Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,899 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026
25,049 results · page 376 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-5243 | Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Doc 1.4 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the doc_directory parameter in (1) down_stat.php, (2) file.php,… | EXPLOIT ✓HIGH 7.5EPSS 3.54% | 12 October 2006 |
| CVE-2006-5241 | Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Gallery 1.4 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the doc_directory parameter in (1) file.php; (2)… | EXPLOIT ✓MEDIUM 5.1EPSS 3.90% | 12 October 2006 |
| CVE-2006-5240 | PHP remote file inclusion vulnerability in engine/require.php in Docmint 2.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the MY_ENV[BASE_ENGINE_LOC] parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 4.14% | 12 October 2006 |
| CVE-2006-5239 | Multiple cross-site scripting (XSS) vulnerabilities in eXpBlog 0.3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the query string (PHP_SELF) in kalender.php or (2) the captcha_session_code parameter in… | EXPLOIT ✓MEDIUM 4.3EPSS 2.08% | 12 October 2006 |
| CVE-2006-4842 | The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary… | EXPLOIT ×6 ✓LOW 3.6EPSS 7.62% | 12 October 2006 |
| CVE-2006-4516 | Integer signedness error in FreeBSD 6.0-RELEASE allows local users to cause a denial of service (memory corruption and kernel panic) via a PT_LWPINFO ptrace command with a large negative data value that satisfies a signed maximum value check but is used… | EXPLOIT ✓MEDIUM 4.9EPSS 0.81% | 12 October 2006 |
| CVE-2006-5236 | SQL injection vulnerability in search.php in 4images 1.7.x allows remote authenticated users to execute arbitrary SQL commands via the search_user parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.08% | 11 October 2006 |
| CVE-2006-5234 | Multiple PHP remote file inclusion vulnerabilities in phpWebSite 0.10.2 allow remote attackers to execute arbitrary PHP code via a URL in the PHPWS_SOURCE_DIR parameter in (1) init.php, (2) users.php, (3) Cookie.php, (4) forms.php, (5) Groups.php, (6)… | EXPLOIT ✓HIGH 7.5EPSS 2.77% | 11 October 2006 |
| CVE-2006-5232 | Multiple PHP remote file inclusion vulnerabilities in iSearch 2.16 allow remote attackers to execute arbitrary PHP code via a URL in the isearch_path parameter in (1) index.php, (2) viewcache.php, (3) sitemap.php, (4) isearch.inc.php, (5)… | EXPLOIT ✓HIGH 7.5EPSS 2.83% | 11 October 2006 |
| CVE-2006-5230 | PHP remote file inclusion vulnerability in forum.php in FreeForum 0.9.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.27% | 11 October 2006 |
| CVE-2006-5229 | OpenSSH portable 4.1 on SUSE Linux, and possibly other platforms and versions, and possibly under limited configurations, allows remote attackers to determine valid usernames via timing discrepancies in which responses take longer for valid usernames… | EXPLOIT ✓LOW 2.6EPSS 58.3% | 10 October 2006 |
| CVE-2006-5228 | Multiple SQL injection vulnerabilities in the Google Gadget login.php (gadget/login.php) in Rob Hensley ackerTodo 4.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) up_login, (2) up_pass, or (3) up_num_tasks parameters. | EXPLOIT ✓HIGH 7.5EPSS 2.07% | 10 October 2006 |
| CVE-2006-5226 | PHP remote file inclusion vulnerability in moteur/moteur.php in Prologin.fr Freenews 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.76% | 10 October 2006 |
| CVE-2006-5224 | PHP remote file inclusion vulnerability in includes/logger_engine.php in Dimitri Seitz Security Suite IP Logger 1.0.0 in dwingmods for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.77% | 10 October 2006 |
| CVE-2006-5223 | PHP remote file inclusion vulnerability in includes/functions_user_viewed_posts.php in the Nivisec User Viewed Posts Tracker module 1.0 and earlier for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 4.12% | 10 October 2006 |
| CVE-2006-5222 | Multiple PHP remote file inclusion vulnerabilities in Dimension of phpBB 0.2.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) includes/themen_portal_mitte.php or (2)… | EXPLOIT ✓HIGH 7.5EPSS 2.77% | 10 October 2006 |
| CVE-2006-5221 | Multiple SQL injection vulnerabilities in Cahier de texte 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) matiere_ID parameter in lire.php or the (2) classe_ID parameter in lire_a_faire.php. | EXPLOIT ✓HIGH 7.5EPSS 1.31% | 10 October 2006 |
| CVE-2006-5220 | Multiple PHP remote file inclusion vulnerabilities in WebYep 1.1.9, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via the webyep_sIncludePath in (1) files in the programm/lib/ directory including (a)… | EXPLOIT ✓MEDIUM 5.1EPSS 14.6% | 10 October 2006 |
| CVE-2006-5219 | SQL injection vulnerability in blog/index.php in the blog module in Moodle 1.6.2 allows remote attackers to execute arbitrary SQL commands via a double-encoded tag parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 2.20% | 10 October 2006 |
| CVE-2006-5217 | SQL injection vulnerability in giris_yap.asp in Emek Portal 2.1 allows remote attackers to execute arbitrary SQL commands by simultaneously injecting into the user name and pass fields in uyegiris.asp, also known as the Kullanici Adi (k_a) and Sifre… | EXPLOIT ✓HIGH 7.5EPSS 1.11% | 10 October 2006 |
| CVE-2006-5216 | Stack-based buffer overflow in Sergey Lyubka Simple HTTPD (shttpd) 1.34 allows remote attackers to execute arbitrary code via a long URI. | EXPLOIT ×2 ✓HIGH 7.5EPSS 63.6% | 10 October 2006 |
| CVE-2006-5209 | PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Admin Topic Action Logging Mod 0.95 and earlier, as used in phpBB 2.0 up to 2.0.21, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path… | EXPLOIT ✓HIGH 7.5EPSS 2.28% | 10 October 2006 |
| CVE-2006-5208 | Multiple SQL injection vulnerabilities in PHP Classifieds 7.1 allow remote attackers to execute arbitrary SQL commands via (1) the catid_search parameter in search.php and (2) the catid parameter in index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.22% | 10 October 2006 |
| CVE-2006-5207 | PHP remote file inclusion vulnerability in images/smileys/smileys_packs.php in phpMyTeam 2.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the smileys_dir parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 3.02% | 10 October 2006 |
| CVE-2006-5206 | SQL injection vulnerability in Invision Gallery 2.0.7 allows remote attackers to execute arbitrary SQL commands via the album parameter in (1) index.php and (2) forum/index.php, when the rate command in the gallery automodule is used. | EXPLOIT ✓HIGH 7.5EPSS 4.33% | 10 October 2006 |
| CVE-2006-5205 | Directory traversal vulnerability in Invision Gallery 2.0.7 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 11.0% | 10 October 2006 |
| CVE-2006-5202 | Linksys WRT54g firmware 1.00.9 does not require credentials when making configuration changes, which allows remote attackers to modify arbitrary configurations via a direct request to Security.tri, as demonstrated using the SecurityMode and layout… | EXPLOIT ✓MEDIUM 5.0EPSS 4.10% | 10 October 2006 |
| CVE-2006-5196 | The HTTP interface in the Motorola SURFboard SB4200 Cable Modem allows remote attackers to cause a denial of service (device crash) via a request with MfcISAPICommand set to SecretProc and a long string in the Secret parameter. | EXPLOIT ✓HIGH 7.8EPSS 7.80% | 10 October 2006 |
| CVE-2006-5193 | PHP remote file inclusion vulnerability in index.php in Josh Schmidt WikyBlog 1.2.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the includeDir parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.56% | 10 October 2006 |
| CVE-2006-5192 | PHP remote file inclusion vulnerability in includes/footer.php in phpGreetz 0.99 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the PHPGREETZ_INCLUDE_DIR parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.31% | 10 October 2006 |
| CVE-2006-5191 | PHP remote file inclusion vulnerability in includes/functions_static_topics.php in the Nivisec Static Topics module for phpBB 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 3.15% | 10 October 2006 |
| CVE-2006-5190 | Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in the (a) banner_manager.php, (b) banner_statistics.php, (c)… | EXPLOIT ×17 ✓MEDIUM 4.3EPSS 7.05% | 10 October 2006 |
| CVE-2006-5189 | PHP remote file inclusion vulnerability in funzioni/lib/show_hlp.php in klinza professional cms 5.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the appl[APPL] parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.49% | 10 October 2006 |
| CVE-2006-5187 | PHP remote file inclusion vulnerability in includes/functions.php in Bulletin Board Ace (BBaCE) 3.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.77% | 10 October 2006 |
| CVE-2006-5186 | PHP remote file inclusion vulnerability in functions.php in phpMyProfiler 0.9.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pmp_rel_path parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 3.99% | 10 October 2006 |
| CVE-2006-5182 | PHP remote file inclusion vulnerability in frontpage.php in Dan Jensen Travelsized CMS 0.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the setup_folder parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.77% | 10 October 2006 |
| CVE-2006-5181 | Multiple PHP remote file inclusion vulnerabilities in Joshua Muheim phpMyWebmin 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the target parameter in (1) change_preferences2.php, (2) create_file.php, (3) upload_local.php, and (4)… | EXPLOIT ✓HIGH 7.5EPSS 2.95% | 10 October 2006 |
| CVE-2006-5180 | PHP remote file inclusion vulnerability in include/main.inc.php in Sebastian Baumann and Philipp Wolfer Newswriter SW 1.42 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the NWCONF_SYSTEM[server_path] parameter, a… | EXPLOIT ✓HIGH 7.5EPSS 2.63% | 10 October 2006 |
| CVE-2006-5178 | Race condition in the symlink function in PHP 5.1.6 and earlier allows local users to bypass the open_basedir restriction by using a combination of symlink, mkdir, and unlink functions to change the file path after the open_basedir check and before the… | EXPLOIT ✓MEDIUM 6.2EPSS 0.66% | 10 October 2006 |
| CVE-2006-5177 | The NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to (1) execute arbitrary code via unspecified vectors involving crafted base64 encoded NTLM Type 3 messages, or (2) cause a denial of service via crafted… | EXPLOIT ✓HIGH 9.3EPSS 7.13% | 10 October 2006 |
| CVE-2006-5143 | Multiple buffer overflows in CA BrightStor ARCserve Backup r11.5 SP1 and earlier, r11.1, and 9.01; BrightStor ARCserve Backup for Windows r11; BrightStor Enterprise Backup 10.5; Server Protection Suite r2; and Business Protection Suite r2 allow remote… | EXPLOIT ×4 ✓HIGH 7.5EPSS 79.5% | 10 October 2006 |
| CVE-2006-4927 | The (a) NAVENG (NAVENG.SYS) and (b) NAVEX15 (NAVEX15.SYS) device drivers 20061.3.0.12 and later, as used in Symantec AntiVirus and security products, allow local users to gain privileges by overwriting critical system addresses using a crafted Irp to… | EXPLOIT ×2 ✓MEDIUM 4.6EPSS 1.75% | 10 October 2006 |
| CVE-2006-4812 | Integer overflow in PHP 5 up to 5.1.6 and 4 before 4.3.0 allows remote attackers to execute arbitrary code via an argument to the unserialize PHP function with a large value for the number of array elements, which triggers the overflow in the Zend… | EXPLOIT ✓HIGH 10.0EPSS 20.4% | 10 October 2006 |
| CVE-2006-5167 | Multiple PHP remote file inclusion vulnerabilities in BasiliX 1.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) BSX_LIBDIR parameter in scripts in /files/ including (a) abook.php3, (b) compose-attach.php3, (c)… | EXPLOIT ✓MEDIUM 5.1EPSS 3.02% | 5 October 2006 |
| CVE-2006-5166 | PHP remote file inclusion vulnerability in functions.php in PHP Web Scripts Easy Banner Free allows remote attackers to execute arbitrary PHP code via a URL in the s[phppath] parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.55% | 5 October 2006 |
| CVE-2006-5165 | PHP remote file inclusion vulnerability in inc/functions.inc.php in Skrypty PPA Gallery 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the config[ppa_root_path] parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 2.63% | 5 October 2006 |
| CVE-2006-5164 | Multiple cross-site scripting (XSS) vulnerabilities in cart.php in Sum Effect Software digiSHOP 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) sortBy or (2) search parameters. | EXPLOIT ✓MEDIUM 6.8EPSS 2.11% | 5 October 2006 |
| CVE-2006-5162 | wininet.dll in Microsoft Internet Explorer 6.0 SP2 and earlier allows remote attackers to cause a denial of service (unhandled exception and crash) via a long Content-Type header, which triggers a stack overflow. | EXPLOIT ✓MEDIUM 5.0EPSS 35.9% | 5 October 2006 |
| CVE-2006-5156 | Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attackers to execute arbitrary code via a request to /spipe/pkg/ with a long source header. | EXPLOIT ×2 ✓HIGH 10.0EPSS 74.0% | 5 October 2006 |
| CVE-2006-5155 | PHP remote file inclusion vulnerability in core/pdf.php in VideoDB 2.2.1 and earlier allows remote attackers to execute arbitrary PHP code via the config[pdf_module] parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.77% | 5 October 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.