Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,893 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026
25,049 results · page 373 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-5618 | Directory traversal vulnerability in script/cat_for_aff.php in Netref 4 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.93% | 31 October 2006 |
| CVE-2006-5615 | PHP remote file inclusion vulnerability in publish.php in Textpattern 1.19, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the txpcfg[txpath] parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.63% | 31 October 2006 |
| CVE-2006-5614 | Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, allows remote attackers to cause a denial of service (svchost.exe crash) via a malformed DNS query, which results in a null pointer… | EXPLOIT ×2 ✓LOW 2.6EPSS 79.6% | 31 October 2006 |
| CVE-2006-5613 | PHP remote file inclusion in Core/core.inc.php in MP3 Streaming DownSampler (mp3SDS) 3.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the fullpath parameter | EXPLOIT ✓HIGH 7.5EPSS 3.39% | 31 October 2006 |
| CVE-2006-5612 | PHP remote file inclusion vulnerability in aide.php3 (aka aide.php) in GestArt beta 1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the aide parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.16% | 31 October 2006 |
| CVE-2006-5609 | Directory traversal vulnerability in dir.php in TorrentFlux 2.1 allows remote attackers to list arbitrary directories via "\.\./" sequences in the dir parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 3.92% | 30 October 2006 |
| CVE-2006-5603 | SQL injection vulnerability in pop_mail.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the RC parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 1.43% | 30 October 2006 |
| CVE-2006-5597 | join.asp in MiniHTTP Web Forum & File Server PowerPack 4.0 allows remote attackers to add or modify arbitrary user accounts via modified (1) frmMailBox and (2) frmUserPass parameters. | EXPLOIT ✓HIGH 7.5EPSS 2.58% | 28 October 2006 |
| CVE-2006-5596 | Directory traversal vulnerability in the SSL server in AEP Smartgate 4.3b allows remote attackers to download arbitrary files via ..\ (dot dot backslash) sequences in an HTTP GET request. | EXPLOIT ✓HIGH 7.5EPSS 2.97% | 28 October 2006 |
| CVE-2006-5590 | PHP remote file inclusion vulnerability in index.php in ArticleBeach Script 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.39% | 27 October 2006 |
| CVE-2006-5588 | Multiple PHP remote file inclusion vulnerabilities in CMS Faethon 2.0 Ultimate and earlier, when register_globals and magic_quotes_gpc are enabled, allow remote attackers to execute arbitrary PHP code via a URL in the mainpath parameter to (1)… | EXPLOIT ✓HIGH 7.5EPSS 2.76% | 27 October 2006 |
| CVE-2006-5587 | Multiple PHP remote file inclusion vulnerabilities in MDweb 1.3 and earlier (Mdweb132-postgres) allow remote attackers to execute arbitrary PHP code via a URL in the chemin_appli parameter in (1) admin/inc/organisations/form_org.inc.php and (2)… | EXPLOIT ✓HIGH 7.5EPSS 2.83% | 27 October 2006 |
| CVE-2006-5571 | Stack-based buffer overflow in /scripts/cruise/cws.exe in CruiseWorks 1.09c and 1.09d allows remote attackers to execute arbitrary code via a long string in the doc parameter. | EXPLOIT ✓HIGH 7.5EPSS 8.28% | 27 October 2006 |
| CVE-2006-5568 | FtpXQ Server 3.0.1 allows remote attackers to cause a denial of service (CPU exhaustion) via a long MKD command. | EXPLOIT ✓MEDIUM 5.0EPSS 3.46% | 27 October 2006 |
| CVE-2006-5567 | Multiple heap-based buffer overflows in AOL Nullsoft WinAmp before 5.31 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) ultravox-max-msg header to the Ultravox protocol handler or (2) unspecified Lyrics3 tags. | EXPLOIT ✓HIGH 9.3EPSS 14.5% | 27 October 2006 |
| CVE-2006-5566 | CRLF injection vulnerability in premium/index.php in Shop-Script allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the (1) links_exchange, (2) news, (3)… | EXPLOIT ✓MEDIUM 5.0EPSS 2.25% | 27 October 2006 |
| CVE-2006-5564 | Cross-site scripting (XSS) vulnerability in user.php in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary web script or HTML via the op parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.66% | 27 October 2006 |
| CVE-2006-5562 | PHP remote file inclusion vulnerability in include/database.php in SourceForge (aka alexandria) 1.0.4 allows remote attackers to execute arbitrary PHP code via the sys_dbtype parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.25% | 27 October 2006 |
| CVE-2006-5561 | SQL injection vulnerability in admincp.php in Discuz! | EXPLOIT ✓HIGH 7.5EPSS 1.11% | 27 October 2006 |
| CVE-2006-5559 | The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when… | EXPLOIT ✓HIGH 9.3EPSS 43.6% | 27 October 2006 |
| CVE-2006-5558 | Format string vulnerability in the swask command in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via format string specifiers in the -s argument. | EXPLOIT ✓HIGH 10.0EPSS 7.71% | 27 October 2006 |
| CVE-2006-5557 | Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via a long -S argument. | EXPLOIT ×2 ✓MEDIUM 4.6EPSS 1.41% | 27 October 2006 |
| CVE-2006-5556 | Buffer overflow in the localtime_r function, and certain other functions, in libc in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via a long TZ environment variable. | EXPLOIT ✓MEDIUM 4.6EPSS 1.33% | 27 October 2006 |
| CVE-2006-5555 | PHP remote file inclusion vulnerability in constantes.inc.php in EPNadmin 0.7 and 0.7.1 allows remote attackers to execute arbitrary PHP code via the langage parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.19% | 26 October 2006 |
| CVE-2006-5554 | Directory traversal vulnerability in index.php in Imageview 5 allows remote attackers to read or execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.58% | 26 October 2006 |
| CVE-2006-5552 | Multiple heap-based buffer overflows in RevilloC MailServer 1.21 and earlier allow remote attackers to cause a denial of service (CPU consumption or application crash) or execute arbitrary code via a long argument to the (1) MAIL FROM or (2) RCPT TO… | EXPLOIT ✓HIGH 7.5EPSS 4.75% | 26 October 2006 |
| CVE-2006-5551 | Stack-based buffer overflow in QK SMTP 3.01 and earlier might allow remote attackers to execute arbitrary code via a long argument to the RCPT TO command. | EXPLOIT ×3 ✓HIGH 7.5EPSS 5.19% | 26 October 2006 |
| CVE-2006-5550 | The kernel in FreeBSD 6.1 and OpenBSD 4.0 allows local users to cause a denial of service via unspecified vectors involving certain ioctl requests to /dev/crypto. | EXPLOIT ✓MEDIUM 4.9EPSS 0.99% | 26 October 2006 |
| CVE-2006-5548 | PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 2.0.0 through 2.1.3 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config][directories][classes]… | EXPLOIT ✓HIGH 7.5EPSS 3.36% | 26 October 2006 |
| CVE-2006-5547 | PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 1.0.0 through 1.0.3 allows remote attackers to execute arbitrary PHP code via a URL in the… | EXPLOIT ✓HIGH 7.5EPSS 3.36% | 26 October 2006 |
| CVE-2006-5546 | PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 1.3.0 through 1.4.1 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config][otscms][directories][classes]… | EXPLOIT ✓MEDIUM 5.1EPSS 3.19% | 26 October 2006 |
| CVE-2006-5543 | PHP remote file inclusion vulnerability in misc/function.php3 in PHP Generator of Object SQL Database (PGOSD), when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 3.10% | 26 October 2006 |
| CVE-2006-5539 | PHP remote file inclusion vulnerability in login/secure.php in UeberProject Management System 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfg[homepath] parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.39% | 26 October 2006 |
| CVE-2006-5536 | Directory traversal vulnerability in cgi-bin/webcm in D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 13.9% | 26 October 2006 |
| CVE-2006-5535 | Multiple cross-site scripting (XSS) vulnerabilities in WebHostManager (WHM) 10.8.0 cPanel 10.9.0 R50 allow remote attackers to inject arbitrary web script or HTML via the (1) theme parameter to scripts/dosetmytheme and the (2) template parameter to… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.94% | 26 October 2006 |
| CVE-2006-5531 | PHP remote file inclusion vulnerability in embedded.php in Ascended Guestbook 1.0.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[path] parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.77% | 26 October 2006 |
| CVE-2006-5530 | Multiple cross-site scripting (XSS) vulnerabilities in Boesch SimpNews before 2.34.01 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) admin/index.php, (2) admin/pwlost.php, and unspecified other files. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.73% | 26 October 2006 |
| CVE-2006-5529 | Cross-site scripting (XSS) vulnerability in smumdadotcom_ascyb_alumni/mod.php in SchoolAlumni Portal 2.26 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search operation in the katalog module. | EXPLOIT ✓MEDIUM 5.1EPSS 1.62% | 26 October 2006 |
| CVE-2006-5528 | Directory traversal vulnerability in mod.php in SchoolAlumni Portal 2.26 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 1.91% | 26 October 2006 |
| CVE-2006-5527 | PHP remote file inclusion vulnerability in lib.editor.inc.php in Intelimen InteliEditor 1.2.x allows remote attackers to execute arbitrary PHP code via a URL in the sys_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.54% | 26 October 2006 |
| CVE-2006-5526 | Multiple PHP remote file inclusion vulnerabilities in Teake Nutma Foing, as modified in Fully Modded phpBB (phpbbfm) 2021.4.40 and earlier, allow remote attackers to execute arbitrary PHP code via a URL in the foing_root_path parameter in (a) faq.php,… | EXPLOIT ✓HIGH 7.5EPSS 2.95% | 26 October 2006 |
| CVE-2006-5525 | Incomplete blacklist vulnerability in mainfile.php in PHP-Nuke 7.9 and earlier allows remote attackers to conduct SQL injection attacks via (1) "/**/UNION " or (2) " UNION/**/" sequences, which are not rejected by the protection mechanism, as… | EXPLOIT ✓MEDIUM 5.1EPSS 1.12% | 26 October 2006 |
| CVE-2006-5524 | Cross-site scripting (XSS) vulnerability in index.php in phplist 2.10.2 allows remote attackers to inject arbitrary web script or HTML via the p parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.09% | 26 October 2006 |
| CVE-2006-5523 | PHP remote file inclusion vulnerability in common.php in EZ-Ticket 0.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the ezt_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.25% | 26 October 2006 |
| CVE-2006-5522 | Multiple PHP remote file inclusion vulnerabilities in Johannes Erdfelt Kawf 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the config parameter in (1) main.php or (2) user/account/main.php. | EXPLOIT ✓HIGH 7.5EPSS 3.25% | 26 October 2006 |
| CVE-2006-5521 | PHP remote file inclusion vulnerability in DNS/RR.php in Net_DNS 0.03 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpdns_basedir parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.17% | 26 October 2006 |
| CVE-2006-5519 | PHP remote file inclusion vulnerability in Savant2/Savant2_Plugin_options.php in the MambWeather 1.8.1 and earlier component for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 5.14% | 26 October 2006 |
| CVE-2006-5518 | Multiple PHP remote file inclusion vulnerabilities in Christopher Fowler (Rhode Island) RSSonate allow remote attackers to execute arbitrary PHP code via a URL in the PROJECT_ROOT parameter to (1) xml2rss.php, (2) config_local.php, (3) rssonate.php, and… | EXPLOIT ✓HIGH 7.5EPSS 10.3% | 26 October 2006 |
| CVE-2006-5517 | Multiple PHP remote file inclusion vulnerabilities in Rhode Island Open Meetings Filing Application (OMFA) allow remote attackers to execute arbitrary PHP code via a URL in the PROJECT_ROOT parameter to (1) editmeetings/session.php, (2)… | EXPLOIT ✓HIGH 7.5EPSS 14.7% | 26 October 2006 |
| CVE-2006-5516 | Multiple cross-site scripting (XSS) vulnerabilities in actions/usersettings.php in WikiNi before 0.4.4 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) email parameters to wakka.php. | EXPLOIT ✓MEDIUM 4.3EPSS 2.62% | 26 October 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.