_for_themes…EXPLOIT ✓HIGH 7.5EPSS 2.17%27 December 2006
CVE-2006-6761Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to execute arbitrary code via a long argument to the SUBSCRIBE command.EXPLOIT ✓MEDIUM 6.5EPSS 53.4%27 December 2006
CVE-2006-6760Multiple PHP remote file inclusion vulnerabilities in template.php in Phpmymanga 0.8.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) actionsPage or (2) formPage parameter.EXPLOIT ✓HIGH 7.5EPSS 2.48%27 December 2006
CVE-2006-6759A certain ActiveX control in rpau3260.dll in RealNetworks RealPlayer 10.5 allows remote attackers to cause a denial of service (Internet Explorer crash) by invoking the RealPlayer.Initialize method with certain arguments.EXPLOIT ✓MEDIUM 5.0EPSS 2.84%27 December 2006
CVE-2006-6758Directory traversal vulnerability in Http explorer 1.02 allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.84%27 December 2006
CVE-2006-6757Directory traversal vulnerability in index.php in cwmExplorer 1.0 allows remote attackers to read arbitrary files and source code, and obtain sensitive information via directory traversal sequences in the show_file parameter.EXPLOIT ✓HIGH 7.8EPSS 2.91%27 December 2006
CVE-2006-6756The code function in install.fct.php in Ixprim 1.2 produces a guessable value of the confidential IXP_CODE in mainfile.php, which might allow remote attackers to gain access to the administration panel via a brute force attack.EXPLOIT ✓MEDIUM 5.1EPSS 2.37%27 December 2006
CVE-2006-6755Ixprim 1.2 allows remote attackers to obtain sensitive information via a direct request for kernel/plugins/fckeditor2/ixprim_api.php, which reveals the path in an error message.EXPLOIT ✓MEDIUM 5.0EPSS 2.67%27 December 2006

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.