SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-29 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,881 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026

25,049 results · page 370 of 501

CVESummaryPriorityPublished
CVE-2006-5948PHP remote file inclusion vulnerability in pntUnit/Inspect.php in phpPeanuts 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the Include parameter.EXPLOIT ✓HIGH 7.5EPSS 3.18%17 November 2006
CVE-2006-5946SQL injection vulnerability in demo/glossary/glossary.asp in FunkyASP Glossary 1.0 allows remote attackers to execute arbitrary SQL commands via the alpha parameter.EXPLOIT ✓HIGH 7.5EPSS 1.26%17 November 2006
CVE-2006-5945Multiple SQL injection vulnerabilities in MGinternet Car Site Manager (CSM) allow remote attackers to execute arbitrary SQL commands via the (1) p parameter to (a) csm/asp/detail.asp, or the (2) l, (3) typ, or (4) loc parameter to (b)…EXPLOIT ×2 ✓HIGH 7.5EPSS 1.27%17 November 2006
CVE-2006-5944Cross-site scripting (XSS) vulnerability in csm/asp/listings.asp in MGinternet Car Site Manager (CSM) allows remote attackers to inject arbitrary web script or HTML via the s parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.17%17 November 2006
CVE-2006-5943Multiple SQL injection vulnerabilities in inventory/display/imager.asp in Website Designs for Less Inventory Manager allow remote attackers to execute arbitrary SQL commands via the (1) pictable, (2) picfield, or (3) where parameter.EXPLOIT ✓HIGH 7.5EPSS 1.08%17 November 2006
CVE-2006-5936SQL injection vulnerability in dept.asp in SiteXpress E-Commerce System allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.22%16 November 2006
CVE-2006-5934SQL injection vulnerability in admin/default.asp in Estate Agent Manager 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the UserName field.EXPLOIT ✓HIGH 7.5EPSS 1.31%16 November 2006
CVE-2006-5930Multiple PHP remote file inclusion vulnerabilities in Aigaion Web based bibliography management system 1.2.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the DIR parameter to (1) _basicfunctions.php, or (2)…EXPLOIT ✓HIGH 7.5EPSS 3.53%16 November 2006
CVE-2006-5928Multiple PHP remote file inclusion vulnerabilities in Phpjobscheduler 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the installed_config_file parameter to (1) add-modify.php, (2) delete.php, (3) modify.php, and (4)…EXPLOIT ✓HIGH 7.5EPSS 4.30%16 November 2006
CVE-2006-5925Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharacters in an smb:// URI, as demonstrated by using PUT and GET statements.EXPLOIT ×2 ✓HIGH 7.5EPSS 8.26%15 November 2006
CVE-2006-5924Cross-site scripting (XSS) vulnerability in index.php in Efficient IP iPmanager (IPm) 2.3 allows remote attackers to inject arbitrary web script or HTML via the errmsg parameter.EXPLOIT ✓MEDIUM 5.8EPSS 1.52%15 November 2006
CVE-2006-5923PHP remote file inclusion vulnerability in index.php in Chris Mac gtcatalog (aka GimeScripts Shopping Catalog) 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the custom parameter.EXPLOIT ✓HIGH 7.5EPSS 2.43%15 November 2006
CVE-2006-5920PHP remote file inclusion vulnerability in common.php in Yuuki Yoshizawa Exporia 0.3.0 allows remote attackers to execute arbitrary PHP code via a URL in the lan parameter.EXPLOIT ✓HIGH 7.5EPSS 3.25%15 November 2006
CVE-2006-5919PHP remote file inclusion vulnerability in admin/e_data/visEdit_control.class.php in ActiveCampaign KnowledgeBuilder 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the visEdit_root parameter, a different vector than CVE-2003-1131.EXPLOIT ✓HIGH 7.5EPSS 3.16%15 November 2006
CVE-2006-5918Unrestricted file upload vulnerability in RapidKill (aka PHP Rapid Kill) 5.7 Pro, and certain other versions, allows remote attackers to upload and execute arbitrary PHP scripts via the "Link to Download" field.EXPLOIT ✓HIGH 7.5EPSS 2.48%15 November 2006
CVE-2006-5915Multiple cross-site scripting (XSS) vulnerabilities in ls.php in SAMEDIA LandShop allow remote attackers to inject arbitrary web script or HTML via the (1) start, (2) CAT_ID, (3) keyword, (4) search_area, (5) search_type, (6) infield, or (7)…EXPLOIT ✓MEDIUM 6.8EPSS 2.10%15 November 2006
CVE-2006-5914SQL injection vulnerability in ls.php in SAMEDIA LandShop allows remote attackers to execute arbitrary SQL commands via the infield parameter.EXPLOIT ✓HIGH 7.5EPSS 1.22%15 November 2006
CVE-2006-5911Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute arbitrary PHP code via a URL in the g_documentRoot parameter to (1) Alias.php, (2) Article.php, (3) ArticleAttachment.php, (4)…EXPLOIT ×38 ✓HIGH 7.5EPSS 4.56%15 November 2006
CVE-2006-5910Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 20061110 allow remote attackers to execute arbitrary PHP code via a URL in the g_documentRoot parameter to (1) bugreporter/thankyou.php and (2) feedback/thankyou.php in…EXPLOIT ✓HIGH 7.5EPSS 2.56%15 November 2006
CVE-2006-5899PHP remote file inclusion vulnerability in install.php3 in @cid stats 2.3 allows remote attackers to execute arbitrary PHP code via a URL in the repertoire parameter.EXPLOIT ✓HIGH 7.5EPSS 2.13%15 November 2006
CVE-2006-5895PHP remote file inclusion vulnerability in core/core.php in EncapsCMS 0.3.6 allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.EXPLOIT ✓HIGH 7.5EPSS 3.95%14 November 2006
CVE-2006-5894Directory traversal vulnerability in lang.php in Rama CMS 0.68 and earlier, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 2.53%14 November 2006
CVE-2006-5893Multiple PHP remote file inclusion vulnerabilities in iWonder Designs Storystream 0.4.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter to (1) mysql.php and (2) mysqli.php in include/classes/pear/DB/.EXPLOIT ✓HIGH 7.5EPSS 3.49%14 November 2006
CVE-2006-5892SQL injection vulnerability in MoreInfo.asp in The Net Guys ASPired2Poll 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.22%14 November 2006
CVE-2006-5891SQL injection vulnerability in detail.asp in Superfreaker Studios UStore 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.31%14 November 2006
CVE-2006-5890SQL injection vulnerability in detail.asp in Superfreaker Studios USupport 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.13%14 November 2006
CVE-2006-5889SQL injection vulnerability in printLog.php in BrewBlogger (BB) 1.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.26%14 November 2006
CVE-2006-5888SQL injection vulnerability in viewarticle.asp in Superfreaker Studios UPublisher 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.13%14 November 2006
CVE-2006-5887SQL injection vulnerability in CampusNewsDetails.asp in Dynamic Dataworx NuSchool 1.0 allows remote attackers to execute arbitrary SQL commands via the NewsID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.79%14 November 2006
CVE-2006-5886SQL injection vulnerability in propertysdetails.asp in Dynamic Dataworx NuRealestate (NuRems) 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the PropID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.26%14 November 2006
CVE-2006-5885SQL injection vulnerability in Products.asp in NuStore 1.0 allows remote attackers to execute arbitrary SQL commands via the SubCatagoryID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.86%14 November 2006
CVE-2006-4688Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via crafted messages, aka "Client Service for NetWare Memory Corruption Vulnerability."EXPLOIT ×2 ✓HIGH 7.5EPSS 75.0%14 November 2006
CVE-2006-5198The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remote attackers to execute arbitrary code via unspecified "unsafe methods."EXPLOIT ✓MEDIUM 4.0EPSS 60.4%14 November 2006
CVE-2006-4691Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC messages with a long hostname.EXPLOIT ×4 ✓HIGH 10.0EPSS 78.9%14 November 2006
CVE-2006-5883Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote authenticated users to inject arbitrary web script or HTML via the (1) dir parameter in (a) seldir.html, and the (2) user and (3) dir parameters in (b) newuser.html.EXPLOIT ×2 ✓LOW 3.5EPSS 1.73%14 November 2006
CVE-2006-5882Stack-based buffer overflow in the Broadcom BCMWL5.SYS wireless device driver 3.50.21.10, as used in Cisco Linksys WPC300N Wireless-N Notebook Adapter before 4.100.15.5 and other products, allows remote attackers to execute arbitrary code via an 802.11…EXPLOIT ✓HIGH 8.3EPSS 13.1%14 November 2006
CVE-2006-5881SQL injection vulnerability in cl_CatListing.asp in Dynamic Dataworx NuCommunity 1.0 allows remote attackers to execute arbitrary SQL commands via the cl_cat_ID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.79%14 November 2006
CVE-2006-5880SQL injection vulnerability on the subMenu page in switch.asp in Munch Pro 1.0 allows remote attackers to execute arbitrary SQL commands via the catid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.13%14 November 2006
CVE-2006-5879SQL injection vulnerability in default1.asp in ASPPortal 4.0.0 beta and earlier allows remote attackers to execute arbitrary SQL commands via the Poll_ID parameter, a different vector than CVE-2006-1353.EXPLOIT ✓HIGH 7.5EPSS 1.22%14 November 2006
CVE-2006-5866Directory traversal vulnerability in Mdoc/view-sourcecode.php for phpManta 1.0.2 and earlier allows remote attackers to read and include arbitrary files via ".." sequences in the file parameter.EXPLOIT ✓MEDIUM 6.4EPSS 3.00%11 November 2006
CVE-2006-5865PHP remote file inclusion vulnerability in language.inc.php in MyAlbum 3.02 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the langs_dir parameter.EXPLOIT ✓HIGH 7.5EPSS 3.79%11 November 2006
CVE-2006-5864Stack-based buffer overflow in the ps_gettext function in ps.c for GNU gv 3.6.2, and possibly earlier versions, allows user-assisted attackers to execute arbitrary code via a PostScript (PS) file with certain headers that contain long comments, as…EXPLOIT ✓MEDIUM 5.1EPSS 15.2%11 November 2006
CVE-2006-5863PHP remote file inclusion vulnerability in inc/session.php for LetterIt 2 allows remote attackers to execute arbitrary PHP code via a URL in the lang parameter.EXPLOIT ✓HIGH 7.5EPSS 3.49%11 November 2006
CVE-2006-5853Cross-site scripting (XSS) vulnerability in logon.aspx in Immediacy CMS (Immediacy .NET CMS) 5.2 allows remote attackers to inject arbitrary web script or HTML via the lang parameter, which is returned to the client in a lang cookie.EXPLOIT ✓MEDIUM 6.8EPSS 2.04%10 November 2006
CVE-2006-5852Untrusted search path vulnerability in openexec in OpenBase SQL before 10.0.1 allows local users to gain privileges via a modified PATH that references a malicious helper binary, as demonstrated by (1) cp, (2) rm, and (3) killall, different vectors than…EXPLOIT ✓MEDIUM 4.6EPSS 0.76%10 November 2006
CVE-2006-5851openexec in OpenBase SQL before 10.0.1 allows local users to create arbitrary files via a symlink attack on the /tmp/output file, a different vulnerability than CVE-2006-5328.EXPLOIT ✓LOW 2.1EPSS 0.74%10 November 2006
CVE-2006-5850Stack-based buffer overflow in Essentia Web Server 2.15 for Windows allows remote attackers to execute arbitrary code via a long URI, as demonstrated by a GET or HEAD request.EXPLOIT ×2 ✓HIGH 7.5EPSS 7.22%10 November 2006
CVE-2006-5849PHP remote file inclusion vulnerability in inc/irayofuncs.php in IrayoBlog alpha-0.2.4 allows remote attackers to execute arbitrary PHP code via a URL in the irayodirhack parameter.EXPLOIT ✓HIGH 7.5EPSS 3.35%10 November 2006
CVE-2006-5847Cross-site scripting (XSS) vulnerability in index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter.EXPLOIT ✓MEDIUM 6.1EPSS 1.97%10 November 2006
CVE-2006-5846Directory traversal vulnerability in index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to read and include arbitrary files via a ..EXPLOIT ✓MEDIUM 6.4EPSS 11.9%10 November 2006

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.