Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,881 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026
25,049 results · page 368 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-6208 | Multiple SQL injection vulnerabilities in Enthrallweb eClassifieds allow remote attackers to execute arbitrary SQL commands via the (1) AD_ID, (2) cat_id, (3) sub_id, and (4) ad_id parameters to (a) ad.asp, the (5) cid parameter to (b) dircat.asp, and… | EXPLOIT ×3 ✓HIGH 7.5EPSS 1.27% | 1 December 2006 |
| CVE-2006-6207 | SQL injection vulnerability in products.asp in Evolve shopping cart (aka Evolve Merchant) allows remote attackers to execute arbitrary SQL commands via the partno parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.24% | 1 December 2006 |
| CVE-2006-6205 | Multiple cross-site scripting (XSS) vulnerabilities in result.asp in Enthrallweb eHomes allow remote attackers to inject arbitrary web script or HTML via the (1) city or (2) State parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.17% | 1 December 2006 |
| CVE-2006-6204 | Multiple SQL injection vulnerabilities in Enthrallweb eHomes allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter to (a) dircat.asp; the (2) sid parameter to (b) dirSub.asp; the (3) TYPE_ID parameter to (c) types.asp; the… | EXPLOIT ×4 ✓HIGH 7.5EPSS 1.27% | 1 December 2006 |
| CVE-2006-6203 | Directory traversal vulnerability in startdown.php in the Flyspray ME 1.0.1 (com_flyspray) component for Mambo allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.33% | 1 December 2006 |
| CVE-2006-6202 | PHP remote file inclusion vulnerability in modules/NukeAI/util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Program E is an AIML chatterbot, allows remote attackers to execute arbitrary PHP code via a URL in the AIbasedir parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.66% | 1 December 2006 |
| CVE-2006-6199 | Stack-based buffer overflow in BlazeVideo BlazeDVD Standard and Professional 5.0, and possibly earlier, allows remote attackers to execute arbitrary code via a long filename in a PLF playlist. | EXPLOIT ×9 ✓HIGH 7.5EPSS 65.3% | 1 December 2006 |
| CVE-2006-6198 | Multiple cross-site scripting (XSS) vulnerabilities in cPanel WebHost Manager (WHM) 3.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) email parameter to (a) scripts2/dochangeemail, the (2) supporturl parameter to… | EXPLOIT ×7 ✓MEDIUM 6.0EPSS 1.77% | 1 December 2006 |
| CVE-2006-6197 | Multiple cross-site scripting (XSS) vulnerabilities in b2evolution 1.8.2 through 1.9 beta allow remote attackers to inject arbitrary web script or HTML via the (1) app_name parameter in (a) _404_not_found.page.php, (b) _410_stats_gone.page.php, and (c)… | EXPLOIT ×3 ✓MEDIUM 6.8EPSS 1.90% | 1 December 2006 |
| CVE-2006-6195 | Multiple SQL injection vulnerabilities in Fixit iDMS Pro Image Gallery allow remote attackers to execute arbitrary SQL commands via the (1) show_id or (2) parentid parameter to (a) filelist.asp, or the (3) fid parameter to (b) showfile.asp. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.08% | 1 December 2006 |
| CVE-2006-6193 | SQL injection vulnerability in edit.asp in BasicForum 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.24% | 1 December 2006 |
| CVE-2006-6191 | SQL injection vulnerability in admin/edit.asp in 8pixel.net simpleblog 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.24% | 1 December 2006 |
| CVE-2006-6189 | SQL injection vulnerability in displayCalendar.asp in ClickTech Click Blog allows remote attackers to execute arbitrary SQL commands via the date parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.08% | 1 December 2006 |
| CVE-2006-6185 | Directory traversal vulnerability in script.php in Wabbit PHP Gallery 0.9 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.46% | 1 December 2006 |
| CVE-2006-6184 | Multiple stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a long filename in a (1) GET or (2) PUT command. | EXPLOIT ×4 ✓HIGH 10.0EPSS 65.9% | 1 December 2006 |
| CVE-2006-6183 | Multiple stack-based buffer overflows in 3Com 3CTftpSvc 2.0.1, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a long mode field (aka transporting mode) in a (1) GET or (2) PUT command. | EXPLOIT ×5 ✓HIGH 10.0EPSS 70.3% | 1 December 2006 |
| CVE-2006-6181 | Multiple SQL injection vulnerabilities in default.asp in ClickTech ClickContact allow remote attackers to execute arbitrary SQL commands via the (1) AlphaSort, (2) In, and (3) orderby parameters. | EXPLOIT ✓HIGH 7.5EPSS 1.22% | 1 December 2006 |
| CVE-2006-6177 | SQL injection vulnerability in system/core/users/users.profile.inc.php in Neocrome Seditio 1.10 and earlier allows remote authenticated users to execute arbitrary SQL commands via a double-url-encoded id parameter to users.php that begins with a valid… | EXPLOIT ✓HIGH 7.5EPSS 1.64% | 30 November 2006 |
| CVE-2006-6173 | Buffer overflow in the shared_region_make_private_np function in vm/vm_unix.c in Mac OS X 10.4.6 and earlier allows local users to execute arbitrary code via (1) a small range count, which causes insufficient memory allocation, or (2) a large number of… | EXPLOIT ✓HIGH 7.2EPSS 1.29% | 30 November 2006 |
| CVE-2006-6160 | SQL injection vulnerability in details.asp in Doug Luxem Liberum Help Desk 0.97.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.08% | 28 November 2006 |
| CVE-2006-6158 | Multiple cross-site scripting (XSS) vulnerabilities in (a) PMOS Help Desk 2.4, formerly (b) InverseFlow Help Desk 2.31 and also sold as (c) Ace Helpdesk 2.31, allow remote attackers to inject arbitrary web script or HTML via the (1) id or email… | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 2.86% | 28 November 2006 |
| CVE-2006-6157 | SQL injection vulnerability in index.php in ContentNow 1.39 and earlier allows remote attackers to execute arbitrary SQL commands via the pageid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.96% | 28 November 2006 |
| CVE-2006-6154 | PHP remote file inclusion vulnerability in addcode.php in HIOX Star Rating System Script (HSRS) 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the hm parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.49% | 28 November 2006 |
| CVE-2006-6153 | Multiple cross-site scripting (XSS) vulnerabilities in vSpin.net Classified System 2004 allow remote attackers to inject arbitrary web script or HTML via (1) catname parameter to cat.asp or the (2) minprice parameter to search.asp. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 2.14% | 28 November 2006 |
| CVE-2006-6152 | Multiple SQL injection vulnerabilities in vSpin.net Classified System 2004 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to (a) cat.asp, or the (2) keyword, (3) order, (4) sort, (5) menuSelect, or (6) state parameter… | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.27% | 28 November 2006 |
| CVE-2006-6151 | PHP remote file inclusion vulnerability in centre.php in Messagerie Locale as of 20061127 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.47% | 28 November 2006 |
| CVE-2006-6150 | PHP remote file inclusion vulnerability in memory/OWLMemoryProperty.php in OWLLib 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the OWLLIB_ROOT parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.15% | 28 November 2006 |
| CVE-2006-6149 | SQL injection vulnerability in index.asp in JiRos FAQ Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the tID parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.23% | 28 November 2006 |
| CVE-2006-6147 | Multiple SQL injection vulnerabilities in JiRos Links Manager allow remote attackers to execute arbitrary SQL commands via the (1) LinkID parameter to openlink.asp or the (2) CategoryID parameter to viewlinks.asp. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.27% | 28 November 2006 |
| CVE-2006-6140 | PHP remote file inclusion vulnerability in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to execute arbitrary PHP code via a URL in the slnt parameter to (1) index.php and (2) print.php. | EXPLOIT ✓HIGH 7.5EPSS 2.13% | 28 November 2006 |
| CVE-2006-6138 | Directory traversal vulnerability in download.php in Sisfo Kampus 0.8 allows remote attackers to list arbitrary directories via an absolute pathname in the dir parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 2.78% | 28 November 2006 |
| CVE-2006-6137 | Multiple PHP remote file inclusion vulnerabilities in Sisfo Kampus 0.8 allow remote attackers to execute arbitrary PHP code via a URL in the (1) exec parameter to index.php or (2) print parameter to print.php, which is also accessible via the print… | EXPLOIT ✓HIGH 7.5EPSS 2.38% | 28 November 2006 |
| CVE-2006-6133 | Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and 2005 and 2005 SP1 (formerly Business Objects Crystal Reports XI Professional) allows user-assisted remote… | EXPLOIT ✓HIGH 7.6EPSS 52.0% | 28 November 2006 |
| CVE-2006-6131 | Untrusted search path vulnerability in (1) WSAdminServer and (2) WSWebServer in Kerio WebSTAR (4D WebSTAR Server Suite) 5.4.2 and earlier allows local users with webstar privileges to gain root privileges via a malicious libucache.dylib helper library… | EXPLOIT ✓MEDIUM 6.2EPSS 0.88% | 28 November 2006 |
| CVE-2006-6130 | Apple Mac OS X AppleTalk allows local users to cause a denial of service (kernel panic) by calling the AIOCREGLOCALZN ioctl command with a crafted data structure on an AppleTalk socket. | EXPLOIT ✓MEDIUM 4.9EPSS 1.09% | 28 November 2006 |
| CVE-2006-6129 | Integer overflow in the fatfile_getarch2 in Apple Mac OS X allows local users to cause a denial of service and possibly execute arbitrary code via a crafted Mach-O Universal program that triggers memory corruption. | EXPLOIT ✓MEDIUM 4.6EPSS 1.29% | 27 November 2006 |
| CVE-2006-6125 | Heap-based buffer overflow in the wireless driver (WG311ND5.SYS) 2.3.1.10 for NetGear WG311v1 wireless adapter allows remote attackers to execute arbitrary code via an 802.11 management frame with a long SSID. | EXPLOIT ✓HIGH 7.5EPSS 14.6% | 27 November 2006 |
| CVE-2006-6124 | Cross-site scripting (XSS) vulnerability in SeleniumServer Web Server 1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | EXPLOIT ✓MEDIUM 6.8EPSS 1.74% | 26 November 2006 |
| CVE-2006-6121 | Acer Notebook LunchApp.APlunch ActiveX control allows remote attackers to execute arbitrary commands by calling the Run method. | EXPLOIT ✓HIGH 9.3EPSS 12.2% | 26 November 2006 |
| CVE-2006-6118 | Cross-site scripting (XSS) vulnerability in thumbs.php in mmgallery 1.55 allows remote attackers to inject arbitrary web script or HTML via the page parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.87% | 26 November 2006 |
| CVE-2006-6117 | SQL injection vulnerability in index1.asp in fipsGallery 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the which parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.24% | 26 November 2006 |
| CVE-2006-6116 | SQL injection vulnerability in default2.asp in fipsForum 2.6 and earlier allows remote attackers to execute arbitrary SQL commands via the kat parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.24% | 26 November 2006 |
| CVE-2006-6115 | SQL injection vulnerability in index.asp in fipsCMS 4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the fid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.24% | 26 November 2006 |
| CVE-2006-6111 | Multiple SQL injection vulnerabilities in Alan Ward A-Cart Pro 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) productid parameter in product.asp or (2) search parameter in search.asp. | EXPLOIT ✓HIGH 7.5EPSS 2.01% | 26 November 2006 |
| CVE-2006-6109 | Multiple SQL injection vulnerabilities in CandyPress Store 3.5.2.14 allow remote attackers to execute arbitrary SQL commands via the (1) policy parameter in openPolicy.asp or the (2) brand parameter in prodList.asp. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.44% | 26 November 2006 |
| CVE-2006-6097 | GNU tar 1.16 and 1.15.1, and possibly other versions, allows user-assisted attackers to overwrite arbitrary files via a tar file that contains a GNUTYPE_NAMES record with a symbolic link, which is not properly handled by the extract_archive function in… | EXPLOIT ✓MEDIUM 4.0EPSS 11.0% | 24 November 2006 |
| CVE-2006-6096 | Cross-site scripting (XSS) vulnerability in activenews_search.asp in ActiveNews Manager allows remote attackers to inject arbitrary web script or HTML via the query parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.93% | 24 November 2006 |
| CVE-2006-6095 | Multiple SQL injection vulnerabilities in ActiveNews Manager allow remote attackers to execute arbitrary SQL commands via the (1) articleID parameter to activenews_view.asp or the (2) page parameter to default.asp. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.43% | 24 November 2006 |
| CVE-2006-6094 | Multiple SQL injection vulnerabilities in ActiveNews Manager allow remote attackers to execute arbitrary SQL commands via the (1) catID parameter to activeNews_categories.asp, the (2) articleID parameter to activeNews_comments.asp, or the (3) query… | EXPLOIT ×2 ✓HIGH 7.5EPSS 3.69% | 24 November 2006 |
| CVE-2006-6093 | Multiple PHP remote file inclusion vulnerabilities in adminprint.php in PicturesPro Photo Cart 3.9 allow remote attackers to execute arbitrary PHP code via a URL in the (1) admin_folder and (2) path parameters. | EXPLOIT ✓HIGH 7.5EPSS 2.70% | 24 November 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.