SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-29 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,881 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026

25,049 results · page 366 of 501

CVESummaryPriorityPublished
CVE-2006-6543Multiple SQL injection vulnerabilities in login.asp in AppIntellect SpotLight CRM 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) login (UserName) and possibly (2) password parameter.EXPLOIT ✓HIGH 7.5EPSS 1.12%14 December 2006
CVE-2006-6542SQL injection vulnerability in news.php in Fantastic News 2.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.12%14 December 2006
CVE-2006-6538D-LINK DWL-2000AP+ firmware 2.11 allows remote attackers to cause (1) a denial of service (device reset) via a flood of ARP replies on the wired or wireless (radio) link and (2) a denial of service (device crash) via a flood of ARP requests on the…EXPLOIT ✓HIGH 7.8EPSS 3.48%14 December 2006
CVE-2006-6536Cross-site scripting (XSS) vulnerability in hata.asp in Cilem Haber Free Edition allows remote attackers to inject arbitrary web script or HTML via the hata parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.66%14 December 2006
CVE-2006-6526PHP remote file inclusion vulnerability in index.php in Gizzar 03162002 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the basePath parameter.EXPLOIT ✓HIGH 7.5EPSS 2.87%14 December 2006
CVE-2006-6525SQL injection vulnerability in vdateUsr.asp in EzHRS HR Assist 1.05 and earlier allows remote attackers to execute arbitrary SQL commands via the password parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%14 December 2006
CVE-2006-6524SQL injection vulnerability in vdateUsr.asp in EzHRS HR Assist 1.05 and earlier allows remote attackers to execute arbitrary SQL commands via the Uname (UserName) parameter.EXPLOIT ✓HIGH 7.5EPSS 1.13%14 December 2006
CVE-2006-6523Cross-site scripting (XSS) vulnerability in mail/manage.html in BoxTrapper in cPanel 11 allows remote attackers to inject arbitrary web script or HTML via the account parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.08%14 December 2006
CVE-2006-6521SQL injection vulnerability in lire-avis.php in Messageriescripthp 2.0 allows remote attackers to execute arbitrary SQL commands via the aa parameter.EXPLOIT ✓HIGH 7.5EPSS 1.08%14 December 2006
CVE-2006-6520Multiple cross-site scripting (XSS) vulnerabilities in Messageriescripthp 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) pseudo parameter to (a) existepseudo.php, the (2) email parameter to (b) existeemail.php, or the (3)…EXPLOIT ×3 ✓MEDIUM 6.8EPSS 2.14%14 December 2006
CVE-2006-6519SQL injection vulnerability in lire-avis.php in ProNews 1.5 allows remote attackers to execute arbitrary SQL commands via the aa parameter.EXPLOIT ✓HIGH 7.5EPSS 1.07%14 December 2006
CVE-2006-6518Multiple cross-site scripting (XSS) vulnerabilities in ProNews 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) pseudo, (2) email, (3) date, (4) sujet, (5) message, (6) site, and (7) lien parameters to (a) admin/change.php,…EXPLOIT ×2 ✓MEDIUM 6.8EPSS 1.88%14 December 2006
CVE-2006-6517Multiple cross-site scripting (XSS) vulnerabilities in KDPics 1.16 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) categories parameter to (a) index.php3 or (b) galeries.inc.php3.EXPLOIT ×3 ✓MEDIUM 6.8EPSS 1.90%14 December 2006
CVE-2006-6516Multiple PHP remote file inclusion vulnerabilities in KDPics 1.16 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) page parameter to (a) index.php3, or the (2) lib_path parameter to (b) authenticate.inc.php3 or (c)…EXPLOIT ✓HIGH 7.5EPSS 3.18%14 December 2006
CVE-2006-6493Buffer overflow in the krbv4_ldap_auth function in servers/slapd/kerberos.c in OpenLDAP 2.4.3 and earlier, when OpenLDAP is compiled with the --enable-kbind (Kerberos KBIND) option, allows remote attackers to execute arbitrary code via an LDAP bind…EXPLOIT ✓MEDIUM 5.1EPSS 9.33%13 December 2006
CVE-2006-6423Stack-based buffer overflow in the IMAP service for MailEnable Professional and Enterprise Edition 2.0 through 2.35, Professional Edition 1.6 through 1.84, and Enterprise Edition 1.1 through 1.41 allows remote attackers to execute arbitrary code via a…EXPLOIT ×3 ✓HIGH 10.0EPSS 70.7%12 December 2006
CVE-2006-6479Multiple cross-site scripting (XSS) vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to inject arbitrary web script or HTML via the email parameter in (1) erreurinscription.php, (2) Templates/admin.dwt.php, (3) Templates/commun.dwt.php, (4)…EXPLOIT ×5 ✓MEDIUM 6.8EPSS 2.14%12 December 2006
CVE-2006-6478Multiple SQL injection vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in (a) email.php, the (2) no parameter in (b) voirannonce.php, the (3) idmembre parameter in (c)…EXPLOIT ×3 ✓HIGH 7.5EPSS 10.6%12 December 2006
CVE-2006-6462PHP remote file inclusion vulnerability in engine/oldnews.inc.php in CM68 News 12.02.06 allows remote attackers to execute arbitrary PHP code via a URL in the addpath parameter.EXPLOIT ✓HIGH 7.5EPSS 3.35%11 December 2006
CVE-2006-6453PHP remote file inclusion vulnerability in JOWAMP_ShowPage.php in J-OWAMP Web Interface 2.1 allows remote authenticated users to execute arbitrary PHP code via a URL in the link parameter.EXPLOIT ✓MEDIUM 6.5EPSS 5.97%10 December 2006
CVE-2006-6451Multiple cross-site scripting (XSS) vulnerabilities in SWsoft Plesk 8.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) get_password.php or (2) login_up.php3.EXPLOIT ×2 ✓MEDIUM 6.8EPSS 2.40%10 December 2006
CVE-2006-6447Multiple cross-site scripting (XSS) vulnerabilities in Vt-Forum Lite 1.3 and 1.5 allow remote attackers to inject arbitrary web script or HTML via (1) the StrMes parameter in vf_info.asp and possibly (2) a URL in the SRC attribute of an IFRAME element…EXPLOIT ×2 ✓MEDIUM 6.8EPSS 2.02%10 December 2006
CVE-2006-6446SQL injection vulnerability in index.php in iWare Professional 5.0.4, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the D parameter.EXPLOIT ✓MEDIUM 6.8EPSS 0.98%10 December 2006
CVE-2006-6445Directory traversal vulnerability in error.php in Envolution 1.1.0 and earlier allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 6.70%10 December 2006
CVE-2006-6383PHP 5.2.0 and 4.4 allows local users to bypass safe_mode and open_basedir restrictions via a malicious path and a null byte before a ";" in a session_save_path argument, followed by an allowed path, which causes a parsing inconsistency in which PHP…EXPLOIT ✓MEDIUM 4.6EPSS 1.14%10 December 2006
CVE-2006-6379Buffer overflow in the BrightStor Backup Discovery Service in multiple CA products, including ARCserve Backup r11.5 SP1 and earlier, ARCserve Backup 9.01 up to 11.1, Enterprise Backup 10.5, and CA Server Protection Suite r2, allows remote attackers to…EXPLOIT ✓HIGH 7.5EPSS 21.1%10 December 2006
CVE-2006-6426PHP remote file inclusion vulnerability in design/thinkedit/render.php in ThinkEdit 1.9.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the template_file parameter.EXPLOIT ✓MEDIUM 6.8EPSS 6.73%10 December 2006
CVE-2006-6421Cross-site scripting (XSS) vulnerability in the private message box implementation (privmsg.php) in phpBB 2.0.x allows remote authenticated users to inject arbitrary web script or HTML via the "Message body" field in a message to a non-existent user.EXPLOIT ✓MEDIUM 6.0EPSS 15.6%10 December 2006
CVE-2006-6417PHP remote file inclusion vulnerability in inc/CONTROL/import/import-mt.php in b2evolution 1.8.5 through 1.9 beta allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter.EXPLOIT ✓HIGH 7.5EPSS 3.36%10 December 2006
CVE-2006-6416Multiple PHP remote file inclusion vulnerabilities in PhpLeague - Univert PhpLeague 0.81 allow remote attackers to execute arbitrary PHP code via a URL in the cheminmini parameter to (1) consult/miniseul.php or (2) config.php.EXPLOIT ✓HIGH 7.5EPSS 2.47%10 December 2006
CVE-2006-6414Multiple SQL injection vulnerabilities in dettaglio.asp in dol storye allow remote attackers to execute arbitrary SQL commands via the (1) id_doc or (2) id_aut parameter.EXPLOIT ✓HIGH 7.5EPSS 1.15%10 December 2006
CVE-2006-6332Stack-based buffer overflow in net80211/ieee80211_wireless.c in MadWifi before 0.9.2.1 allows remote attackers to execute arbitrary code via unspecified vectors, related to the encode_ie and giwscan_cb functions.EXPLOIT ×3 ✓HIGH 7.5EPSS 20.3%10 December 2006
CVE-2006-6410Buffer overflow in an ActiveX control in VMWare 5.5.1 allows local users to execute arbitrary code via a long VmdbDb parameter to the Initialize function.EXPLOIT ✓MEDIUM 4.6EPSS 1.38%10 December 2006
CVE-2006-6396Stack-based buffer overflow in BlazeVideo HDTV Player 2.1, and possibly earlier, allows remote attackers to execute arbitrary code via a long filename in a PLF playlist, a different product than CVE-2006-6199.EXPLOIT ✓HIGH 7.5EPSS 4.92%8 December 2006
CVE-2006-6391Multiple directory traversal vulnerabilities in Open Solution Quick.Cart 2.0, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to include arbitrary files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 1.96%8 December 2006
CVE-2006-6390Multiple directory traversal vulnerabilities in Open Solution Quick.Cart 2.0, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 2.14%8 December 2006
CVE-2006-6389Multiple cross-site scripting (XSS) vulnerabilities in ac4p Mobile allow remote attackers to inject arbitrary web script or HTML via the (1) Taaa parameter to (a) up.php, or the (2) pollhtml and (3) Bloks parameters to (b) polls.php, different vectors…EXPLOIT ×2 ✓MEDIUM 6.8EPSS 1.90%8 December 2006
CVE-2006-6387Multiple SQL injection vulnerabilities in LINK Content Management Server (CMS) allow remote attackers to execute arbitrary SQL commands via the (1) IDMeniGlavni parameter to navigacija.php, and the (2) IDStranicaPodaci parameter to prikazInformacije.php.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.08%8 December 2006
CVE-2006-6334Heap-based buffer overflow in the SendChannelData function in wfica.ocx in Citrix Presentation Server Client before 9.230 for Windows allows remote malicious web sites to execute arbitrary code via a DataSize parameter that is less than the length of…EXPLOIT ✓MEDIUM 6.8EPSS 34.8%8 December 2006
CVE-2006-6381Directory traversal vulnerability in getfile.asp in Ultimate HelpDesk allows remote attackers to read arbitrary files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.73%7 December 2006
CVE-2006-6380Cross-site scripting (XSS) vulnerability in index.asp in Ultimate HelpDesk allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.85%7 December 2006
CVE-2006-6377Uploadscript 1.2 and earlier stores sensitive data under the web root with insufficient access control, which allows remote attackers to obtain the admin password hash via a direct request for /password.txt.EXPLOIT ✓HIGH 7.5EPSS 3.13%7 December 2006
CVE-2006-6376Multiple directory traversal vulnerabilities in fm.php in Simple File Manager (SFM) 0.24a allow remote attackers to use ".." sequences to (1) read arbitrary files via the filename parameter in a download action, (2) delete arbitrary files via the delete…EXPLOIT ✓HIGH 7.5EPSS 4.18%7 December 2006
CVE-2006-6369SQL injection vulnerability in lib/entry_reply_entry.php in Invision Community Blog Mod 1.2.4 allows remote attackers to execute arbitrary SQL commands via the eid parameter, when accessed through the "Preview message" functionality.EXPLOIT ✓HIGH 7.5EPSS 1.08%7 December 2006
CVE-2006-6368PHP remote file inclusion vulnerability in login.php.inc in awrate 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the toroot parameter to search.php.EXPLOIT ✓HIGH 7.5EPSS 3.47%7 December 2006
CVE-2006-6367Multiple SQL injection vulnerabilities in detail.asp in DUware DUdownload 1.1, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) iFile or (2) action parameter.EXPLOIT ✓HIGH 7.5EPSS 1.59%7 December 2006
CVE-2006-6366Cross-site scripting (XSS) vulnerability in includes/elements/spellcheck/spellwin.php in Cerberus Helpdesk 0.97.3, 2.0 through 2.7, 3.2.1, and 3.3 allows remote attackers to inject arbitrary web script or HTML via the js parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.80%7 December 2006
CVE-2006-6365SQL injection vulnerability in detail.asp in DUware DUpaypal 3.1, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the iType parameter.EXPLOIT ✓HIGH 7.5EPSS 1.44%7 December 2006
CVE-2006-6364Cross-site scripting (XSS) vulnerability in error.php in Inside Systems Mail (ISMail) 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.09%7 December 2006
CVE-2006-6363Cross-site scripting (XSS) vulnerability in admin.pl in BlueSocket Secure Controller (BSC) before 5.2, or without 5.1.1-BluePatch, allows remote attackers to inject arbitrary web script or HTML via the ad_name parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.40%7 December 2006

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.