Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,853 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 365 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-6644 | PHP remote file inclusion vulnerability in pages/meeting_constants.php in the Meeting (mx_meeting) 1.1.2 and earlier module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.35% | 20 December 2006 |
| CVE-2006-6643 | Fightersoft Multimedia Star FTP server 1.10 allows remote attackers to cause a denial of service (crash) via multiple RETR commands with long arguments. | EXPLOIT ✓MEDIUM 5.0EPSS 2.86% | 20 December 2006 |
| CVE-2006-6642 | SQL injection vulnerability in haber.asp in Contra Haber Sistemi 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.08% | 20 December 2006 |
| CVE-2006-6640 | Multiple cross-site scripting (XSS) vulnerabilities in Omniture SiteCatalyst allow remote attackers to inject arbitrary web script or HTML via the (1) ss parameter in (a) search.asp and the (2) company and (3) username fields on (b) the web login page. | EXPLOIT ✓MEDIUM 6.8EPSS 2.05% | 19 December 2006 |
| CVE-2006-6635 | PHP remote file inclusion vulnerability in includes/functions.php in JumbaCMS 0.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the jcms_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.43% | 18 December 2006 |
| CVE-2006-6634 | Multiple PHP remote file inclusion vulnerabilities in the ExtCalThai (com_extcalendar) 0.9.1 and earlier component for Mambo allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG_EXT[LANGUAGES_DIR] parameter to… | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.72% | 18 December 2006 |
| CVE-2006-6633 | PHP remote file inclusion vulnerability in include/yapbb_session.php in YapBB 1.2 Beta2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[include_Bit] parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.43% | 18 December 2006 |
| CVE-2006-6632 | PHP remote file inclusion vulnerability in genepi.php in Genepi 1.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the topdir parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.11% | 18 December 2006 |
| CVE-2006-6631 | PHP remote file inclusion vulnerability in lib/xml/oai/GetRecord.php in osprey 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lib_dir parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.11% | 18 December 2006 |
| CVE-2006-6628 | Integer overflow in OpenOffice.org (OOo) 2.1 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted DOC file, as demonstrated by the 12122006-djtest.doc file, a variant of CVE-2006-6561 in a separate codebase. | EXPLOIT ✓MEDIUM 4.3EPSS 3.64% | 18 December 2006 |
| CVE-2006-6625 | Cross-site scripting (XSS) vulnerability in mod/forum/discuss.php in Moodle 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the navtail parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.06% | 18 December 2006 |
| CVE-2006-6624 | The FTP Server in Sambar Server 6.4 allows remote authenticated users to cause a denial of service (application crash) via a long series of "./" sequences in the SIZE command. | EXPLOIT ✓MEDIUM 4.0EPSS 6.23% | 18 December 2006 |
| CVE-2006-6619 | AVG Anti-Virus plus Firewall 7.5.431 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle… | EXPLOIT ✓HIGH 7.2EPSS 0.99% | 18 December 2006 |
| CVE-2006-6615 | PHP remote file inclusion vulnerability in includes/act_constants.php in the Activity Games (mx_act) 0.92 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.59% | 18 December 2006 |
| CVE-2006-6613 | Directory traversal vulnerability in language.php in phpAlbum 0.4.1 Beta 6 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to include and execute arbitrary local files or obtain sensitive… | EXPLOIT ✓MEDIUM 6.8EPSS 2.19% | 18 December 2006 |
| CVE-2006-6612 | PHP remote file inclusion vulnerability in basic.inc.php in PhpMyCms 0.3 allows remote attackers to execute arbitrary PHP code via a URL in the basepath_start parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.68% | 18 December 2006 |
| CVE-2006-6611 | PHP remote file inclusion vulnerability in interface.php in Barman 0.0.1r3 allows remote attackers to execute arbitrary PHP code via a URL in the basepath parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.68% | 18 December 2006 |
| CVE-2006-6604 | Directory traversal vulnerability in downloaddetails.php in TorrentFlux 2.2 allows remote authenticated users to read arbitrary files via .. | EXPLOIT ✓MEDIUM 6.5EPSS 2.83% | 15 December 2006 |
| CVE-2006-6602 | explorer.exe in Windows Explorer 6.00.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service via a crafted WMV file. | EXPLOIT ✓MEDIUM 4.3EPSS 15.0% | 15 December 2006 |
| CVE-2006-6601 | Windows Media Player 10.00.00.4036 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service via a .MID (MIDI) file with a malformed header chunk without any track chunks, possibly involving (1) number of tracks of… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 18.1% | 15 December 2006 |
| CVE-2006-6599 | maketorrent.php in TorrentFlux 2.2 allows remote authenticated users to execute arbitrary commands via shell metacharacters (";" semicolon) in the announce parameter. | EXPLOIT ✓MEDIUM 6.0EPSS 2.78% | 15 December 2006 |
| CVE-2006-6598 | Directory traversal vulnerability in viewnfo.php in (1) TorrentFlux before 2.2 and (2) torrentflux-b4rt before 2.1-b4rt-972 allows remote authenticated users to read arbitrary files via .. | EXPLOIT ✓MEDIUM 6.5EPSS 2.65% | 15 December 2006 |
| CVE-2006-6597 | Argument injection vulnerability in HyperAccess 8.4 allows user-assisted remote attackers to execute arbitrary vbscript and commands via the /r option in a telnet:// URI, which is configured to use hawin32.exe. | EXPLOIT ✓MEDIUM 6.8EPSS 2.63% | 15 December 2006 |
| CVE-2006-6593 | PHP remote file inclusion vulnerability in zufallscodepart.php in AMAZONIA MOD for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.43% | 15 December 2006 |
| CVE-2006-6592 | Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code via a URL in the page[path] parameter to (1) index.php, (2) admin.php, (3) rss.php, (4) rdf.php, (5) rss2.php, or (6) files/mainfile.php. | EXPLOIT ×6 ✓HIGH 7.5EPSS 2.67% | 15 December 2006 |
| CVE-2006-6590 | PHP remote file inclusion vulnerability in usercp_menu.php in AR Memberscript allows remote attackers to execute arbitrary PHP code via a URL in the script_folder parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.22% | 15 December 2006 |
| CVE-2006-6586 | Multiple PHP remote file inclusion vulnerabilities in Vortex Blog (vBlog, aka C12) a0.1_nonfunc allow remote attackers to execute arbitrary PHP code via a URL in the cfgProgDir parameter in (1) secure.php or (2) checklogin.php in admin/auth/. | EXPLOIT ✓HIGH 7.5EPSS 2.43% | 15 December 2006 |
| CVE-2006-6581 | PHP remote file inclusion vulnerability in tests/debug_test.php in Vernet Loic PHP_Debug 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the debugClassLocation parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.57% | 15 December 2006 |
| CVE-2006-6577 | SQL injection vulnerability in polls.php in Neocrome Land Down Under (LDU) 8.x and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 1.03% | 15 December 2006 |
| CVE-2006-6576 | Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long PASS command. | EXPLOIT ×3 ✓HIGH 7.5EPSS 67.2% | 15 December 2006 |
| CVE-2006-6575 | PHP remote file inclusion vulnerability in ldap.php in Brian Drawert Yet Another PHP LDAP Admin Project (yaplap) 0.6 and 0.6.1 allows remote attackers to execute arbitrary PHP code via a URL in the LOGIN_style parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.22% | 15 December 2006 |
| CVE-2006-6571 | Multiple cross-site scripting (XSS) vulnerabilities in form.php in GenesisTrader 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) cuve, (2) chem, (3) do, and possibly other parameters. | EXPLOIT ✓MEDIUM 6.8EPSS 1.87% | 15 December 2006 |
| CVE-2006-6569 | form.php in GenesisTrader 1.0 allows remote attackers to read source code for arbitrary files and obtain sensitive information via the (1) do and (2) chem parameters with a "modfich" floap parameter. | EXPLOIT ✓HIGH 7.8EPSS 2.75% | 15 December 2006 |
| CVE-2006-6568 | Directory traversal vulnerability in includes/kb_constants.php in the Knowledge Base (mx_kb) 2.0.2 module for mxBB allows remote attackers to include arbitrary files via a .. | EXPLOIT ✓HIGH 10.0EPSS 4.04% | 15 December 2006 |
| CVE-2006-6567 | PHP remote file inclusion vulnerability in includes/kb_constants.php in the Knowledge Base (mx_kb) 2.0.2 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter. | EXPLOIT ✓HIGH 10.0EPSS 4.34% | 15 December 2006 |
| CVE-2006-6566 | PHP remote file inclusion vulnerability in includes/profilcp_constants.php in the Profile Control Panel (CPanel) module for mxBB 0.91c allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.30% | 15 December 2006 |
| CVE-2006-6565 | FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to the (1) LIST or (2) NLST commands, which results in a NULL pointer dereference, a different set of vectors than CVE-2006-6564. | EXPLOIT ✓MEDIUM 4.0EPSS 70.6% | 15 December 2006 |
| CVE-2006-6564 | FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a malformed argument to the STOR command, which results in a NULL pointer dereference. | EXPLOIT ×2 ✓MEDIUM 4.0EPSS 6.07% | 15 December 2006 |
| CVE-2006-6563 | Stack-based buffer overflow in the pr_ctrls_recv_request function in ctrls.c in the mod_ctrls module in ProFTPD before 1.3.1rc1 allows local users to execute arbitrary code via a large reqarglen length value. | EXPLOIT ×4 ✓MEDIUM 6.6EPSS 2.33% | 15 December 2006 |
| CVE-2006-6561 | Unspecified vulnerability in Microsoft Word 2000, 2002, and Word Viewer 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted DOC file that triggers memory corruption, as demonstrated via the 12122006-djtest.doc file, a… | EXPLOIT ✓HIGH 9.3EPSS 41.3% | 14 December 2006 |
| CVE-2006-6560 | PHP remote file inclusion vulnerability in includes/common.php in the mx_modsdb 1.0.0 module for MxBB (aka MX-System) Portal allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.59% | 14 December 2006 |
| CVE-2006-6559 | SQL injection vulnerability in ProductDetails.asp in Lotfian Request For Travel 1.0 allows remote attackers to execute arbitrary SQL commands via the PID parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.12% | 14 December 2006 |
| CVE-2006-6558 | Crob FTP Server 3.6.1 b.263 allows remote attackers to cause a denial of service via a long series of "?A" sequences in the (1) LIST and possibly (2) NLST command. | EXPLOIT ✓MEDIUM 5.0EPSS 6.44% | 14 December 2006 |
| CVE-2006-6553 | PHP remote file inclusion vulnerability in includes/newssuite_constants.php in the NewsSuite 1.03 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the mx_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.87% | 14 December 2006 |
| CVE-2006-6552 | PHP remote file inclusion vulnerability in admin/plugins/NP_UserSharing.php in BLOG:CMS 4.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DIR_ADMIN parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.38% | 14 December 2006 |
| CVE-2006-6551 | PHP remote file inclusion vulnerability in libs/tucows/api/cartridges/crt_TUCOWS_domains/lib/domainutils.inc.php in Tucows Client Code Suite (CCS) 1.2.1015 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _ENV[TCA_HOME]… | EXPLOIT ✓HIGH 7.5EPSS 2.22% | 14 December 2006 |
| CVE-2006-6550 | PHP remote file inclusion vulnerability in common.php in Phorum 3.2.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the db_file parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.22% | 14 December 2006 |
| CVE-2006-6546 | PHP remote file inclusion vulnerability in inc/shows.inc.php in cutenews aj-fork (CN:AJ) 167f and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.87% | 14 December 2006 |
| CVE-2006-6545 | PHP remote file inclusion vulnerability in includes/common.php in the ErrorDocs 1.0.0 and earlier module for mxBB (mx_errordocs) allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.59% | 14 December 2006 |
| CVE-2006-6544 | Cross-site scripting (XSS) vulnerability in CM68 News allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | EXPLOIT ✓MEDIUM 6.8EPSS 1.62% | 14 December 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.