Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,893 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026
25,049 results · page 372 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-5726 | alloccgblk in the UFS filesystem in Solaris 10 allows local users to cause a denial of service (memory corruption) by mounting crafted UFS filesystems with malformed data structures. | EXPLOIT ✓MEDIUM 4.9EPSS 0.80% | 6 November 2006 |
| CVE-2006-5725 | The SSL server in AEP Smartgate 4.3b allows remote attackers to determine existence of directories via a direct request for a directory URI, which returns different HTTP status codes for existing and non-existing directories. | EXPLOIT ✓MEDIUM 5.0EPSS 2.77% | 4 November 2006 |
| CVE-2006-5722 | Multiple PHP remote file inclusion vulnerabilities in Segue CMS 1.5.9 and earlier, when magic_quotes_gpc is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the theme parameter to (1) themesettings.php or (2) index.php, a… | EXPLOIT ✓MEDIUM 5.1EPSS 2.07% | 4 November 2006 |
| CVE-2006-5721 | The \Device\SandBox driver in Outpost Firewall PRO 4.0 (964.582.059) allows local users to cause a denial of service (system crash) via an invalid argument to the DeviceIoControl function that triggers an invalid memory operation. | EXPLOIT ✓MEDIUM 4.9EPSS 0.97% | 4 November 2006 |
| CVE-2006-5720 | SQL injection vulnerability in modules/journal/search.php in the Journal module in Francisco Burzi PHP-Nuke 7.9 and earlier allows remote attackers to execute arbitrary SQL commands via the forwhat parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.41% | 4 November 2006 |
| CVE-2006-5716 | Directory traversal vulnerability in aff_news.php in FreeNews 2.1 allows remote attackers to include local files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.91% | 4 November 2006 |
| CVE-2006-5715 | Easy File Sharing (EFS) Easy Address Book 1.2, when run on an NTFS file system, allows remote attackers to read arbitrary files under the web root by appending "::$DATA" to the end of an HTTP GET request, which accesses the alternate data stream. | EXPLOIT ✓MEDIUM 5.0EPSS 6.25% | 4 November 2006 |
| CVE-2006-5714 | Easy File Sharing (EFS) Web Server 4.0, when running on an NTFS file system, allows remote attackers to read arbitrary files under the web root by appending "::$DATA" to the end of a HTTP GET request, which accesses the alternate data stream. | EXPLOIT ✓MEDIUM 5.0EPSS 6.25% | 4 November 2006 |
| CVE-2006-5712 | Cross-site scripting (XSS) vulnerability in Mirapoint WebMail allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated using the width style for an IMG element. | EXPLOIT ✓MEDIUM 4.3EPSS 1.61% | 4 November 2006 |
| CVE-2006-5711 | ECI Telecom B-FOCuS Wireless 802.11b/g ADSL2+ Router allows remote attackers to read arbitrary files via a certain HTTP request, as demonstrated by a request for a router configuration file, related to the /html/defs/ URI. | EXPLOIT ✓MEDIUM 5.0EPSS 3.33% | 4 November 2006 |
| CVE-2006-5710 | The Airport driver for certain Orinoco based Airport cards in Darwin kernel 8.8.0 in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to execute arbitrary code via an 802.11 probe response frame without any valid information… | EXPLOIT ✓HIGH 7.5EPSS 18.5% | 4 November 2006 |
| CVE-2006-5707 | SQL injection vulnerability in index.php in PHPEasyData Pro 1.4.1 and 2.2.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.09% | 4 November 2006 |
| CVE-2006-5703 | Cross-site scripting (XSS) vulnerability in tiki-featured_link.php in Tikiwiki 1.9.5 allows remote attackers to inject arbitrary web script or HTML via a url parameter that evades filtering, as demonstrated by a parameter value containing malformed,… | EXPLOIT ✓MEDIUM 4.3EPSS 2.43% | 4 November 2006 |
| CVE-2006-5702 | Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-listpages.php, (2) tiki-lastchanges.php, (3) messu-archive.php, (4) messu-mailbox.php, (5) messu-sent.php,… | EXPLOIT ✓MEDIUM 5.0EPSS 53.3% | 4 November 2006 |
| CVE-2006-5701 | Double free vulnerability in squashfs module in the Linux kernel 2.6.x, as used in Fedora Core 5 and possibly other distributions, allows local users to cause a denial of service by mounting a crafted squashfs filesystem. | EXPLOIT ✓MEDIUM 4.9EPSS 0.86% | 3 November 2006 |
| CVE-2006-5676 | SQL injection vulnerability in consult/classement.php in Uni-Vert PhpLeague 0.82 and earlier allows remote attackers to execute arbitrary SQL commands via the champ parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 1.10% | 3 November 2006 |
| CVE-2006-5675 | Multiple unspecified vulnerabilities in Pentaho Business Intelligence (BI) Suite before 1.2 RC3 (1.2.0.470-RC3) have unknown impact and attack vectors, related to "MySQL Scripts need changes for security," possibly SQL injection vulnerabilities… | EXPLOIT ✓HIGH 10.0EPSS 1.47% | 3 November 2006 |
| CVE-2006-5673 | PHP remote file inclusion vulnerability in bb_func_txt.php in miniBB 2.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pathToFiles parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 6.06% | 3 November 2006 |
| CVE-2006-5672 | PHP remote file inclusion vulnerability in web/init_mysource.php in MySource CMS 2.16.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_PATH parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.43% | 3 November 2006 |
| CVE-2006-5670 | PHP remote file inclusion vulnerability in forgot_pass.php in Free Image Hosting 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.18% | 3 November 2006 |
| CVE-2006-5669 | PHP remote file inclusion vulnerability in gestion/savebackup.php in Gepi 1.4.0 and earlier, and possibly other versions before 1.4.4, allows remote attackers to execute arbitrary PHP code via a URL in the filename parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.50% | 3 November 2006 |
| CVE-2006-5667 | Multiple PHP remote file inclusion vulnerabilities in P-Book 1.17 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the pb_lang parameter to (1) admin.php and (2) pbook.php. | EXPLOIT ✓HIGH 7.5EPSS 3.38% | 3 November 2006 |
| CVE-2006-5666 | SQL injection vulnerability in includes/menu.inc.php in E-Annu 1.0 allows remote attackers to execute arbitrary SQL commands via the login parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.09% | 3 November 2006 |
| CVE-2006-5665 | PHP remote file inclusion vulnerability in admin/modules_data.php in the phpBB module Spider Friendly 1.3.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.38% | 3 November 2006 |
| CVE-2006-5662 | SQL injection vulnerability in easy notesManager (eNM) 0.0.1 allows remote attackers to execute arbitrary SQL commands via (1) the username parameter in login.php and (2) a search on the "search page." | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.09% | 3 November 2006 |
| CVE-2006-5661 | Cross-site scripting (XSS) vulnerability in nquser.php in VIRtech Netquery allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header. | EXPLOIT ✓MEDIUM 6.8EPSS 2.82% | 3 November 2006 |
| CVE-2006-5653 | Cross-site scripting (XSS) vulnerability in the errorHTML function in the index script in Sun Java System Messenger Express 6 allows remote attackers to inject arbitrary web script or HTML via the error parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 4.80% | 3 November 2006 |
| CVE-2006-5652 | Cross-site scripting (XSS) vulnerability in Sun iPlanet Messaging Server Messenger Express allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated by setting the width style for an… | EXPLOIT ✓MEDIUM 4.3EPSS 1.64% | 3 November 2006 |
| CVE-2006-5647 | Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a malformed CHM… | EXPLOIT ✓MEDIUM 6.4EPSS 21.1% | 1 November 2006 |
| CVE-2006-5646 | Heap-based buffer overflow in Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when archive scanning is enabled, allows remote attackers to trigger a denial of service (memory… | EXPLOIT ✓MEDIUM 5.0EPSS 17.9% | 1 November 2006 |
| CVE-2006-5645 | Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when "Enabled scanning of archives" is set, allows remote attackers to cause a denial of service (infinite loop) via a malformed… | EXPLOIT ✓MEDIUM 5.0EPSS 17.8% | 1 November 2006 |
| CVE-2006-4704 | Cross-zone scripting vulnerability in the WMI Object Broker (WMIScriptUtils.WMIObjectBroker2) ActiveX control (WmiScriptUtils.dll) in Microsoft Visual Studio 2005 allows remote attackers to bypass Internet zone restrictions and execute arbitrary code by… | EXPLOIT ✓MEDIUM 6.8EPSS 43.9% | 1 November 2006 |
| CVE-2006-5643 | Cross-site scripting (XSS) vulnerability in search_de.html in foresite CMS allows remote attackers to inject arbitrary web script or HTML via the query parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.15% | 1 November 2006 |
| CVE-2006-5641 | SQL injection vulnerability in MainAnnounce2.asp in Techno Dreams Announcement allows remote attackers to execute arbitrary SQL commands via the key parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.09% | 1 November 2006 |
| CVE-2006-5640 | SQL injection vulnerability in guestbookview.asp in Techno Dreams Guest Book 1.0 earlier allows remote attackers to execute arbitrary SQL commands via the key parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.09% | 1 November 2006 |
| CVE-2006-5638 | Multiple SQL injection vulnerabilities in cherche.php in PHPMyRing 4.2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) limite and (2) mots parameters. | EXPLOIT ✓HIGH 7.5EPSS 1.09% | 1 November 2006 |
| CVE-2006-5637 | PHP remote file inclusion vulnerability in faq_reply.php in Faq Administrator 2.1b allows remote attackers to execute arbitrary PHP code via a URL in the email parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.39% | 1 November 2006 |
| CVE-2006-5636 | PHP remote file inclusion vulnerability in common.php in Simple Website Software (SWS) 0.99 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the SWSDIR parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 3.35% | 1 November 2006 |
| CVE-2006-5635 | SQL injection vulnerability in forum/search.asp in Web Wiz Forums allows remote attackers to execute arbitrary SQL commands via the KW parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.08% | 1 November 2006 |
| CVE-2006-5634 | Multiple PHP remote file inclusion vulnerabilities in phpProfiles 2.1 Beta allow remote attackers to execute arbitrary PHP code via a URL in the (1) reqpath parameter to (a) body.inc.php and (b) body_blog.inc.php in users/include/; or the (2) usrinc… | EXPLOIT ✓MEDIUM 6.8EPSS 6.14% | 1 November 2006 |
| CVE-2006-5633 | Firefox 1.5.0.7 and 2.0, and Seamonkey 1.1b, allows remote attackers to cause a denial of service (crash) by creating a range object using createRange, calling selectNode on a DocType node (DOCUMENT_TYPE_NODE), then calling createContextualFragment on… | EXPLOIT ✓MEDIUM 5.0EPSS 7.47% | 31 October 2006 |
| CVE-2006-5629 | Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote attackers to execute arbitrary SQL commands via the ForumID parameter in (1) DisableForum.asp and (2) enableForum.asp. | EXPLOIT ✓HIGH 7.5EPSS 3.22% | 31 October 2006 |
| CVE-2006-5627 | Multiple PHP remote file inclusion vulnerabilities in QnECMS 2.5.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the adminfolderpath parameter to (1) headerscripts.php, (2) footerhome.php, and (3) footermain.php in… | EXPLOIT ✓HIGH 7.5EPSS 17.1% | 31 October 2006 |
| CVE-2006-5626 | Cross-site scripting (XSS) vulnerability in cms_images/js/htmlarea/htmlarea.php in phpFaber Content Management System (CMS) before 1.3.36 on 20061026 allows remote attackers to inject arbitrary web script or HTML, probably via arbitrary parameters in… | EXPLOIT ✓MEDIUM 4.3EPSS 1.95% | 31 October 2006 |
| CVE-2006-5625 | PHP remote file inclusion vulnerability in wwwdev/nxheader.inc.php in N/X 2002 Professional Edition Web Content Management System (WCMS) 4.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the c[path] parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 2.38% | 31 October 2006 |
| CVE-2006-5624 | Multiple PHP remote file inclusion vulnerabilities in Multi-Page Comment System (MPCS) 1.0.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) include.php or (2) functions.php. | EXPLOIT ✓HIGH 7.5EPSS 2.93% | 31 October 2006 |
| CVE-2006-5623 | PHP remote file inclusion vulnerability in ip.inc.php in Electronic Engineering Tool (EE Tool) 0.4-1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cgipath parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.49% | 31 October 2006 |
| CVE-2006-5622 | SQL injection vulnerability in picmgr.php in Coppermine Photo Gallery 1.4.9 allows remote attackers to execute arbitrary SQL commands via the aid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.18% | 31 October 2006 |
| CVE-2006-5621 | PHP remote file inclusion vulnerability in end.php in ask_rave 0.9 PR, and other versions before 0.9b, allows remote attackers to execute arbitrary PHP code via a URL in the footfile parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.83% | 31 October 2006 |
| CVE-2006-5620 | PHP remote file inclusion vulnerability in include/menu_builder.php in MiniBILL 2006-10-10 (1.2.3) and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the config[page_dir] parameter, a… | EXPLOIT ✓HIGH 7.5EPSS 3.77% | 31 October 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.