Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,881 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026
25,049 results · page 369 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-6092 | Multiple SQL injection vulnerabilities in vehiclelistings.asp in 20/20 Auto Gallery allow remote attackers to execute arbitrary SQL commands via the (1) vehicleID, (2) categoryID_list, (3) sale_type, (4) stock_number, (5) manufacturer, (6) model, (7)… | EXPLOIT ✓HIGH 7.5EPSS 1.26% | 24 November 2006 |
| CVE-2006-6088 | Multiple cross-site scripting (XSS) vulnerabilities in BlueCollar i-Gallery 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) n or (2) d parameter in igallery.asp, or (3) an unspecified parameter related to search, possibly… | EXPLOIT ✓MEDIUM 4.3EPSS 1.89% | 24 November 2006 |
| CVE-2006-6087 | Cross-site scripting (XSS) vulnerability in weblog.php in my little weblog allows remote attackers to inject arbitrary web script or HTML via the action parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.84% | 24 November 2006 |
| CVE-2006-6086 | PHP remote file inclusion vulnerability in src/ark_inc.php in e-Ark 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_pear_path parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 2.98% | 24 November 2006 |
| CVE-2006-6084 | Directory traversal vulnerability in abitwhizzy.php in aBitWhizzy allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.92% | 24 November 2006 |
| CVE-2006-6083 | SQL injection vulnerability in search.asp in CreaScripts Creadirectory allows remote attackers to execute arbitrary SQL commands via the category parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.22% | 24 November 2006 |
| CVE-2006-6082 | Multiple cross-site scripting (XSS) vulnerabilities in CreaScripts Creadirectory allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to addlisting.asp or the (2) search parameter to search.asp. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.92% | 24 November 2006 |
| CVE-2006-6080 | Multiple SQL injection vulnerabilities in categories.asp in gNews Publisher allow remote attackers to execute arbitrary SQL commands via the (1) catID or (2) editorID parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.08% | 24 November 2006 |
| CVE-2006-6078 | PHP remote file inclusion vulnerability in common.inc.php in a-ConMan 3.2 beta allows remote attackers to execute arbitrary PHP code via a URL in the cm_basedir parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.28% | 24 November 2006 |
| CVE-2006-6076 | Buffer overflow in the Tape Engine (tapeeng.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 and earlier allows remote attackers to execute arbitrary code via certain RPC requests to TCP port 6502. | EXPLOIT ✓HIGH 10.0EPSS 70.9% | 24 November 2006 |
| CVE-2006-6070 | SQL injection vulnerability in module/account/register/register.asp in ASP Nuke 0.80 and earlier allows remote attackers to execute arbitrary SQL commands via the StateCode parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.08% | 22 November 2006 |
| CVE-2006-6067 | Multiple SQL injection vulnerabilities in 20/20 DataShed (aka Real Estate Listing System) allow remote attackers to execute arbitrary SQL commands via the (1) itemID parameter to (a) f-email.asp, or the (2) peopleID and (2) sort_order parameters to (b)… | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.09% | 22 November 2006 |
| CVE-2006-6066 | Multiple SQL injection vulnerabilities in Dragon Calendar / Events Listing 2.x allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to (a) admin_login.asp, the (3) ID parameter to (b)… | EXPLOIT ×3 ✓HIGH 7.5EPSS 2.03% | 22 November 2006 |
| CVE-2006-6065 | PHP remote file inclusion vulnerability in includes/mx_common.php in the CalSnails Module for MxBB Portal 1.06 allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 3.08% | 22 November 2006 |
| CVE-2006-6063 | Stack-based buffer overflow in Un4seen XMPlay 3.3.0.5 and earlier allows remote attackers to execute arbitrary code via a M3U file containing a long (1) FileName, and cause a crash via a long (2) DisplayName. | EXPLOIT ×3 ✓HIGH 7.5EPSS 59.0% | 22 November 2006 |
| CVE-2006-6062 | Unspecified vulnerability in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a malformed UDTO HFS+ disk image, such as with "bad sectors," which triggers memory corruption. | EXPLOIT ×2 ✓MEDIUM 5.1EPSS 5.58% | 22 November 2006 |
| CVE-2006-6059 | Buffer overflow in MA521nd5.SYS driver 5.148.724.2003 for NetGear MA521 PCMCIA adapter allows remote attackers to execute arbitrary code via (1) beacon or (2) probe 802.11 frame responses with an long supported rates information element. | EXPLOIT ✓HIGH 10.0EPSS 18.9% | 22 November 2006 |
| CVE-2006-6055 | Stack-based buffer overflow in A5AGU.SYS 1.0.1.41 for the D-Link DWL-G132 wireless adapter allows remote attackers to execute arbitrary code via a 802.11 beacon request with a long Rates information element (IE). | EXPLOIT ✓HIGH 10.0EPSS 5.86% | 22 November 2006 |
| CVE-2006-6051 | PHP remote file inclusion vulnerability in reporter.logic.php in the MosReporter (com_reporter) component for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.43% | 22 November 2006 |
| CVE-2006-6050 | Multiple SQL injection vulnerabilities in ClickTech Texas Rank'em allow remote attackers to execute arbitrary SQL commands via the (1) selPlayer parameter to player.asp or the (2) tournament_id parameter to tournaments.asp. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.09% | 22 November 2006 |
| CVE-2006-6047 | Directory traversal vulnerability in manager/index.php in Etomite 0.6.1.2 allows remote authenticated administrators to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 5.8EPSS 7.99% | 22 November 2006 |
| CVE-2006-6045 | Multiple PHP remote file inclusion vulnerabilities in Comdev One Admin Pro 4.1 allow remote attackers to execute arbitrary PHP code via a URL in the path[skin] parameter to (1) adminfoot.php, (2) adminhead.php, or (3) adminlogin.php. | EXPLOIT ✓MEDIUM 6.8EPSS 2.79% | 22 November 2006 |
| CVE-2006-6044 | PHP remote file inclusion vulnerability in gallery_top.inc.php in PHPQuickGallery 1.9 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the textFile parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.86% | 22 November 2006 |
| CVE-2006-6042 | PHP remote file inclusion vulnerability in core/editor.php in phpWebThings 1.5.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the editor_insert_bottom parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 5.87% | 22 November 2006 |
| CVE-2006-6041 | Multiple PHP remote file inclusion vulnerabilities in Laurent Van den Reysen WORK system e-commerce 3.0.2, and other versions before 3.0.4, allow remote attackers to execute arbitrary PHP code via a URL in the g_include parameter to (1) index.php, (2)… | EXPLOIT ✓HIGH 7.5EPSS 3.57% | 22 November 2006 |
| CVE-2006-6040 | Multiple cross-site scripting (XSS) vulnerabilities in admincp/index.php in Jelsoft vBulletin 3.6.x allow remote attackers to inject arbitrary web script or HTML via (1) the prefs parameter in a buildnavprefs action or (2) the navprefs parameter in a… | EXPLOIT ✓MEDIUM 6.8EPSS 2.24% | 22 November 2006 |
| CVE-2006-6039 | SQL injection vulnerability in matchdetail.php in Powie's PHP MatchMaker 4.05 and earlier allows remote attackers to execute arbitrary SQL commands via the edit parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.31% | 22 November 2006 |
| CVE-2006-6038 | SQL injection vulnerability in editpoll.php in Powie's PHP Forum (pForum) 1.29a and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.21% | 22 November 2006 |
| CVE-2006-6035 | Cross-site scripting (XSS) vulnerability in list.php in BLOG:CMS 4.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the FADDR parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.74% | 22 November 2006 |
| CVE-2006-6029 | SQL injection vulnerability in vir_Login.asp in Property Pro 1.0 allows remote attackers to execute arbitrary SQL commands via the UserName field. | EXPLOIT ✓HIGH 7.5EPSS 1.22% | 21 November 2006 |
| CVE-2006-6028 | Directory traversal vulnerability in textview.php in Anton Vlasov DoSePa 1.0.4 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.34% | 21 November 2006 |
| CVE-2006-6027 | Adobe Reader (Adobe Acrobat Reader) 7.0 through 7.0.8 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument string to the LoadFile method in an AcroPDF ActiveX control. | EXPLOIT ✓HIGH 9.3EPSS 43.2% | 21 November 2006 |
| CVE-2006-6026 | Heap-based buffer overflow in Real Networks Helix Server and Helix Mobile Server before 11.1.3, and Helix DNA Server 11.0 and 11.1, allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a DESCRIBE request… | EXPLOIT ✓HIGH 10.0EPSS 10.7% | 21 November 2006 |
| CVE-2006-6022 | Cross-site scripting (XSS) vulnerability in login_form.asp in BestWebApp Dating Site allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.87% | 21 November 2006 |
| CVE-2006-6021 | SQL injection vulnerability in the login component in BestWebApp Dating Site allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters. | EXPLOIT ✓HIGH 7.5EPSS 1.22% | 21 November 2006 |
| CVE-2006-6020 | Cross-site scripting (XSS) vulnerability in announce.php in Blog Torrent Preview 0.92 allows remote attackers to inject arbitrary web script or HTML via the left parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.76% | 21 November 2006 |
| CVE-2006-6015 | Buffer overflow in the JavaScript implementation in Safari on Apple Mac OS X 10.4 allows remote attackers to cause a denial of service (application crash) via a long argument to the exec method of a regular expression. | EXPLOIT ✓MEDIUM 5.0EPSS 4.21% | 21 November 2006 |
| CVE-2006-3890 | Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in certain other applications, allows remote attackers to execute arbitrary code via a long FilePattern attribute in a WZFILEVIEW… | EXPLOIT ✓HIGH 9.3EPSS 14.6% | 21 November 2006 |
| CVE-2006-5987 | SQL injection vulnerability in default.asp in ASPintranet, possibly 1.2, allows remote attackers to execute arbitrary SQL commands via the a parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.07% | 20 November 2006 |
| CVE-2006-5983 | Multiple cross-site scripting (XSS) vulnerabilities in JBMC Software DirectAdmin 1.28.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) user parameter to (a) CMD_SHOW_RESELLER or (b) CMD_SHOW_USER in the Admin level;… | EXPLOIT ×8 ✓MEDIUM 6.0EPSS 1.77% | 20 November 2006 |
| CVE-2006-5976 | Multiple SQL injection vulnerabilities in admin_login.asp in BlogMe 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) Username or (2) Password field. | EXPLOIT ✓HIGH 7.5EPSS 1.22% | 20 November 2006 |
| CVE-2006-5975 | Multiple cross-site scripting (XSS) vulnerabilities in comments.asp in BlogMe 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) URL, or (3) Comments field. | EXPLOIT ✓MEDIUM 6.8EPSS 2.09% | 20 November 2006 |
| CVE-2006-5972 | Stack-based buffer overflow in WG111v2.SYS in NetGear WG111v2 wireless adapter (USB) allows remote attackers to execute arbitrary code via a long 802.11 beacon request. | EXPLOIT ✓HIGH 10.0EPSS 19.8% | 18 November 2006 |
| CVE-2006-5962 | Multiple SQL injection vulnerabilities in Hpecs Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields in the (a) login screen, and (3) searchstring parameter in (b) insearch_list.asp. | EXPLOIT ✓HIGH 7.5EPSS 1.31% | 17 November 2006 |
| CVE-2006-5961 | Buffer overflow in Mercury Mail Transport System 4.01b for Windows has unknown impact and attack vectors, as originally reported in a GLEG VulnDisco pack. | EXPLOIT ✓HIGH 7.5EPSS 2.19% | 17 November 2006 |
| CVE-2006-5958 | Multiple cross-site scripting (XSS) vulnerabilities in INFINICART allow remote attackers to inject arbitrary web script or HTML via the (1) username and (2) password fields in (a) login.asp, (3) search field in (b) search.asp, and (4) email field in (c)… | EXPLOIT ×3 ✓MEDIUM 6.8EPSS 2.14% | 17 November 2006 |
| CVE-2006-5957 | Multiple SQL injection vulnerabilities in INFINICART allow remote attackers to execute arbitrary SQL commands via the (1) groupid parameter in (a) browse_group.asp, (2) productid parameter in (b) added_to_cart.asp, and (3) catid and (4) subid parameter… | EXPLOIT ×3 ✓HIGH 7.5EPSS 1.19% | 17 November 2006 |
| CVE-2006-5954 | SQL injection vulnerability in page.asp in NetVIOS 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the NewsID parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.28% | 17 November 2006 |
| CVE-2006-5952 | SQL injection vulnerability in admin/default.asp in ASP Smiley 1.0 allows remote attackers to execute arbitrary SQL commands via the Username field. | EXPLOIT ✓HIGH 7.5EPSS 1.13% | 17 November 2006 |
| CVE-2006-5951 | PHP remote file inclusion vulnerability in pipe.php in Exophpdesk 1.2 allows remote attackers to execute arbitrary PHP code via a URL in the lang_file parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.25% | 17 November 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.