SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-29 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,881 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026

25,049 results · page 371 of 501

CVESummaryPriorityPublished
CVE-2006-5841Multiple PHP remote file inclusion vulnerabilities in dodosmail.php in DodosMail 2.0.1 and earlier, and possibly 2.1, allow remote attackers to execute arbitrary PHP code via a URL in the (1) dodosmail_header_file or (2) dodosmail_footer_file parameters.EXPLOIT ✓HIGH 7.5EPSS 3.18%10 November 2006
CVE-2006-5839PHP remote file inclusion vulnerability in ad_main.php in PHPAdventure 1.1-Alpha and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _mygamefile parameter.EXPLOIT ✓HIGH 7.5EPSS 2.57%10 November 2006
CVE-2006-5838PHP remote file inclusion vulnerability in lib/class.Database.php in NewP News Publication System 1.0.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the path parameter.EXPLOIT ✓MEDIUM 5.1EPSS 2.33%10 November 2006
CVE-2006-5837Static code injection vulnerability in chat_panel.php in the SimpleChat 1.0.0 module for iWare Professional CMS allows remote attackers to inject arbitrary PHP code into chat_log.php via the msg parameter.EXPLOIT ✓HIGH 7.5EPSS 2.45%10 November 2006
CVE-2006-5836The fpathconf syscall function in bsd/kern/kern_descrip.c in the Darwin kernel (XNU) 8.8.1 in Apple Mac OS X allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via a file descriptor with an unrecognized…EXPLOIT ✓HIGH 7.2EPSS 1.30%10 November 2006
CVE-2006-5834Directory traversal vulnerability in general.php in OpenSolution Quick.Cms.Lite 0.3 allows remote attackers to include arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.29%10 November 2006
CVE-2006-5832All In One Control Panel (AIOCP) 1.3.007 and earlier allows remote attackers to obtain the full path of the web server via certain requests to (1) public/code/cp_dpage.php, possibly involving the aiocp_dp[] parameter, (2)…EXPLOIT ×3 ✓MEDIUM 5.0EPSS 3.01%10 November 2006
CVE-2006-5831PHP remote file inclusion vulnerability in admin/code/index.php in All In One Control Panel (AIOCP) 1.3.007 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the load_page parameter.EXPLOIT ✓HIGH 7.5EPSS 2.76%10 November 2006
CVE-2006-5830Multiple cross-site scripting (XSS) vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) topid, (2) forid, and (3) catid parameters to code/cp_forum_view.php;…EXPLOIT ×5 ✓MEDIUM 6.8EPSS 2.38%10 November 2006
CVE-2006-5829Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) choosed_language parameter to (a) cp_dpage.php, (b) cp_news.php, (c) cp_forum_view.php,…EXPLOIT ×12 ✓MEDIUM 6.8EPSS 1.17%10 November 2006
CVE-2006-5828SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.1 and earlier allows remote attackers to execute arbitrary SQL commands via the user_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.09%10 November 2006
CVE-2006-5826Buffer overflow in Texas Imperial Software WFTPD Pro Server 3.23.1.1 allows remote authenticated users to execute arbitrary code or cause a denial of service (application crash) via crafted APPE commands that contain "/" (slash) or "\" (backslash)…EXPLOIT ✓MEDIUM 5.8EPSS 10.8%10 November 2006
CVE-2006-5825Cross-site scripting (XSS) vulnerability in index.php in Kayako SupportSuite 3.00.32 allows remote attackers to inject arbitrary web script or HTML via the query string.EXPLOIT ✓MEDIUM 4.3EPSS 1.64%10 November 2006
CVE-2006-5815Stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0 and earlier allows remote attackers, probably authenticated, to cause a denial of service and execute arbitrary code, as demonstrated by vd_proftpd.pm, a "ProFTPD remote exploit."EXPLOIT ×2 ✓HIGH 10.0EPSS 74.2%8 November 2006
CVE-2006-5811PHP remote file inclusion vulnerability in library/translation.inc.php in OpenEMR 2.8.1, with register_globals enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[srcdir] parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.86%8 November 2006
CVE-2006-5810Cross-site scripting (XSS) vulnerability in modules/wfdownloads/newlist.php in XOOPS 1.0 allows remote attackers to inject arbitrary web script or HTML via the newdownloadshowdays parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.61%8 November 2006
CVE-2006-5802SQL injection vulnerability in message_details.php in The Web Drivers Simple Forum, dated 20060318, allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.09%8 November 2006
CVE-2006-5796Multiple PHP remote file inclusion vulnerabilities in Soholaunch Pro Edition 4.9 r46 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the _SESSION[docroot_path] parameter to (1)…EXPLOIT ✓HIGH 7.5EPSS 3.53%8 November 2006
CVE-2006-5795Multiple PHP remote file inclusion vulnerabilities in OpenEMR 2.8.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the srcdir parameter to (a) billing_process.php, (b) billing_report.php,…EXPLOIT ✓HIGH 7.5EPSS 3.28%8 November 2006
CVE-2006-5792Unspecified vulnerability in XLink Omni-NFS Enterprise allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by vd_xlink2.pm, an "Omni-NFS Enterprise remote exploit." NOTE: this is probably a different vulnerability…EXPLOIT ×2 ✓HIGH 7.5EPSS 60.9%7 November 2006
CVE-2006-5789War FTP Daemon (WarFTPd) 1.82.00-RC11 allows remote authenticated users to cause a denial of service via a large number of "%s" format strings in (1) CWD, (2) CDUP, (3) DELE, (4) NLST, (5) LIST, (6) SIZE, and possibly other commands.EXPLOIT ✓MEDIUM 4.0EPSS 2.92%7 November 2006
CVE-2006-5788PHP remote file inclusion vulnerability in (1) index.php and (2) admin/index.php in IPrimal Forums as of 20061105 allows remote attackers to execute arbitrary PHP code via a URL in the p parameter.EXPLOIT ✓HIGH 7.5EPSS 3.46%7 November 2006
CVE-2006-5787admin/index.php in IPrimal Forums as of 20061105 allows remote attackers to bypass authentication and modify user passwords via a direct request, possibly related to an authentication issue in admin/chk_admin.php.EXPLOIT ✓HIGH 7.5EPSS 2.67%7 November 2006
CVE-2006-5786Directory traversal vulnerability in class2.php in e107 0.7.5 and earlier allows remote attackers to read and execute PHP code in arbitrary files via ".." sequences in the e107language_e107cookie cookie to gsitemap.php.EXPLOIT ✓HIGH 7.5EPSS 2.50%7 November 2006
CVE-2006-5784Unspecified vulnerability in enserver.exe in SAP Web Application Server 6.40 before patch 136 and 7.00 before patch 66 allows remote attackers to read arbitrary files via crafted data on a "3200+SYSNR" TCP port, as demonstrated by port 3201.EXPLOIT ✓MEDIUM 4.6EPSS 2.92%7 November 2006
CVE-2006-5650The ICQPhone.SipxPhoneManager ActiveX control in America Online ICQ 5.1 allows remote attackers to download and execute arbitrary code via the DownloadAgent function, as demonstrated using an ICQ avatar.EXPLOIT ×2 ✓HIGH 7.5EPSS 67.1%7 November 2006
CVE-2006-5780Stack-based buffer overflow in nfsd.exe in XLink Omni-NFS Server 5.2 allows remote attackers to execute arbitrary code via a crafted TCP packet to port 2049 (nfsd), as demonstrated by vd_xlink.pm.EXPLOIT ×2 ✓HIGH 7.5EPSS 62.3%7 November 2006
CVE-2006-5777Creasito E-Commerce Content Manager 1.3.08 allows remote attackers to bypass authentication and perform privileged functions via a non-empty finame parameter to (1) addnewcont.php, (2) adminpassw.php, (3) amministrazione.php, (4) artins.php, (5)…EXPLOIT ✓HIGH 7.5EPSS 2.81%7 November 2006
CVE-2006-5773Directory traversal vulnerability in index.php in FreeWebshop 2.2.1 and earlier allows remote attackers to read arbitrary files and disclose the installation path via a ..EXPLOIT ✓MEDIUM 5.0EPSS 7.90%6 November 2006
CVE-2006-5772Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) password and (2) prod parameter.EXPLOIT ✓HIGH 7.5EPSS 1.13%6 November 2006
CVE-2006-5770Multiple cross-site scripting (XSS) vulnerabilities in ac4p Mobile allow remote attackers to inject arbitrary web script or HTML via (1) Bloks, (2) Newnews, (3) lBlok, and (4) foooot parameter in (a) index.php; Newnews, (5) newmsgs, and Bloks parameter…EXPLOIT ×6 ✓MEDIUM 6.8EPSS 2.68%6 November 2006
CVE-2006-5768Multiple PHP remote file inclusion vulnerabilities in Cyberfolio 2.0 RC1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the av parameter to (1) msg/view.php, (2) msg/inc_message.php, (3)…EXPLOIT ✓HIGH 7.5EPSS 9.79%6 November 2006
CVE-2006-5767PHP remote file inclusion vulnerability in includes/xhtml.php in Drake CMS 0.2.2 alpha rev.846 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the d_root parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.74%6 November 2006
CVE-2006-5766PHP remote file inclusion vulnerability in volume.php in Article System 0.6 allows remote attackers to execute arbitrary PHP code via a URL in the config[public_dir] parameter.EXPLOIT ✓HIGH 7.5EPSS 3.16%6 November 2006
CVE-2006-5765SQL injection vulnerability in rss.php in Article Script 1.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter.EXPLOIT ✓HIGH 7.5EPSS 1.26%6 November 2006
CVE-2006-5764PHP remote file inclusion vulnerability in contact.php in Free File Hosting 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter.EXPLOIT ✓HIGH 7.5EPSS 2.66%6 November 2006
CVE-2006-5763Multiple PHP remote file inclusion vulnerabilities in Free File Hosting 1.1, and possibly earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter to (1) login.php, (2)…EXPLOIT ×2 ✓MEDIUM 5.1EPSS 4.95%6 November 2006
CVE-2006-5762PHP remote file inclusion vulnerability in forgot_pass.php in Free File Hosting 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter.EXPLOIT ✓MEDIUM 5.1EPSS 4.03%6 November 2006
CVE-2006-5761Cross-site scripting (XSS) vulnerability in index.php in Rhadrix If-CMS 1.01 and 2.07 allows remote attackers to inject arbitrary web script or HTML via the rns parameter.EXPLOIT ✓MEDIUM 4.3EPSS 2.03%6 November 2006
CVE-2006-5760Multiple PHP remote file inclusion vulnerabilities in phpDynaSite 3.2.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the racine parameter to (1) function_log.php, (2) function_balise_url.php, or (3) connection.php.EXPLOIT ✓HIGH 7.5EPSS 3.75%6 November 2006
CVE-2006-5758The Graphics Rendering Engine in Microsoft Windows 2000 through 2000 SP4 and Windows XP through SP2 maps GDI Kernel structures on a global shared memory section that is mapped with read-only permissions, but can be remapped by other processes as…EXPLOIT ×3 ✓HIGH 7.2EPSS 6.32%6 November 2006
CVE-2006-5757Race condition in the __find_get_block_slow function in the ISO9660 filesystem in Linux 2.6.18 and possibly other versions allows local users to cause a denial of service (infinite loop) by mounting a crafted ISO9660 filesystem containing malformed data…EXPLOIT ✓LOW 1.2EPSS 0.78%6 November 2006
CVE-2006-5745Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 on Windows, when accessed by Internet Explorer, allows remote attackers to execute arbitrary code via crafted…EXPLOIT ×4 ✓HIGH 7.6EPSS 76.6%6 November 2006
CVE-2006-5739PHP remote file inclusion vulnerability in cpadmin/cpa_index.php in Leicestershire communityPortals 1.0_2005-10-18_12-31-18 allows remote attackers to execute arbitrary PHP code via a URL in the cp_root_path parameter, a different vector than…EXPLOIT ✓HIGH 7.5EPSS 2.17%6 November 2006
CVE-2006-5733Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 3.00%6 November 2006
CVE-2006-5732SQL injection vulnerability in logout.php in T.G.S.EXPLOIT ✓MEDIUM 5.0EPSS 1.02%6 November 2006
CVE-2006-5731Directory traversal vulnerability in classes/index.php in Lithium CMS 4.04c and earlier allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.4EPSS 2.38%6 November 2006
CVE-2006-5730PHP remote file inclusion vulnerability in manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php in Modx CMS 0.9.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.EXPLOIT ✓MEDIUM 5.1EPSS 3.00%6 November 2006
CVE-2006-5728XM Easy Personal FTP Server 5.2.1 and earlier allows remote authenticated users to cause a denial of service via a long argument to the NLST command, possibly involving the -al flags.EXPLOIT ✓MEDIUM 4.0EPSS 2.37%6 November 2006
CVE-2006-5727PHP remote file inclusion vulnerability in admin/controls/cart.php in sazcart 1.5 allows remote attackers to execute arbitrary PHP code via the (1) _saz[settings][shippingfolder] and (2) _saz[settings][taxfolder] parameters.EXPLOIT ✓MEDIUM 5.1EPSS 3.35%6 November 2006

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.