Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,881 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026
25,049 results · page 371 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-5841 | Multiple PHP remote file inclusion vulnerabilities in dodosmail.php in DodosMail 2.0.1 and earlier, and possibly 2.1, allow remote attackers to execute arbitrary PHP code via a URL in the (1) dodosmail_header_file or (2) dodosmail_footer_file parameters. | EXPLOIT ✓HIGH 7.5EPSS 3.18% | 10 November 2006 |
| CVE-2006-5839 | PHP remote file inclusion vulnerability in ad_main.php in PHPAdventure 1.1-Alpha and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _mygamefile parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.57% | 10 November 2006 |
| CVE-2006-5838 | PHP remote file inclusion vulnerability in lib/class.Database.php in NewP News Publication System 1.0.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the path parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 2.33% | 10 November 2006 |
| CVE-2006-5837 | Static code injection vulnerability in chat_panel.php in the SimpleChat 1.0.0 module for iWare Professional CMS allows remote attackers to inject arbitrary PHP code into chat_log.php via the msg parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.45% | 10 November 2006 |
| CVE-2006-5836 | The fpathconf syscall function in bsd/kern/kern_descrip.c in the Darwin kernel (XNU) 8.8.1 in Apple Mac OS X allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via a file descriptor with an unrecognized… | EXPLOIT ✓HIGH 7.2EPSS 1.30% | 10 November 2006 |
| CVE-2006-5834 | Directory traversal vulnerability in general.php in OpenSolution Quick.Cms.Lite 0.3 allows remote attackers to include arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.29% | 10 November 2006 |
| CVE-2006-5832 | All In One Control Panel (AIOCP) 1.3.007 and earlier allows remote attackers to obtain the full path of the web server via certain requests to (1) public/code/cp_dpage.php, possibly involving the aiocp_dp[] parameter, (2)… | EXPLOIT ×3 ✓MEDIUM 5.0EPSS 3.01% | 10 November 2006 |
| CVE-2006-5831 | PHP remote file inclusion vulnerability in admin/code/index.php in All In One Control Panel (AIOCP) 1.3.007 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the load_page parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.76% | 10 November 2006 |
| CVE-2006-5830 | Multiple cross-site scripting (XSS) vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) topid, (2) forid, and (3) catid parameters to code/cp_forum_view.php;… | EXPLOIT ×5 ✓MEDIUM 6.8EPSS 2.38% | 10 November 2006 |
| CVE-2006-5829 | Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) choosed_language parameter to (a) cp_dpage.php, (b) cp_news.php, (c) cp_forum_view.php,… | EXPLOIT ×12 ✓MEDIUM 6.8EPSS 1.17% | 10 November 2006 |
| CVE-2006-5828 | SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.1 and earlier allows remote attackers to execute arbitrary SQL commands via the user_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.09% | 10 November 2006 |
| CVE-2006-5826 | Buffer overflow in Texas Imperial Software WFTPD Pro Server 3.23.1.1 allows remote authenticated users to execute arbitrary code or cause a denial of service (application crash) via crafted APPE commands that contain "/" (slash) or "\" (backslash)… | EXPLOIT ✓MEDIUM 5.8EPSS 10.8% | 10 November 2006 |
| CVE-2006-5825 | Cross-site scripting (XSS) vulnerability in index.php in Kayako SupportSuite 3.00.32 allows remote attackers to inject arbitrary web script or HTML via the query string. | EXPLOIT ✓MEDIUM 4.3EPSS 1.64% | 10 November 2006 |
| CVE-2006-5815 | Stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0 and earlier allows remote attackers, probably authenticated, to cause a denial of service and execute arbitrary code, as demonstrated by vd_proftpd.pm, a "ProFTPD remote exploit." | EXPLOIT ×2 ✓HIGH 10.0EPSS 74.2% | 8 November 2006 |
| CVE-2006-5811 | PHP remote file inclusion vulnerability in library/translation.inc.php in OpenEMR 2.8.1, with register_globals enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[srcdir] parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.86% | 8 November 2006 |
| CVE-2006-5810 | Cross-site scripting (XSS) vulnerability in modules/wfdownloads/newlist.php in XOOPS 1.0 allows remote attackers to inject arbitrary web script or HTML via the newdownloadshowdays parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.61% | 8 November 2006 |
| CVE-2006-5802 | SQL injection vulnerability in message_details.php in The Web Drivers Simple Forum, dated 20060318, allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.09% | 8 November 2006 |
| CVE-2006-5796 | Multiple PHP remote file inclusion vulnerabilities in Soholaunch Pro Edition 4.9 r46 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the _SESSION[docroot_path] parameter to (1)… | EXPLOIT ✓HIGH 7.5EPSS 3.53% | 8 November 2006 |
| CVE-2006-5795 | Multiple PHP remote file inclusion vulnerabilities in OpenEMR 2.8.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the srcdir parameter to (a) billing_process.php, (b) billing_report.php,… | EXPLOIT ✓HIGH 7.5EPSS 3.28% | 8 November 2006 |
| CVE-2006-5792 | Unspecified vulnerability in XLink Omni-NFS Enterprise allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by vd_xlink2.pm, an "Omni-NFS Enterprise remote exploit." NOTE: this is probably a different vulnerability… | EXPLOIT ×2 ✓HIGH 7.5EPSS 60.9% | 7 November 2006 |
| CVE-2006-5789 | War FTP Daemon (WarFTPd) 1.82.00-RC11 allows remote authenticated users to cause a denial of service via a large number of "%s" format strings in (1) CWD, (2) CDUP, (3) DELE, (4) NLST, (5) LIST, (6) SIZE, and possibly other commands. | EXPLOIT ✓MEDIUM 4.0EPSS 2.92% | 7 November 2006 |
| CVE-2006-5788 | PHP remote file inclusion vulnerability in (1) index.php and (2) admin/index.php in IPrimal Forums as of 20061105 allows remote attackers to execute arbitrary PHP code via a URL in the p parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.46% | 7 November 2006 |
| CVE-2006-5787 | admin/index.php in IPrimal Forums as of 20061105 allows remote attackers to bypass authentication and modify user passwords via a direct request, possibly related to an authentication issue in admin/chk_admin.php. | EXPLOIT ✓HIGH 7.5EPSS 2.67% | 7 November 2006 |
| CVE-2006-5786 | Directory traversal vulnerability in class2.php in e107 0.7.5 and earlier allows remote attackers to read and execute PHP code in arbitrary files via ".." sequences in the e107language_e107cookie cookie to gsitemap.php. | EXPLOIT ✓HIGH 7.5EPSS 2.50% | 7 November 2006 |
| CVE-2006-5784 | Unspecified vulnerability in enserver.exe in SAP Web Application Server 6.40 before patch 136 and 7.00 before patch 66 allows remote attackers to read arbitrary files via crafted data on a "3200+SYSNR" TCP port, as demonstrated by port 3201. | EXPLOIT ✓MEDIUM 4.6EPSS 2.92% | 7 November 2006 |
| CVE-2006-5650 | The ICQPhone.SipxPhoneManager ActiveX control in America Online ICQ 5.1 allows remote attackers to download and execute arbitrary code via the DownloadAgent function, as demonstrated using an ICQ avatar. | EXPLOIT ×2 ✓HIGH 7.5EPSS 67.1% | 7 November 2006 |
| CVE-2006-5780 | Stack-based buffer overflow in nfsd.exe in XLink Omni-NFS Server 5.2 allows remote attackers to execute arbitrary code via a crafted TCP packet to port 2049 (nfsd), as demonstrated by vd_xlink.pm. | EXPLOIT ×2 ✓HIGH 7.5EPSS 62.3% | 7 November 2006 |
| CVE-2006-5777 | Creasito E-Commerce Content Manager 1.3.08 allows remote attackers to bypass authentication and perform privileged functions via a non-empty finame parameter to (1) addnewcont.php, (2) adminpassw.php, (3) amministrazione.php, (4) artins.php, (5)… | EXPLOIT ✓HIGH 7.5EPSS 2.81% | 7 November 2006 |
| CVE-2006-5773 | Directory traversal vulnerability in index.php in FreeWebshop 2.2.1 and earlier allows remote attackers to read arbitrary files and disclose the installation path via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 7.90% | 6 November 2006 |
| CVE-2006-5772 | Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) password and (2) prod parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.13% | 6 November 2006 |
| CVE-2006-5770 | Multiple cross-site scripting (XSS) vulnerabilities in ac4p Mobile allow remote attackers to inject arbitrary web script or HTML via (1) Bloks, (2) Newnews, (3) lBlok, and (4) foooot parameter in (a) index.php; Newnews, (5) newmsgs, and Bloks parameter… | EXPLOIT ×6 ✓MEDIUM 6.8EPSS 2.68% | 6 November 2006 |
| CVE-2006-5768 | Multiple PHP remote file inclusion vulnerabilities in Cyberfolio 2.0 RC1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the av parameter to (1) msg/view.php, (2) msg/inc_message.php, (3)… | EXPLOIT ✓HIGH 7.5EPSS 9.79% | 6 November 2006 |
| CVE-2006-5767 | PHP remote file inclusion vulnerability in includes/xhtml.php in Drake CMS 0.2.2 alpha rev.846 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the d_root parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.74% | 6 November 2006 |
| CVE-2006-5766 | PHP remote file inclusion vulnerability in volume.php in Article System 0.6 allows remote attackers to execute arbitrary PHP code via a URL in the config[public_dir] parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.16% | 6 November 2006 |
| CVE-2006-5765 | SQL injection vulnerability in rss.php in Article Script 1.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.26% | 6 November 2006 |
| CVE-2006-5764 | PHP remote file inclusion vulnerability in contact.php in Free File Hosting 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.66% | 6 November 2006 |
| CVE-2006-5763 | Multiple PHP remote file inclusion vulnerabilities in Free File Hosting 1.1, and possibly earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter to (1) login.php, (2)… | EXPLOIT ×2 ✓MEDIUM 5.1EPSS 4.95% | 6 November 2006 |
| CVE-2006-5762 | PHP remote file inclusion vulnerability in forgot_pass.php in Free File Hosting 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 4.03% | 6 November 2006 |
| CVE-2006-5761 | Cross-site scripting (XSS) vulnerability in index.php in Rhadrix If-CMS 1.01 and 2.07 allows remote attackers to inject arbitrary web script or HTML via the rns parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 2.03% | 6 November 2006 |
| CVE-2006-5760 | Multiple PHP remote file inclusion vulnerabilities in phpDynaSite 3.2.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the racine parameter to (1) function_log.php, (2) function_balise_url.php, or (3) connection.php. | EXPLOIT ✓HIGH 7.5EPSS 3.75% | 6 November 2006 |
| CVE-2006-5758 | The Graphics Rendering Engine in Microsoft Windows 2000 through 2000 SP4 and Windows XP through SP2 maps GDI Kernel structures on a global shared memory section that is mapped with read-only permissions, but can be remapped by other processes as… | EXPLOIT ×3 ✓HIGH 7.2EPSS 6.32% | 6 November 2006 |
| CVE-2006-5757 | Race condition in the __find_get_block_slow function in the ISO9660 filesystem in Linux 2.6.18 and possibly other versions allows local users to cause a denial of service (infinite loop) by mounting a crafted ISO9660 filesystem containing malformed data… | EXPLOIT ✓LOW 1.2EPSS 0.78% | 6 November 2006 |
| CVE-2006-5745 | Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 on Windows, when accessed by Internet Explorer, allows remote attackers to execute arbitrary code via crafted… | EXPLOIT ×4 ✓HIGH 7.6EPSS 76.6% | 6 November 2006 |
| CVE-2006-5739 | PHP remote file inclusion vulnerability in cpadmin/cpa_index.php in Leicestershire communityPortals 1.0_2005-10-18_12-31-18 allows remote attackers to execute arbitrary PHP code via a URL in the cp_root_path parameter, a different vector than… | EXPLOIT ✓HIGH 7.5EPSS 2.17% | 6 November 2006 |
| CVE-2006-5733 | Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 3.00% | 6 November 2006 |
| CVE-2006-5732 | SQL injection vulnerability in logout.php in T.G.S. | EXPLOIT ✓MEDIUM 5.0EPSS 1.02% | 6 November 2006 |
| CVE-2006-5731 | Directory traversal vulnerability in classes/index.php in Lithium CMS 4.04c and earlier allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.4EPSS 2.38% | 6 November 2006 |
| CVE-2006-5730 | PHP remote file inclusion vulnerability in manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php in Modx CMS 0.9.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 3.00% | 6 November 2006 |
| CVE-2006-5728 | XM Easy Personal FTP Server 5.2.1 and earlier allows remote authenticated users to cause a denial of service via a long argument to the NLST command, possibly involving the -al flags. | EXPLOIT ✓MEDIUM 4.0EPSS 2.37% | 6 November 2006 |
| CVE-2006-5727 | PHP remote file inclusion vulnerability in admin/controls/cart.php in sazcart 1.5 allows remote attackers to execute arbitrary PHP code via the (1) _saz[settings][shippingfolder] and (2) _saz[settings][taxfolder] parameters. | EXPLOIT ✓MEDIUM 5.1EPSS 3.35% | 6 November 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.