Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,881 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026
25,049 results · page 367 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-6360 | PHP remote file inclusion vulnerability in activate.php in PHP Upload Center 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the footerpage parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.83% | 7 December 2006 |
| CVE-2006-6356 | Multiple cross-site scripting (XSS) vulnerabilities in templates/link_temp.php in PHPNews 1.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) url, (2) id, (3) subject, (4) username, or (5) time parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.98% | 7 December 2006 |
| CVE-2006-6355 | SQL injection vulnerability in default.asp in DuWare DuClassmate allows remote attackers to execute arbitrary SQL commands via the iCity parameter. | EXPLOIT ✓HIGH 10.0EPSS 1.82% | 7 December 2006 |
| CVE-2006-6352 | FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to cause a denial of service (infinite loop) via a crafted ACE file. | EXPLOIT ✓MEDIUM 5.0EPSS 9.43% | 7 December 2006 |
| CVE-2006-6349 | Multiple SQL injection vulnerabilities in PWP Technologies The Classified Ad System allow remote attackers to execute arbitrary SQL commands via (1) the main parameter in a view action (includes/mainpage/view.asp) in default.asp or (2) a query in the… | EXPLOIT ✓HIGH 7.5EPSS 2.07% | 7 December 2006 |
| CVE-2006-6343 | SQL injection vulnerability in polls.php in Neocrome Seditio 1.10 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.16% | 7 December 2006 |
| CVE-2006-6342 | Multiple SQL injection vulnerabilities in KLF-DESIGN (aka Kim L. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.08% | 7 December 2006 |
| CVE-2006-6341 | Multiple PHP remote file inclusion vulnerabilities in mg.applanix 1.3.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the apx_root_path parameter to (1) act/act_check_access.php, (2) dsp/dsp_form_booking_ctl.php, and (3)… | EXPLOIT ✓HIGH 7.5EPSS 3.55% | 7 December 2006 |
| CVE-2006-6340 | keystone.exe in nVIDIA nView allows attackers to cause a denial of service via a long command line argument. | EXPLOIT ✓MEDIUM 5.0EPSS 2.70% | 7 December 2006 |
| CVE-2006-6339 | SQL injection vulnerability in sites/index.php in deV!L`z Clanportal (DZCP) before 1.3.6.1 allows remote attackers to execute arbitrary SQL commands via the show element in a GET request. | EXPLOIT ✓MEDIUM 6.8EPSS 1.21% | 7 December 2006 |
| CVE-2006-6338 | Unrestricted file upload vulnerability in upload/index.php in deV!L`z Clanportal (DZCP) before 1.3.6.1 allows remote attackers to upload and execute arbitrary .php files by embedding PHP code in a JPEG or GIF file that is uploaded to… | EXPLOIT ✓MEDIUM 5.0EPSS 2.68% | 7 December 2006 |
| CVE-2006-6337 | Multiple SQL injection vulnerabilities in giris.asp in Aspee and Dogantepe Ziyaretci Defteri allow remote attackers to execute arbitrary SQL commands via the (1) kullanici or (2) parola parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.23% | 7 December 2006 |
| CVE-2006-6330 | index.php for TorrentFlux 2.2 allows remote registered users to execute arbitrary commands via shell metacharacters in the kill parameter. | EXPLOIT ✓MEDIUM 6.0EPSS 3.02% | 6 December 2006 |
| CVE-2006-6329 | index.php for TorrentFlux 2.2 allows remote attackers to delete files by specifying the target filename in the delfile parameter. | EXPLOIT ✓MEDIUM 4.9EPSS 2.59% | 6 December 2006 |
| CVE-2006-6328 | Directory traversal vulnerability in index.php for TorrentFlux 2.2 allows remote attackers to create or overwrite arbitrary files via sequences in the alias_file parameter. | EXPLOIT ✓MEDIUM 4.9EPSS 2.59% | 6 December 2006 |
| CVE-2006-6311 | Microsoft Internet Explorer 6.0.2900.2180 allows remote attackers to cause a denial of service via a style attribute in an HTML table tag with a width value that is dynamically calculated using JavaScript. | EXPLOIT ✓MEDIUM 5.0EPSS 26.5% | 6 December 2006 |
| CVE-2006-6310 | Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (crash) via an invalid src attribute value ("?") in an HTML frame tag that is in a frameset tag with a large rows attribute. | EXPLOIT ✓MEDIUM 5.0EPSS 15.8% | 6 December 2006 |
| CVE-2006-6300 | Cross-site scripting (XSS) vulnerability in CuteNews 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the result parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.64% | 5 December 2006 |
| CVE-2006-6298 | SQL injection vulnerability in uye_giris_islem.asp in Metyus Okul Yonetim Sistemi 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) kullanici_ismi and (2) sifre parameters. | EXPLOIT ✓HIGH 7.5EPSS 1.08% | 5 December 2006 |
| CVE-2006-6296 | The RpcGetPrinterData function in the Print Spooler (spoolsv.exe) service in Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via an RPC request… | EXPLOIT ✓MEDIUM 6.1EPSS 22.0% | 5 December 2006 |
| CVE-2006-6295 | PHP remote file inclusion vulnerability in includes/mx_common.php in the mx_tinies 1.3.0 Module for MxBB Portal 1.06 allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 6.42% | 5 December 2006 |
| CVE-2006-6293 | Heap-based buffer overflow in FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to execute arbitrary code via a crafted CHM file. | EXPLOIT ✓HIGH 7.5EPSS 16.4% | 5 December 2006 |
| CVE-2006-6289 | Woltlab Burning Board (wBB) Lite 1.0.2 does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL commands via… | EXPLOIT ✓MEDIUM 6.8EPSS 2.09% | 5 December 2006 |
| CVE-2006-6288 | Multiple buffer overflows in Niek Albers CoolPlayer 216 and earlier allow remote attackers to execute arbitrary code via (1) a playlist file with long song names, because of an overflow in the CPL_AddPrefixedFile function in CPI_Playlist.c; (2) a skin… | EXPLOIT ✓MEDIUM 4.6EPSS 6.77% | 4 December 2006 |
| CVE-2006-6287 | Stack-based buffer overflow in AtomixMP3 2.3 and earlier allows remote attackers to execute arbitrary code via a long pathname in an M3U file. | EXPLOIT ✓HIGH 7.5EPSS 10.2% | 4 December 2006 |
| CVE-2006-6284 | Directory traversal vulnerability in admin.php in Vikingboard 0.1.2 allows remote authenticated administrators to include arbitrary files via a .. | EXPLOIT ✓HIGH 9.0EPSS 3.78% | 4 December 2006 |
| CVE-2006-6281 | PHP remote file inclusion vulnerability in check_status.php in dicshunary 0.1 alpha allows remote attackers to execute arbitrary PHP code via a URL in the dicshunary_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.43% | 4 December 2006 |
| CVE-2006-6280 | SQL injection vulnerability in viewthread.php in Oxygen (O2PHP Bulletin Board) 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter, a different vector than CVE-2006-1572. | EXPLOIT ✓HIGH 7.5EPSS 1.08% | 4 December 2006 |
| CVE-2006-6277 | Directory traversal vulnerability in admin/FileServer.php in ContentServ 4.x allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.44% | 4 December 2006 |
| CVE-2006-6272 | Cross-site scripting (XSS) vulnerability in sp_index.php in Simple PHP Gallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the dir parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.76% | 4 December 2006 |
| CVE-2006-6261 | Buffer overflow in Quintessential Player 4.50.1.82 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) M3u or (2) M3u-8 file; or a (3) crafted PLS file with a long value in the… | EXPLOIT ✓HIGH 9.3EPSS 5.81% | 4 December 2006 |
| CVE-2006-6255 | Direct static code injection vulnerability in util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Program E is an AIML chatterbot, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension in the… | EXPLOIT ✓HIGH 7.5EPSS 2.44% | 4 December 2006 |
| CVE-2006-6254 | administration/telecharger.php in Cahier de texte 2.0 allows remote attackers to obtain unparsed content (source code) of files via the chemin parameter, as demonstrated using directory traversal sequences to obtain the MySQL username and password from… | EXPLOIT ✓MEDIUM 4.3EPSS 2.91% | 4 December 2006 |
| CVE-2006-6251 | Stack-based buffer overflow in VUPlayer 2.44 and earlier allows remote attackers to execute arbitrary code via a long string in an M3U file, aka an "M3U UNC Name" attack. | EXPLOIT ×3 ✓HIGH 7.5EPSS 67.5% | 4 December 2006 |
| CVE-2006-6250 | Format string vulnerability in Songbird Media Player 0.2 and earlier allows remote attackers to cause a denial of service (crash) via an M3U Playlist file containing extended ASCII, which causes the Unicode converter to be invoked. | EXPLOIT ✓HIGH 7.8EPSS 3.28% | 4 December 2006 |
| CVE-2006-6247 | Multiple SQL injection vulnerabilities in Uapplication UPhotoGallery 1.1 allow remote attackers to execute arbitrary SQL commands via the ci parameter to (1) slideshow.asp or (2) thumbnails.asp. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.23% | 4 December 2006 |
| CVE-2006-6243 | Multiple SQL injection vulnerabilities in index.asp in FipsSHOP allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) did parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.22% | 4 December 2006 |
| CVE-2006-6242 | Multiple directory traversal vulnerabilities in Serendipity 1.0.3 and earlier allow remote attackers to read or include arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 4.55% | 3 December 2006 |
| CVE-2006-6237 | SQL injection vulnerability in the decode_cookie function in thread.php in Woltlab Burning Board Lite 1.0.2 allows remote attackers to execute arbitrary SQL commands via the threadvisit Cookie parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.59% | 3 December 2006 |
| CVE-2006-5854 | Multiple buffer overflows in the Spooler service (nwspool.dll) in Novell Netware Client 4.91 through 4.91 SP2 allow remote attackers to execute arbitrary code via a long argument to the (1) EnumPrinters and (2) OpenPrinter functions. | EXPLOIT ×2 ✓HIGH 7.5EPSS 57.5% | 3 December 2006 |
| CVE-2006-6232 | PHP remote file inclusion vulnerability in admin/index.php in DreamAccount 3.1 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.25% | 2 December 2006 |
| CVE-2006-6225 | Multiple PHP remote file inclusion vulnerabilities in GeekLog 1.4 allow remote attackers to execute arbitrary code via a URL in the _CONF[path] parameter to (1) links/functions.inc, (2) polls/functions.inc, (3) spamx/BlackList.Examine.class.php, (4)… | EXPLOIT ✓MEDIUM 5.1EPSS 4.37% | 2 December 2006 |
| CVE-2006-6220 | Multiple SQL injection vulnerabilities in Recipes Website (Recipes Complete Website) 1.1.14 allow remote attackers to execute arbitrary SQL commands via the (1) recipeid parameter to recipe.php or the (2) categoryid parameter to list.php. | EXPLOIT ✓MEDIUM 6.8EPSS 1.02% | 1 December 2006 |
| CVE-2006-6216 | SQL injection vulnerability in admin_hacks_list.php in the Nivisec Hacks List 1.21 and earlier phpBB module allows remote attackers to execute arbitrary SQL commands via the hack_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.08% | 1 December 2006 |
| CVE-2006-6214 | SQL injection vulnerability in wallpaper.php in Wallpaper Website (Wallpaper Complete Website) 1.0.09 allows remote attackers to execute arbitrary SQL commands via the wallpaperid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.24% | 1 December 2006 |
| CVE-2006-6213 | index.php in PEGames uses the extract function to overwrite critical variables, which allows remote attackers to conduct PHP remote file inclusion attacks via the abs_url parameter, which is later extracted to overwrite a previously uncontrolled value. | EXPLOIT ✓HIGH 7.5EPSS 2.66% | 1 December 2006 |
| CVE-2006-6212 | PHP remote file inclusion vulnerability in centre.php in Site News (site_news) 2.00, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.44% | 1 December 2006 |
| CVE-2006-6211 | Multiple cross-site scripting (XSS) vulnerabilities in BirdBlog 1.4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter to (a) admin/admincore.php, the (2) month parameter to (b) admin/comments.php or (c)… | EXPLOIT ×4 ✓MEDIUM 6.8EPSS 1.90% | 1 December 2006 |
| CVE-2006-6210 | SQL injection vulnerability in listpics.asp in ASP ListPics 5.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.24% | 1 December 2006 |
| CVE-2006-6209 | Multiple SQL injection vulnerabilities in MidiCart ASP Shopping Cart and ASP Plus Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) id2006quant parameter to (a) item_show.asp, or the (2) maingroup or (3) secondgroup… | EXPLOIT ✓HIGH 7.5EPSS 1.39% | 1 December 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.