Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,899 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026
25,049 results · page 375 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-5391 | Xfire 1.64 and earlier allows remote attackers to cause a denial of service (client application crash) via a long string to UDP port 25777. | EXPLOIT ✓MEDIUM 5.0EPSS 3.09% | 18 October 2006 |
| CVE-2006-5390 | PHP remote file inclusion vulnerability in includes/functions_mod_user.php in the ACP User Registration (MMW) 1.00 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.94% | 18 October 2006 |
| CVE-2006-5388 | SQL injection vulnerability in index.php in WebSPELL 4.01.01 and earlier allows remote attackers to execute arbitrary SQL commands via the getsquad parameter, a different vector than CVE-2006-4783. | EXPLOIT ✓HIGH 7.5EPSS 1.11% | 18 October 2006 |
| CVE-2006-5387 | PHP remote file inclusion vulnerability in mods/iai/includes/constants.php in the PlusXL 20_272 and earlier phpBB module allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.29% | 18 October 2006 |
| CVE-2006-5386 | PHP remote file inclusion vulnerability in process.php in NuralStorm Webmail 0.98b and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the DEFAULT_SKIN parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.66% | 18 October 2006 |
| CVE-2006-5385 | PHP remote file inclusion vulnerability in admin/admin_spam.php in the SpamOborona 1.0b and earlier phpBB module allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.29% | 18 October 2006 |
| CVE-2006-5384 | PHP remote file inclusion vulnerability in modification/SendAlertEmail.php in CDS Software Consortium CDS Agenda 4.2.9 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AGE parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.77% | 18 October 2006 |
| CVE-2006-5383 | SQL injection vulnerability in comadd.php in Def-Blog 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the article parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.11% | 18 October 2006 |
| CVE-2006-5379 | The accelerated rendering functionality of NVIDIA Binary Graphics Driver (binary blob driver) For Linux v8774 and v8762, and probably on other operating systems, allows local and remote attackers to execute arbitrary code via a large width value in a… | EXPLOIT ✓HIGH 7.5EPSS 27.4% | 18 October 2006 |
| CVE-2006-5320 | Directory traversal vulnerability in getimg.php in Album Photo Sans Nom 1.6 allows remote attackers to read arbitrary files via the img parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 4.06% | 17 October 2006 |
| CVE-2006-5319 | Directory traversal vulnerability in redir.php in Foafgen 0.3 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.56% | 17 October 2006 |
| CVE-2006-5318 | PHP remote file inclusion vulnerability in index.php in Nayco JASmine (aka Jasmine-Web) allows remote attackers to execute arbitrary PHP code via an FTP URL in the section parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.29% | 17 October 2006 |
| CVE-2006-5317 | PHP remote file inclusion vulnerability in index.php in eboli allows remote attackers to execute arbitrary PHP code via a URL in the contentSpecial parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.17% | 17 October 2006 |
| CVE-2006-5316 | registroTL stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for /usuarios.dat. | EXPLOIT ✓HIGH 7.8EPSS 2.81% | 17 October 2006 |
| CVE-2006-5315 | PHP remote file inclusion vulnerability in main.php in registroTL allows remote attackers to execute arbitrary PHP code via an ftp:// URL in the page parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.17% | 17 October 2006 |
| CVE-2006-5314 | PHP remote file inclusion vulnerability in ftag.php in TribunaLibre 3.12 Beta allows remote attackers to execute arbitrary PHP code via a URL in the mostrar parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.17% | 17 October 2006 |
| CVE-2006-5312 | PHP remote file inclusion vulnerability in shoutbox.php in the Ajax Shoutbox 0.0.5 and earlier module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.22% | 17 October 2006 |
| CVE-2006-5311 | PHP remote file inclusion vulnerability in includes/archive/archive_topic.php in Buzlas 2006-1 Full allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.53% | 17 October 2006 |
| CVE-2006-5310 | PHP remote file inclusion vulnerability in common/visiteurs/include/menus.inc.php in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and possibly other products, allows remote attackers to execute arbitrary PHP… | EXPLOIT ✓MEDIUM 6.8EPSS 5.98% | 17 October 2006 |
| CVE-2006-5309 | PHP remote file inclusion vulnerability in language/lang_french/lang_prillian_faq.php in the Prillian French 0.8.0 and earlier module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.29% | 17 October 2006 |
| CVE-2006-5308 | Multiple PHP remote file inclusion vulnerabilities in Open Conference Systems (OCS) before 1.1.6 allow remote attackers to execute arbitrary PHP code via a URL in the fullpath parameter in (1) include/theme.inc.php or (2) include/footer.inc.php. | EXPLOIT ✓HIGH 7.5EPSS 6.78% | 17 October 2006 |
| CVE-2006-5307 | Multiple PHP remote file inclusion vulnerabilities in AFGB GUESTBOOK 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the Htmls parameter in (1) add.php, (2) admin.php, (3) look.php, or (4) re.php. | EXPLOIT ✓HIGH 7.5EPSS 9.68% | 17 October 2006 |
| CVE-2006-5306 | Multiple PHP remote file inclusion vulnerabilities in the Journals System module 1.0.2 (RC2) and earlier for phpBB allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) includes/journals_delete.php, (2)… | EXPLOIT ✓MEDIUM 6.8EPSS 3.05% | 17 October 2006 |
| CVE-2006-5305 | PHP remote file inclusion vulnerability in lat2cyr.php in the lat2cyr 1.0.1 and earlier phpbb module allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 3.12% | 17 October 2006 |
| CVE-2006-5304 | PHP remote file inclusion vulnerability in inc/settings.php in IncCMS Core 1.0.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.19% | 17 October 2006 |
| CVE-2006-5302 | Multiple PHP remote file inclusion vulnerabilities in Redaction System 1.0000 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lang_prefix parameter to (a) conn.php, (b) sesscheck.php, (c) wap/conn.php, or (d) wap/sesscheck.php,… | EXPLOIT ✓HIGH 7.5EPSS 15.6% | 17 October 2006 |
| CVE-2006-5301 | PHP remote file inclusion vulnerability in includes/antispam.php in the SpamBlockerMODv 1.0.2 and earlier module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 5.53% | 17 October 2006 |
| CVE-2006-5295 | Unspecified vulnerability in ClamAV before 0.88.5 allows remote attackers to cause a denial of service (scanning service crash) via a crafted Compressed HTML Help (CHM) file that causes ClamAV to "read an invalid memory location." | EXPLOIT ✓MEDIUM 5.0EPSS 11.4% | 16 October 2006 |
| CVE-2006-5210 | Directory traversal vulnerability in IronWebMail before 6.1.1 HotFix-17 allows remote attackers to read arbitrary files via a GET request to the IM_FILE identifier with double-url-encoded "../" sequences ("%252e%252e/"). | EXPLOIT ✓MEDIUM 5.0EPSS 4.28% | 16 October 2006 |
| CVE-2006-4182 | Integer overflow in ClamAV 0.88.1 and 0.88.4, and other versions before 0.88.5, allows remote attackers to cause a denial of service (scanning service crash) and execute arbitrary code via a crafted Portable Executable (PE) file that leads to a… | EXPLOIT ✓HIGH 7.5EPSS 21.4% | 16 October 2006 |
| CVE-2006-5296 | PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and application crash) via a crafted… | EXPLOIT ✓MEDIUM 4.3EPSS 27.0% | 16 October 2006 |
| CVE-2006-5294 | Cross-site scripting (XSS) vulnerability in index.php in phplist before 2.10.3 allows remote attackers to inject arbitrary web script or HTML via the unsubscribeemail parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 2.52% | 16 October 2006 |
| CVE-2006-5292 | PHP remote file inclusion vulnerability in photo_comment.php in Exhibit Engine 1.5 RC 4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the toroot parameter. | EXPLOIT ✓HIGH 7.5EPSS 6.28% | 16 October 2006 |
| CVE-2006-5291 | PHP remote file inclusion vulnerability in admin/includes/spaw/spaw_control.class.php in Download-Engine 1.4.2 allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 4.69% | 16 October 2006 |
| CVE-2006-5289 | Multiple PHP remote file inclusion vulnerabilities in Vtiger CRM 4.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the calpath parameter to (1) modules/Calendar/admin/update.php, (2) modules/Calendar/admin/scheme.php, or… | EXPLOIT ✓HIGH 7.5EPSS 7.89% | 13 October 2006 |
| CVE-2006-5284 | PHP remote file inclusion vulnerability in auth/phpbb.inc.php in Shen Cheng-Da PHP News Reader (aka pnews) 2.6.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CFG[auth_phpbb_path] parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 2.63% | 13 October 2006 |
| CVE-2006-5283 | PHP remote file inclusion vulnerability in ftag.php in Minichat 6.0 allows remote attackers to execute arbitrary PHP code via a URL in the mostrar parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.95% | 13 October 2006 |
| CVE-2006-5282 | Multiple PHP remote file inclusion vulnerabilities in SH-News 3.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the scriptpath parameter to (1) report.php, (2) archive.php, (3) comments.php, (4) init.php, or (5) news.php. | EXPLOIT ✓HIGH 7.5EPSS 3.39% | 13 October 2006 |
| CVE-2006-5281 | PHP remote file inclusion vulnerability in naboard_pnr.php in n@board 3.1.9e and earlier allows remote attackers to execute arbitrary PHP code via a URL in the skin parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.50% | 13 October 2006 |
| CVE-2006-5263 | Directory traversal vulnerability in templates/header.php3 in phpMyAgenda 3.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.63% | 12 October 2006 |
| CVE-2006-5262 | CRLF injection vulnerability in lib/session.php in Hastymail 1.5 and earlier before 20061008 allows remote authenticated users to send arbitrary IMAP commands via a CRLF sequence in a mailbox name. | EXPLOIT ✓MEDIUM 6.5EPSS 2.57% | 12 October 2006 |
| CVE-2006-5261 | Multiple PHP remote file inclusion vulnerabilities in PHPMyNews 1.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the cfg_include_dir parameter in (1) disp_form.php3, (2) disp_smileys.php3, (3) little_news.php3, and (4)… | EXPLOIT ✓HIGH 7.5EPSS 2.76% | 12 October 2006 |
| CVE-2006-5259 | PHP remote file inclusion vulnerability in param_editor.php in Compteur 2 allows remote attackers to execute arbitrary PHP code via a URL in the folder parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.29% | 12 October 2006 |
| CVE-2006-5257 | PHP remote file inclusion vulnerability in modules/forum/include/config.php in Ciamos Content Management System (CMS) 0.9.6b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the module_cache_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.49% | 12 October 2006 |
| CVE-2006-5256 | PHP remote file inclusion vulnerability in claroline/inc/lib/import.lib.php in Claroline 1.8.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the includePath parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.54% | 12 October 2006 |
| CVE-2006-5254 | PHP remote file inclusion vulnerability in registration_detailed.inc.php in Mark Van Bellen Detailed User Registration (com_registration_detailed), aka regdetailed, 4.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the… | EXPLOIT ✓HIGH 7.5EPSS 2.49% | 12 October 2006 |
| CVE-2006-5251 | PHP remote file inclusion vulnerability in index.php in Deep CMS 2.0a allows remote attackers to execute arbitrary PHP code via a URL in the ConfigDir parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.16% | 12 October 2006 |
| CVE-2006-5250 | PHP remote file inclusion vulnerability in lib/googlesearch/GoogleSearch.php in BlueShoes 4.6_public and earlier allows remote attackers to execute arbitrary PHP code via a URL in the APP[path][lib] parameter, a different vector than CVE-2006-2864. | EXPLOIT ✓MEDIUM 5.1EPSS 6.97% | 12 October 2006 |
| CVE-2006-5249 | PHP remote file inclusion vulnerability in tagmin/delTagUser.php in TagIt! | EXPLOIT ✓HIGH 7.5EPSS 3.18% | 12 October 2006 |
| CVE-2006-5244 | Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Blog 1.4 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the doc_directory parameter in (1) down_stat.php, (2) file.php,… | EXPLOIT ×2 ✓MEDIUM 5.1EPSS 3.65% | 12 October 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.