Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,853 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 364 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-6425 | Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to execute arbitrary code via unspecified vectors involving the APPEND command. | EXPLOIT ✓HIGH 9.0EPSS 58.2% | 27 December 2006 |
| CVE-2006-6424 | Multiple buffer overflows in Novell NetMail before 3.52e FTF2 allow remote attackers to execute arbitrary code (1) by appending literals to certain IMAP verbs when specifying command continuation requests to IMAPD, resulting in a heap overflow; and (2)… | EXPLOIT ✓HIGH 9.0EPSS 60.3% | 27 December 2006 |
| CVE-2006-6752 | Buffer overflow in FTPRush 1.0.0.610 might allow attackers to gain privileges via a long Host field. | EXPLOIT ✓HIGH 7.5EPSS 2.00% | 27 December 2006 |
| CVE-2006-6751 | Format string vulnerability in XM Easy Personal FTP Server 5.2.1 allows remote attackers to cause a denial of service (application crash) via format string specifiers in the USER command or certain other available or nonexistent commands. | EXPLOIT ✓MEDIUM 5.0EPSS 3.36% | 27 December 2006 |
| CVE-2006-6750 | Format string vulnerability in XM Easy Personal FTP Server 5.0.1 allows remote attackers to cause a denial of service (application crash) via format string specifiers in a long PORT command. | EXPLOIT ✓MEDIUM 5.0EPSS 2.25% | 27 December 2006 |
| CVE-2006-6747 | SQL injection vulnerability in show_news.php in Xt-News 0.1 allows remote attackers to execute arbitrary SQL commands via the id_news parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.20% | 27 December 2006 |
| CVE-2006-6746 | Multiple cross-site scripting (XSS) vulnerabilities in Xt-News 0.1 allow remote attackers to inject arbitrary web script or HTML via the id_news parameter to (1) add_comment.php or (2) show_news.php. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.84% | 27 December 2006 |
| CVE-2006-6741 | Cross-site request forgery (CSRF) vulnerability in urlobox in MKPortal allows remote attackers to delete arbitrary messages as an administrator via a delete operation in an img BBcode tag. | EXPLOIT ✓MEDIUM 5.8EPSS 0.97% | 26 December 2006 |
| CVE-2006-6740 | Multiple PHP remote file inclusion vulnerabilities in phpProfiles 3.1.2b and earlier allow remote attackers to execute arbitrary PHP code via a URL in the menu parameter to (1) include/body.inc.php or (2) include/body_admin.inc.php; or a URL in the… | EXPLOIT ✓HIGH 7.5EPSS 9.50% | 26 December 2006 |
| CVE-2006-6739 | PHP remote file inclusion vulnerability in buycd.php in Paristemi 0.8.3 allows remote attackers to execute arbitrary PHP code via a URL in the HTTP_DOCUMENT_ROOT parameter, a different vector than CVE-2006-6689. | EXPLOIT ✓HIGH 7.5EPSS 2.22% | 26 December 2006 |
| CVE-2006-6738 | PHP remote file inclusion vulnerability in statistic.php in cwmCounter 5.1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.10% | 26 December 2006 |
| CVE-2006-6734 | Cross-site scripting (XSS) vulnerability in modules/viewcategory.php in Minh Nguyen Duong Obie Website Mini Web Shop 2.1.c allows remote attackers to inject arbitrary web script or HTML via the catname parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.80% | 26 December 2006 |
| CVE-2006-6733 | Cross-site scripting (XSS) vulnerability in support/view.php in Support Cards 1 (osTicket) allows remote attackers to inject arbitrary web script or HTML via the e parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.58% | 26 December 2006 |
| CVE-2006-6732 | PHP remote file inclusion vulnerability in archive.php in cwmVote 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the abs parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.33% | 26 December 2006 |
| CVE-2006-6729 | Cross-site scripting (XSS) vulnerability in a-blog 1.51 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | EXPLOIT ✓MEDIUM 4.3EPSS 1.90% | 26 December 2006 |
| CVE-2006-6726 | PHP remote file inclusion vulnerability in inertianews_main.php in inertianews 0.02 beta allows remote attackers to execute arbitrary PHP code via a URL in the inews_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.54% | 26 December 2006 |
| CVE-2006-6724 | BolinTech Dream FTP Server 1.02 allows remote authenticated users, including anonymous users, to cause a denial of service (application crash) via a certain invalid PORT command. | EXPLOIT ✓MEDIUM 4.0EPSS 2.51% | 26 December 2006 |
| CVE-2006-6723 | The Workstation service in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to cause a denial of service (memory consumption) via a large maxlen value in an NetrWkstaUserEnum RPC request. | EXPLOIT ✓HIGH 7.8EPSS 37.2% | 26 December 2006 |
| CVE-2006-6722 | Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to create administrative accounts via a direct request to admin.php with the Login parameter set to 1. | EXPLOIT ✓HIGH 7.5EPSS 2.50% | 23 December 2006 |
| CVE-2006-6721 | Multiple cross-site scripting (XSS) vulnerabilities in shout.php in Knusperleicht ShoutBox 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) sbNick or (2) sbKommentar parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.83% | 23 December 2006 |
| CVE-2006-6720 | PHP remote file inclusion vulnerability in admin/index_sitios.php in Azucar CMS 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the _VIEW parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.67% | 23 December 2006 |
| CVE-2006-6719 | The ftp_syst function in ftp-basic.c in Free Software Foundation (FSF) GNU wget 1.10.2 allows remote attackers to cause a denial of service (application crash) via a malicious FTP server with a large number of blank 220 responses to the SYST command. | EXPLOIT ✓MEDIUM 5.0EPSS 4.30% | 23 December 2006 |
| CVE-2006-6716 | SQL injection vulnerability in administration/administre2.php in Eric GUILLAUME uploader&downloader 3 allows remote attackers to execute arbitrary SQL commands via the id_user parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.08% | 23 December 2006 |
| CVE-2006-6715 | PHP remote file inclusion vulnerability in footer.inc.php in PowerClan 1.14a and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the settings[footer] parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 3.00% | 23 December 2006 |
| CVE-2006-6711 | PHP remote file inclusion vulnerability in compteur/mapage.php in Newxooper 0.9.1 allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.43% | 23 December 2006 |
| CVE-2006-6710 | Multiple PHP remote file inclusion vulnerabilities in PgmReloaded 0.8.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) lang parameter to (a) index.php, the (2) CFG[libdir] and (3) CFG[localedir] parameters to (b)… | EXPLOIT ✓HIGH 7.5EPSS 2.42% | 23 December 2006 |
| CVE-2006-6709 | Multiple SQL injection vulnerabilities in MGinternet Property Site Manager allow remote attackers to execute arbitrary SQL commands via the (1) p parameter to (a) detail.asp; the (2) l, (3) typ, or (4) loc parameter to (b) listings.asp; or the (5)… | EXPLOIT ×3 ✓HIGH 7.5EPSS 1.09% | 23 December 2006 |
| CVE-2006-6708 | Cross-site scripting (XSS) vulnerability in listings.asp in MGinternet Property Site Manager allows remote attackers to inject arbitrary web script or HTML via the s parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.85% | 23 December 2006 |
| CVE-2006-6707 | Stack-based buffer overflow in the NeoTraceExplorer.NeoTraceLoader ActiveX control (NeoTraceExplorer.dll) in NeoTrace Express 3.25 and NeoTrace Pro (aka McAfee Visual Trace) 3.25 allows remote attackers to execute arbitrary code via a long argument… | EXPLOIT ×2 ✓HIGH 7.5EPSS 56.2% | 23 December 2006 |
| CVE-2006-6703 | Multiple cross-site scripting (XSS) vulnerabilities in Oracle Portal 9i and 10g allow remote attackers to inject arbitrary JavaScript via the tc parameter in webapp/jsp/container_tabs.jsp, and other unspecified vectors. | EXPLOIT ✓MEDIUM 6.8EPSS 3.44% | 23 December 2006 |
| CVE-2006-6697 | CRLF injection vulnerability in webapp/jsp/calendar.jsp in Oracle Portal 10g and earlier, including 9.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the enc parameter. | EXPLOIT ✓HIGH 7.5EPSS 13.1% | 22 December 2006 |
| CVE-2006-6696 | Double free vulnerability in Microsoft Windows 2000, XP, 2003, and Vista allows local users to gain privileges by calling the MessageBox function with a MB_SERVICE_NOTIFICATION message with crafted data, which sends a HardError message to Client/Server… | EXPLOIT ×2 ✓MEDIUM 6.9EPSS 3.41% | 22 December 2006 |
| CVE-2006-6694 | Directory traversal vulnerability in include/config.php in E-Uploader Pro 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.50% | 21 December 2006 |
| CVE-2006-6692 | Multiple format string vulnerabilities in zabbix before 20061006 allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in information that would be recorded in the system log… | EXPLOIT ✓HIGH 7.5EPSS 7.91% | 21 December 2006 |
| CVE-2006-6691 | Multiple PHP remote file inclusion vulnerabilities in Valdersoft Shopping Cart 3.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the commonIncludePath parameter to (1) admin/include/common.php, (2) include/common.php, or… | EXPLOIT ✓HIGH 7.5EPSS 2.87% | 21 December 2006 |
| CVE-2006-6690 | rtehtmlarea/pi1/class.tx_rtehtmlarea_pi1.php in Typo3 4.0.0 through 4.0.3, 3.7 and 3.8 with the rtehtmlarea extension, and 4.1 beta allows remote authenticated users to execute arbitrary commands via shell metacharacters in the userUid parameter to… | EXPLOIT ✓HIGH 7.5EPSS 6.33% | 21 December 2006 |
| CVE-2006-6686 | PHP remote file inclusion vulnerability in sender.php in Carsen Klock TextSend 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the ROOT_PATH parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.11% | 21 December 2006 |
| CVE-2006-6104 | The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attackers to (1) read source code by appending a space (%20) to a URI, and (2) read credentials via a request for… | EXPLOIT ✓MEDIUM 5.0EPSS 5.25% | 21 December 2006 |
| CVE-2006-6673 | WinFtp Server 2.0.2 allows remote attackers to cause a denial of service (crash) via long (1) PASV, (2) LIST, (3) USER, (4) PORT, and possibly other commands. | EXPLOIT ✓MEDIUM 5.0EPSS 3.01% | 21 December 2006 |
| CVE-2006-6671 | SQL injection vulnerability in down.asp in Burak Yylmaz Download Portal allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.07% | 21 December 2006 |
| CVE-2006-6666 | PHP remote file inclusion vulnerability in index.php in VerliAdmin 0.3 and earlier allows remote authenticated users to execute arbitrary PHP code via a URL in the q parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.59% | 20 December 2006 |
| CVE-2006-6665 | Buffer overflow in Astonsoft DeepBurner Pro and Free 1.8.0 and earlier allows user-assisted remote attackers to execute arbitrary code via a long file name tag in a dbr file. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 30.9% | 20 December 2006 |
| CVE-2006-6661 | Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overwrite arbitrary program variables and execute arbitrary PHP code via multiple vectors that use the extract function, as demonstrated by the (1) f,… | EXPLOIT ✓HIGH 7.5EPSS 6.65% | 20 December 2006 |
| CVE-2006-6660 | The nodeType function in KDE libkhtml 4.2.0 and earlier, as used by Konquerer, KMail, and other programs, allows remote attackers to cause a denial of service (crash) via malformed HTML tags, possibly involving a COL SPAN tag embedded in a RANGE tag. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 2.58% | 20 December 2006 |
| CVE-2006-6659 | The Microsoft Office Outlook Recipient ActiveX control (ole32.dll) in Windows XP SP2 allows remote attackers to cause a denial of service (Internet Explorer 7 hang) via crafted HTML. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 17.6% | 20 December 2006 |
| CVE-2006-6652 | Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current before 20050914, NetBSD 2.* and 3.* before 20061203, and Apple Mac OS X before 2007-004, as used by the FTP daemon and tnftpd, allows remote authenticated users to execute… | EXPLOIT ×2 ✓HIGH 9.0EPSS 20.0% | 20 December 2006 |
| CVE-2006-6651 | Race condition in W29N51.SYS in the Intel 2200BG wireless driver 9.0.3.9 allows remote attackers to cause memory corruption and execute arbitrary code via a series of crafted beacon frames. | EXPLOIT ✓MEDIUM 6.8EPSS 3.50% | 20 December 2006 |
| CVE-2006-6650 | PHP remote file inclusion vulnerability in charts_constants.php in the Charts (mx_charts) 1.0.0 and earlier module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.35% | 20 December 2006 |
| CVE-2006-6648 | PHP remote file inclusion vulnerability in main.inc.php in planetluc.com RateMe 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pathtoscript parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.76% | 20 December 2006 |
| CVE-2006-6645 | PHP remote file inclusion vulnerability in language/lang_english/lang_admin.php in the Web Links (mx_links) 2.05 and earlier module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the mx_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.43% | 20 December 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.