SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-29 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,893 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026

25,049 results · page 372 of 501

CVESummaryPriorityPublished
CVE-2006-5726alloccgblk in the UFS filesystem in Solaris 10 allows local users to cause a denial of service (memory corruption) by mounting crafted UFS filesystems with malformed data structures.EXPLOIT ✓MEDIUM 4.9EPSS 0.80%6 November 2006
CVE-2006-5725The SSL server in AEP Smartgate 4.3b allows remote attackers to determine existence of directories via a direct request for a directory URI, which returns different HTTP status codes for existing and non-existing directories.EXPLOIT ✓MEDIUM 5.0EPSS 2.77%4 November 2006
CVE-2006-5722Multiple PHP remote file inclusion vulnerabilities in Segue CMS 1.5.9 and earlier, when magic_quotes_gpc is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the theme parameter to (1) themesettings.php or (2) index.php, a…EXPLOIT ✓MEDIUM 5.1EPSS 2.07%4 November 2006
CVE-2006-5721The \Device\SandBox driver in Outpost Firewall PRO 4.0 (964.582.059) allows local users to cause a denial of service (system crash) via an invalid argument to the DeviceIoControl function that triggers an invalid memory operation.EXPLOIT ✓MEDIUM 4.9EPSS 0.97%4 November 2006
CVE-2006-5720SQL injection vulnerability in modules/journal/search.php in the Journal module in Francisco Burzi PHP-Nuke 7.9 and earlier allows remote attackers to execute arbitrary SQL commands via the forwhat parameter.EXPLOIT ✓HIGH 7.5EPSS 2.41%4 November 2006
CVE-2006-5716Directory traversal vulnerability in aff_news.php in FreeNews 2.1 allows remote attackers to include local files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.91%4 November 2006
CVE-2006-5715Easy File Sharing (EFS) Easy Address Book 1.2, when run on an NTFS file system, allows remote attackers to read arbitrary files under the web root by appending "::$DATA" to the end of an HTTP GET request, which accesses the alternate data stream.EXPLOIT ✓MEDIUM 5.0EPSS 6.25%4 November 2006
CVE-2006-5714Easy File Sharing (EFS) Web Server 4.0, when running on an NTFS file system, allows remote attackers to read arbitrary files under the web root by appending "::$DATA" to the end of a HTTP GET request, which accesses the alternate data stream.EXPLOIT ✓MEDIUM 5.0EPSS 6.25%4 November 2006
CVE-2006-5712Cross-site scripting (XSS) vulnerability in Mirapoint WebMail allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated using the width style for an IMG element.EXPLOIT ✓MEDIUM 4.3EPSS 1.61%4 November 2006
CVE-2006-5711ECI Telecom B-FOCuS Wireless 802.11b/g ADSL2+ Router allows remote attackers to read arbitrary files via a certain HTTP request, as demonstrated by a request for a router configuration file, related to the /html/defs/ URI.EXPLOIT ✓MEDIUM 5.0EPSS 3.33%4 November 2006
CVE-2006-5710The Airport driver for certain Orinoco based Airport cards in Darwin kernel 8.8.0 in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to execute arbitrary code via an 802.11 probe response frame without any valid information…EXPLOIT ✓HIGH 7.5EPSS 18.5%4 November 2006
CVE-2006-5707SQL injection vulnerability in index.php in PHPEasyData Pro 1.4.1 and 2.2.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter.EXPLOIT ✓HIGH 7.5EPSS 2.09%4 November 2006
CVE-2006-5703Cross-site scripting (XSS) vulnerability in tiki-featured_link.php in Tikiwiki 1.9.5 allows remote attackers to inject arbitrary web script or HTML via a url parameter that evades filtering, as demonstrated by a parameter value containing malformed,…EXPLOIT ✓MEDIUM 4.3EPSS 2.43%4 November 2006
CVE-2006-5702Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-listpages.php, (2) tiki-lastchanges.php, (3) messu-archive.php, (4) messu-mailbox.php, (5) messu-sent.php,…EXPLOIT ✓MEDIUM 5.0EPSS 53.3%4 November 2006
CVE-2006-5701Double free vulnerability in squashfs module in the Linux kernel 2.6.x, as used in Fedora Core 5 and possibly other distributions, allows local users to cause a denial of service by mounting a crafted squashfs filesystem.EXPLOIT ✓MEDIUM 4.9EPSS 0.86%3 November 2006
CVE-2006-5676SQL injection vulnerability in consult/classement.php in Uni-Vert PhpLeague 0.82 and earlier allows remote attackers to execute arbitrary SQL commands via the champ parameter.EXPLOIT ✓MEDIUM 6.4EPSS 1.10%3 November 2006
CVE-2006-5675Multiple unspecified vulnerabilities in Pentaho Business Intelligence (BI) Suite before 1.2 RC3 (1.2.0.470-RC3) have unknown impact and attack vectors, related to "MySQL Scripts need changes for security," possibly SQL injection vulnerabilities…EXPLOIT ✓HIGH 10.0EPSS 1.47%3 November 2006
CVE-2006-5673PHP remote file inclusion vulnerability in bb_func_txt.php in miniBB 2.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pathToFiles parameter.EXPLOIT ✓MEDIUM 6.8EPSS 6.06%3 November 2006
CVE-2006-5672PHP remote file inclusion vulnerability in web/init_mysource.php in MySource CMS 2.16.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_PATH parameter.EXPLOIT ✓HIGH 7.5EPSS 2.43%3 November 2006
CVE-2006-5670PHP remote file inclusion vulnerability in forgot_pass.php in Free Image Hosting 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter.EXPLOIT ✓HIGH 7.5EPSS 3.18%3 November 2006
CVE-2006-5669PHP remote file inclusion vulnerability in gestion/savebackup.php in Gepi 1.4.0 and earlier, and possibly other versions before 1.4.4, allows remote attackers to execute arbitrary PHP code via a URL in the filename parameter.EXPLOIT ✓HIGH 7.5EPSS 2.50%3 November 2006
CVE-2006-5667Multiple PHP remote file inclusion vulnerabilities in P-Book 1.17 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the pb_lang parameter to (1) admin.php and (2) pbook.php.EXPLOIT ✓HIGH 7.5EPSS 3.38%3 November 2006
CVE-2006-5666SQL injection vulnerability in includes/menu.inc.php in E-Annu 1.0 allows remote attackers to execute arbitrary SQL commands via the login parameter.EXPLOIT ✓HIGH 7.5EPSS 1.09%3 November 2006
CVE-2006-5665PHP remote file inclusion vulnerability in admin/modules_data.php in the phpBB module Spider Friendly 1.3.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.EXPLOIT ✓HIGH 7.5EPSS 3.38%3 November 2006
CVE-2006-5662SQL injection vulnerability in easy notesManager (eNM) 0.0.1 allows remote attackers to execute arbitrary SQL commands via (1) the username parameter in login.php and (2) a search on the "search page."EXPLOIT ×2 ✓HIGH 7.5EPSS 1.09%3 November 2006
CVE-2006-5661Cross-site scripting (XSS) vulnerability in nquser.php in VIRtech Netquery allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.EXPLOIT ✓MEDIUM 6.8EPSS 2.82%3 November 2006
CVE-2006-5653Cross-site scripting (XSS) vulnerability in the errorHTML function in the index script in Sun Java System Messenger Express 6 allows remote attackers to inject arbitrary web script or HTML via the error parameter.EXPLOIT ✓MEDIUM 4.3EPSS 4.80%3 November 2006
CVE-2006-5652Cross-site scripting (XSS) vulnerability in Sun iPlanet Messaging Server Messenger Express allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated by setting the width style for an…EXPLOIT ✓MEDIUM 4.3EPSS 1.64%3 November 2006
CVE-2006-5647Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a malformed CHM…EXPLOIT ✓MEDIUM 6.4EPSS 21.1%1 November 2006
CVE-2006-5646Heap-based buffer overflow in Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when archive scanning is enabled, allows remote attackers to trigger a denial of service (memory…EXPLOIT ✓MEDIUM 5.0EPSS 17.9%1 November 2006
CVE-2006-5645Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when "Enabled scanning of archives" is set, allows remote attackers to cause a denial of service (infinite loop) via a malformed…EXPLOIT ✓MEDIUM 5.0EPSS 17.8%1 November 2006
CVE-2006-4704Cross-zone scripting vulnerability in the WMI Object Broker (WMIScriptUtils.WMIObjectBroker2) ActiveX control (WmiScriptUtils.dll) in Microsoft Visual Studio 2005 allows remote attackers to bypass Internet zone restrictions and execute arbitrary code by…EXPLOIT ✓MEDIUM 6.8EPSS 43.9%1 November 2006
CVE-2006-5643Cross-site scripting (XSS) vulnerability in search_de.html in foresite CMS allows remote attackers to inject arbitrary web script or HTML via the query parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.15%1 November 2006
CVE-2006-5641SQL injection vulnerability in MainAnnounce2.asp in Techno Dreams Announcement allows remote attackers to execute arbitrary SQL commands via the key parameter.EXPLOIT ✓HIGH 7.5EPSS 1.09%1 November 2006
CVE-2006-5640SQL injection vulnerability in guestbookview.asp in Techno Dreams Guest Book 1.0 earlier allows remote attackers to execute arbitrary SQL commands via the key parameter.EXPLOIT ✓HIGH 7.5EPSS 1.09%1 November 2006
CVE-2006-5638Multiple SQL injection vulnerabilities in cherche.php in PHPMyRing 4.2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) limite and (2) mots parameters.EXPLOIT ✓HIGH 7.5EPSS 1.09%1 November 2006
CVE-2006-5637PHP remote file inclusion vulnerability in faq_reply.php in Faq Administrator 2.1b allows remote attackers to execute arbitrary PHP code via a URL in the email parameter.EXPLOIT ✓HIGH 7.5EPSS 3.39%1 November 2006
CVE-2006-5636PHP remote file inclusion vulnerability in common.php in Simple Website Software (SWS) 0.99 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the SWSDIR parameter.EXPLOIT ✓MEDIUM 5.1EPSS 3.35%1 November 2006
CVE-2006-5635SQL injection vulnerability in forum/search.asp in Web Wiz Forums allows remote attackers to execute arbitrary SQL commands via the KW parameter.EXPLOIT ✓HIGH 7.5EPSS 1.08%1 November 2006
CVE-2006-5634Multiple PHP remote file inclusion vulnerabilities in phpProfiles 2.1 Beta allow remote attackers to execute arbitrary PHP code via a URL in the (1) reqpath parameter to (a) body.inc.php and (b) body_blog.inc.php in users/include/; or the (2) usrinc…EXPLOIT ✓MEDIUM 6.8EPSS 6.14%1 November 2006
CVE-2006-5633Firefox 1.5.0.7 and 2.0, and Seamonkey 1.1b, allows remote attackers to cause a denial of service (crash) by creating a range object using createRange, calling selectNode on a DocType node (DOCUMENT_TYPE_NODE), then calling createContextualFragment on…EXPLOIT ✓MEDIUM 5.0EPSS 7.47%31 October 2006
CVE-2006-5629Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote attackers to execute arbitrary SQL commands via the ForumID parameter in (1) DisableForum.asp and (2) enableForum.asp.EXPLOIT ✓HIGH 7.5EPSS 3.22%31 October 2006
CVE-2006-5627Multiple PHP remote file inclusion vulnerabilities in QnECMS 2.5.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the adminfolderpath parameter to (1) headerscripts.php, (2) footerhome.php, and (3) footermain.php in…EXPLOIT ✓HIGH 7.5EPSS 17.1%31 October 2006
CVE-2006-5626Cross-site scripting (XSS) vulnerability in cms_images/js/htmlarea/htmlarea.php in phpFaber Content Management System (CMS) before 1.3.36 on 20061026 allows remote attackers to inject arbitrary web script or HTML, probably via arbitrary parameters in…EXPLOIT ✓MEDIUM 4.3EPSS 1.95%31 October 2006
CVE-2006-5625PHP remote file inclusion vulnerability in wwwdev/nxheader.inc.php in N/X 2002 Professional Edition Web Content Management System (WCMS) 4.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the c[path] parameter.EXPLOIT ✓MEDIUM 5.1EPSS 2.38%31 October 2006
CVE-2006-5624Multiple PHP remote file inclusion vulnerabilities in Multi-Page Comment System (MPCS) 1.0.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) include.php or (2) functions.php.EXPLOIT ✓HIGH 7.5EPSS 2.93%31 October 2006
CVE-2006-5623PHP remote file inclusion vulnerability in ip.inc.php in Electronic Engineering Tool (EE Tool) 0.4-1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cgipath parameter.EXPLOIT ✓HIGH 7.5EPSS 2.49%31 October 2006
CVE-2006-5622SQL injection vulnerability in picmgr.php in Coppermine Photo Gallery 1.4.9 allows remote attackers to execute arbitrary SQL commands via the aid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.18%31 October 2006
CVE-2006-5621PHP remote file inclusion vulnerability in end.php in ask_rave 0.9 PR, and other versions before 0.9b, allows remote attackers to execute arbitrary PHP code via a URL in the footfile parameter.EXPLOIT ✓HIGH 7.5EPSS 2.83%31 October 2006
CVE-2006-5620PHP remote file inclusion vulnerability in include/menu_builder.php in MiniBILL 2006-10-10 (1.2.3) and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the config[page_dir] parameter, a…EXPLOIT ✓HIGH 7.5EPSS 3.77%31 October 2006

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.