SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-29 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,899 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026

25,049 results · page 377 of 501

CVESummaryPriorityPublished
CVE-2006-5154PHP remote file inclusion vulnerability in cp/sig.php in DeluxeBB 1.09 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the templatefolder parameter.EXPLOIT ✓HIGH 7.5EPSS 3.37%5 October 2006
CVE-2006-5148Multiple PHP remote file inclusion vulnerabilities in Forum82 2.5.2b and earlier allow remote attackers to execute arbitrary PHP code via a URL in the repertorylevel parameter including scripts in /forum/ including (1) search.php, (2) message.php, (3)…EXPLOIT ✓HIGH 7.5EPSS 3.26%5 October 2006
CVE-2006-5147PHP remote file inclusion vulnerability in wamp_dir/setup/yesno.phtml in VAMP Webmail 2.0beta1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the no_url parameter.EXPLOIT ✓HIGH 7.5EPSS 3.25%5 October 2006
CVE-2006-5146Multiple cross-site scripting (XSS) vulnerabilities in Yblog allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in (a) funk.php, or the (2) action parameter in (b) tem.php and (c) uss.php.EXPLOIT ×3 ✓MEDIUM 6.8EPSS 1.93%5 October 2006
CVE-2006-5145Multiple SQL injection vulnerabilities in OlateDownload 3.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) page parameter in details.php or the (2) query parameter in search.php.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.12%5 October 2006
CVE-2006-5141PHP remote file inclusion vulnerability in script.php in Kevin A.EXPLOIT ✓HIGH 7.5EPSS 2.13%3 October 2006
CVE-2006-5140SQL injection vulnerability in display.php in Lappy512 PHP Krazy Image Host Script (phpkimagehost) 0.7a allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.11%3 October 2006
CVE-2006-5137Multiple direct static code injection vulnerabilities in Groupee UBB.threads 6.5.1.1 allow remote attackers to (1) inject PHP code via a theme[] array parameter to admin/doedittheme.php, which is injected into includes/theme.inc.php; (2) inject PHP code…EXPLOIT ✓MEDIUM 5.1EPSS 2.20%3 October 2006
CVE-2006-5135Multiple PHP remote file inclusion vulnerabilities in A-Blog 2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) open_box, (2) middle_box, and (3) close_box parameters in (a) sources/myaccount.php; the (4) navigation_end…EXPLOIT ✓HIGH 7.5EPSS 2.49%3 October 2006
CVE-2006-5126PHP remote file inclusion vulnerability in index.php in John Himmelman (aka DaRk2k1) PowerPortal 1.3a allows remote attackers to execute arbitrary PHP code via a URL in the file_name[] parameter.EXPLOIT ✓HIGH 7.5EPSS 2.49%3 October 2006
CVE-2006-5125Directory traversal vulnerability in window.php, possibly used by home.php, in Joshua Muheim phpMyWebmin 1.0 allows remote attackers to obtain sensitive information via a directory name in the target parameter, which triggers a directory listing through…EXPLOIT ×2 ✓MEDIUM 5.0EPSS 3.66%3 October 2006
CVE-2006-5124Multiple PHP remote file inclusion vulnerabilities in Joshua Muheim phpMyWebmin 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) target and (2) action parameters in window.php, and possibly the (3) target parameter in…EXPLOIT ×2 ✓HIGH 7.5EPSS 3.46%3 October 2006
CVE-2006-5120Multiple cross-site scripting (XSS) vulnerabilities in Scott Metoyer Red Mombin 0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) index.php and (2) process_login.php.EXPLOIT ×2 ✓MEDIUM 4.0EPSS 1.90%3 October 2006
CVE-2006-5118PHP remote file inclusion vulnerability in index.php3 in the PDD package for PHPSelect Web Development Division allows remote attackers to execute arbitrary PHP code via a URL in the Application_Root parameter.EXPLOIT ✓HIGH 7.5EPSS 2.55%3 October 2006
CVE-2006-5115Directory traversal vulnerability in kgcall.php in KGB 1.87 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 5.1EPSS 2.43%3 October 2006
CVE-2006-5114Multiple cross-site scripting (XSS) vulnerabilities in wgate in SAP Internet Transaction Server (ITS) 6.1 and 6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) ~urlmime or (2) ~command parameter, different vectors than…EXPLOIT ✓MEDIUM 6.8EPSS 2.46%3 October 2006
CVE-2006-5112Buffer overflow in InterVations NaviCOPA Web Server 2.01 allows remote attackers to execute arbitrary code via a long HTTP GET request.EXPLOIT ×3 ✓HIGH 7.5EPSS 66.9%3 October 2006
CVE-2006-5108Multiple cross-site scripting (XSS) vulnerabilities in Devellion CubeCart 2.0.x allow remote attackers to inject arbitrary web script or HTML via the order_id parameter in (1) admin/print_order.php and (2) view_order.php; the (3) site_url and (4)…EXPLOIT ×6 ✓MEDIUM 6.8EPSS 6.07%3 October 2006
CVE-2006-5107Multiple SQL injection vulnerabilities in Devellion CubeCart 2.0.x allow remote attackers to execute arbitrary SQL commands via (1) the user_name parameter in admin/forgot_pass.php, (2) the order_id parameter in view_order.php, (3) the view_doc…EXPLOIT ×4 ✓HIGH 7.5EPSS 1.12%3 October 2006
CVE-2006-5104SQL injection vulnerability in global.php in Jelsoft vBulletin 2.x allows remote attackers to execute arbitrary SQL commands via the templatesused parameter.EXPLOIT ✓HIGH 7.5EPSS 1.11%3 October 2006
CVE-2006-5103PHP remote file inclusion vulnerability in admin/index2.php in bbsNew 2.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the "right" parameter.EXPLOIT ✓HIGH 7.5EPSS 2.56%3 October 2006
CVE-2006-5102PHP remote file inclusion vulnerability in include/editfunc.inc.php in Sebastian Baumann and Philipp Wolfer Newswriter SW 1.42 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the NWCONF_SYSTEM[server_path] parameter.EXPLOIT ✓HIGH 7.5EPSS 3.02%3 October 2006
CVE-2006-5100PHP remote file inclusion vulnerability in parse/parser.php in WEB//NEWS (aka webnews) 1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the WN_BASEDIR parameter.EXPLOIT ✓HIGH 7.5EPSS 3.77%3 October 2006
CVE-2006-4392The Mach kernel, as used in operating systems including (1) Mac OS X 10.4 through 10.4.7 and (2) OpenStep before 4.2, allows local users to gain privileges via a parent process that forces an exception in a setuid child and uses Mach exception ports to…EXPLOIT ×2 ✓HIGH 7.2EPSS 1.58%3 October 2006
CVE-2006-5096Multiple cross-site scripting (XSS) vulnerabilities in index.php in VirtueMart (formerly known as mambo-phpShop) Joomla! eCommerce Edition CMS 1.0.11, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the Itemid…EXPLOIT ✓MEDIUM 6.8EPSS 2.09%29 September 2006
CVE-2006-5094PHP remote file inclusion vulnerability in includes/functions_kb.php in the phpBB XS 2 (Spain version) allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter, a different vector than CVE-2006-4780 or…EXPLOIT ✓MEDIUM 5.1EPSS 3.15%29 September 2006
CVE-2006-5093PHP remote file inclusion vulnerability in index.php in Tagmin Control Center in TagIt!EXPLOIT ✓HIGH 7.5EPSS 3.58%29 September 2006
CVE-2006-5092PHP remote file inclusion vulnerability in navigation/menu.php in A-Blog 2 allows remote attackers to execute arbitrary PHP code via a URL in the navigation_start parameter.EXPLOIT ✓HIGH 7.5EPSS 3.72%29 September 2006
CVE-2006-5090Multiple cross-site scripting (XSS) vulnerabilities in Phoenix Evolution CMS (PECMS) allow remote attackers to inject arbitrary web script or HTML via the (1) mod or (2) action parameters in index.php, or the (3) pageid parameter in…EXPLOIT ×2 ✓MEDIUM 6.8EPSS 1.93%29 September 2006
CVE-2006-5089PHP remote file inclusion vulnerability in mybic_server.php in Jim Plush My-BIC 0.6.5 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.EXPLOIT ✓HIGH 7.5EPSS 2.17%29 September 2006
CVE-2006-5087Multiple PHP remote file inclusion vulnerabilities in evoBB 0.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter in (1) track.php or (2) connect.php.EXPLOIT ✓HIGH 7.5EPSS 3.56%29 September 2006
CVE-2006-5086Blog Pixel Motion 2.1.1 allows remote attackers to change the username and password for the admin user via a direct request to insere_base.php with modified (1) login and (2) pass parameters.EXPLOIT ✓MEDIUM 6.4EPSS 1.24%29 September 2006
CVE-2006-5085Static code injection vulnerability in config.php in Blog Pixel Motion 2.1.1 allows remote attackers to execute arbitrary PHP code via the nom_blog parameter, which is injected into include/variables.php.EXPLOIT ✓HIGH 7.5EPSS 47.3%29 September 2006
CVE-2006-5084Format string vulnerability in the NSRunAlertPanel function in eBay Skype for Mac 1.5.*.79 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed Skype URL, as originally…EXPLOIT ✓HIGH 7.5EPSS 16.1%29 September 2006
CVE-2006-5079PHP remote file inclusion vulnerability in class.mysql.php in Matt Humphrey paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path_to_bt_dir parameter.EXPLOIT ✓HIGH 7.5EPSS 2.73%29 September 2006
CVE-2006-5078PHP remote file inclusion vulnerability in view/general.php in Kristian Niemi Polaring 00.04.03 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _SESSION[dirMain] parameter.EXPLOIT ✓HIGH 7.5EPSS 2.73%29 September 2006
CVE-2006-5077PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Chris Smith Minerva Build 238 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.EXPLOIT ✓MEDIUM 5.1EPSS 3.58%29 September 2006
CVE-2006-5076Multiple PHP remote file inclusion vulnerabilities in OpenConcept Back-End 0.4.5 allow remote attackers to execute arbitrary PHP code via a URL in the includes_path parameter in (1) admin/index.php, (2) Facts.php, or (3) search.php.EXPLOIT ×3 ✓HIGH 7.5EPSS 3.59%29 September 2006
CVE-2006-5074Cross-site scripting (XSS) vulnerability in home.php in PHP Invoice 2.2 allows remote attackers to inject arbitrary web script or HTML via the alert parameter.EXPLOIT ✓MEDIUM 5.1EPSS 1.98%29 September 2006
CVE-2006-4343The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows remote servers to cause a denial of service (client crash) via unknown vectors that trigger a null pointer dereference.EXPLOIT ×2 ✓MEDIUM 4.3EPSS 19.1%28 September 2006
CVE-2006-5070PHP remote file inclusion vulnerability in fsl2/objects/fs_form_links.php in faceStones Personal 2.0.42 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[fsinit][objpath] parameter.EXPLOIT ✓MEDIUM 5.1EPSS 3.02%28 September 2006
CVE-2006-5068PHP remote file inclusion vulnerability in admin/index.php in Brudaswen (1) BrudaNews 1.1 and earlier and (2) BrudaGB 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the o parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 3.84%28 September 2006
CVE-2006-5066Multiple cross-site scripting (XSS) vulnerabilities in DanPHPSupport 0.5, and other versions before 1.0, allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in index.php or the (2) do parameter in admin.php.EXPLOIT ×2 ✓MEDIUM 5.1EPSS 2.07%28 September 2006
CVE-2006-5065PHP remote file inclusion vulnerability in libs/dbmax/mysql.php in ZoomStats 1.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[lib][db][path] parameter.EXPLOIT ✓MEDIUM 5.1EPSS 2.36%28 September 2006
CVE-2006-5064Multiple cross-site scripting (XSS) vulnerabilities in BirdBlog 1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entryid parameter in comment.php, (2) page parameter in index.php, or the (3) uid parameter in…EXPLOIT ×3 ✓MEDIUM 5.1EPSS 2.07%28 September 2006
CVE-2006-5062PHP remote file inclusion vulnerability in templates/pb/language/lang_nl.php in PBLang (PBL) 4.66z and earlier allows remote attackers to execute arbitrary PHP code via a URL in the temppath parameter.EXPLOIT ✓HIGH 7.5EPSS 2.76%28 September 2006
CVE-2006-5061PHP remote file inclusion vulnerability in mcf.php in Advanced-Clan-Script (AVCX) 3.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the content parameter.EXPLOIT ✓HIGH 7.5EPSS 3.19%28 September 2006
CVE-2006-5060Cross-site scripting (XSS) vulnerability in login.php in Jamroom 3.0.16 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the forgot parameter in the forgot mode.EXPLOIT ✓MEDIUM 5.1EPSS 2.18%28 September 2006
CVE-2006-5058Buffer overflow in (1) Call of Duty 1.5b and earlier, (2) Call of Duty United Offensive 1.51b and earlier, and (3) Call of Duty 2 1.3 and earlier allows remote attackers to execute arbitrary code via a long map argument to the "callvote map" command.EXPLOIT ✓HIGH 7.5EPSS 10.1%28 September 2006
CVE-2006-5057Multiple cross-site scripting (XSS) vulnerabilities in Ktools.net PhotoStore allow remote attackers to inject arbitrary web script or HTML via the (1) gid parameter in details.php, or the (2) photogid parameter in view_photog.php.EXPLOIT ×2 ✓MEDIUM 5.1EPSS 2.07%28 September 2006

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.