Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,899 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026
25,049 results · page 378 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-5056 | Cross-site scripting (XSS) vulnerability in index.php in Opial Audio/Video Download Management 1.0 allows remote attackers to inject arbitrary web script or HTML via the destination parameter in the Login view. | EXPLOIT ✓MEDIUM 5.1EPSS 1.98% | 28 September 2006 |
| CVE-2006-5055 | PHP remote file inclusion vulnerability in admin/testing/tests/0004_init_urls.php in syntaxCMS 1.1.1 through 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the init_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.47% | 28 September 2006 |
| CVE-2006-5054 | SQL injection vulnerability in uye/uye_ayrinti.asp in iyzi Forum 1 Beta 2 and earlier allows remote attackers to execute arbitrary SQL commands via the uye_nu parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.16% | 28 September 2006 |
| CVE-2006-5053 | PHP remote file inclusion vulnerability in webnews/template.php in Web-News 1.6.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the content_page parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.19% | 28 September 2006 |
| CVE-2006-5048 | Multiple PHP remote file inclusion vulnerabilities in Security Images (com_securityimages) component 3.0.5 and earlier for Joomla! allow remote attackers to execute arbitrary code via a URL in the mosConfig_absolute_path parameter in (1)… | EXPLOIT ✓MEDIUM 6.8EPSS 15.8% | 27 September 2006 |
| CVE-2006-5045 | Unspecified vulnerability in PollXT component (com_pollxt) 1.22.07 and earlier for Joomla! has unspecified impact and attack vectors, probably related to PHP remote file inclusion in the mosConfig_absolute_path to conf.pollxt.php. | EXPLOIT ✓MEDIUM 6.8EPSS 5.57% | 27 September 2006 |
| CVE-2006-5044 | Unspecified vulnerability in Prince Clan (Princeclan) Chess component (com_pcchess) 0.8 and earlier for Mambo and Joomla! has unspecified impact and attack vectors. | EXPLOIT ✓HIGH 7.5EPSS 2.00% | 27 September 2006 |
| CVE-2006-5043 | Multiple PHP remote file inclusion vulnerabilities in the Joomlaboard Forum Component (com_joomlaboard) before 1.1.2 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the sbp parameter to (1) file_upload.php or (2)… | EXPLOIT ✓MEDIUM 6.8EPSS 4.03% | 27 September 2006 |
| CVE-2006-5034 | Directory traversal vulnerability in Paul Smith Computer Services vCAP 1.9.0 Beta and earlier allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.55% | 27 September 2006 |
| CVE-2006-5033 | Unspecified vulnerability in StoresAndCalendarsList.cgi in Paul Smith Computer Services vCAP 1.9.0 Beta and earlier allows remote attackers to cause a denial of service via the session parameter, possibly related to format string specifiers or malformed… | EXPLOIT ✓MEDIUM 5.0EPSS 3.57% | 27 September 2006 |
| CVE-2006-5032 | PHP remote file inclusion vulnerability in dix.php3 in PHPartenaire 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the url_phpartenaire parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.95% | 27 September 2006 |
| CVE-2006-5031 | Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 7.53% | 27 September 2006 |
| CVE-2006-5030 | SQL injection vulnerability in modules/messages/index.php in exV2 2.0.4.3 and earlier allows remote authenticated users to execute arbitrary SQL commands via the sort parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.11% | 27 September 2006 |
| CVE-2006-5028 | Directory traversal vulnerability in filemanager/filemanager.php in SWsoft Plesk 7.5 Reload and Plesk 7.6 for Microsoft Windows allows remote attackers to list arbitrary directories via a ../ (dot dot slash) in the file parameter in a chdir action. | EXPLOIT ✓MEDIUM 5.0EPSS 46.6% | 27 September 2006 |
| CVE-2006-5023 | SQL injection vulnerability in kategori.asp in xweblog 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the kategori parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.11% | 27 September 2006 |
| CVE-2006-5022 | PHP remote file inclusion vulnerability in includes/global.php in Joshua Wilson pNews System 1.1.0 (aka PowerNews) allows remote attackers to execute arbitrary PHP code via a URL in the nbs parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.49% | 27 September 2006 |
| CVE-2006-5021 | Multiple PHP remote file inclusion vulnerabilities in redgun RedBLoG 0.5 allow remote attackers to execute arbitrary PHP code via a URL in (1) the root parameter in imgen.php, and the root_path parameter in (2) admin/config.php, (3) common.php, and (4)… | EXPLOIT ×4 ✓CRITICAL 9.8EPSS 3.12% | 27 September 2006 |
| CVE-2006-5020 | Multiple PHP remote file inclusion vulnerabilities in SolidState 0.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the base_path parameter in manager/pages/ scripts including (1) AccountsPage.class.php, (2)… | EXPLOIT ✓HIGH 7.5EPSS 17.1% | 27 September 2006 |
| CVE-2006-5019 | Google Mini 4.4.102.M.36 and earlier allows remote attackers to obtain sensitive information via a direct request for /search with an invalid client parameter, which reveals the path in an error message. | EXPLOIT ✓MEDIUM 5.0EPSS 4.06% | 27 September 2006 |
| CVE-2006-5017 | SQL injection vulnerability in admin/all_users.php in Szava Gyula and Csaba Tamas e-Vision CMS, probably 1.0, allows remote attackers to execute arbitrary SQL commands via the from parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.23% | 27 September 2006 |
| CVE-2006-5016 | Unrestricted file upload vulnerability in admin/x_image.php in Szava Gyula and Csaba Tamas e-Vision CMS, probably 1.0, allows remote attackers to upload arbitrary files to the /imagebank directory. | EXPLOIT ✓MEDIUM 5.0EPSS 2.65% | 27 September 2006 |
| CVE-2006-5014 | Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqladmin and (2) hooksadmin. | EXPLOIT ✓HIGH 8.8EPSS 3.97% | 27 September 2006 |
| CVE-2006-4924 | sshd in OpenSSH before 4.4, when using the version 1 SSH protocol, allows remote attackers to cause a denial of service (CPU consumption) via an SSH packet that contains duplicate blocks, which is not properly handled by the CRC compensation attack… | EXPLOIT ✓HIGH 7.8EPSS 37.5% | 27 September 2006 |
| CVE-2006-4993 | Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.4.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the _AMGconfig[cfg_serverpath] parameter in (1) modules/AllMyGuests/signin.php (aka the Nuke module)… | EXPLOIT ✓HIGH 7.5EPSS 3.99% | 26 September 2006 |
| CVE-2006-4992 | Multiple PHP remote file inclusion vulnerabilities in JD-WordPress for Joomla! | EXPLOIT ×3 ✓HIGH 7.5EPSS 8.82% | 26 September 2006 |
| CVE-2006-4989 | Patrick Michaelis Wili-CMS allows remote attackers to obtain sensitive information via a direct request for (1) thumbnail.php, (2) functions/admin/all.php, (3) functions/admin/init_session.php, (4) functions/all.php, and (5) certain files in… | EXPLOIT ✓MEDIUM 5.0EPSS 2.82% | 26 September 2006 |
| CVE-2006-4988 | Multiple cross-site scripting (XSS) vulnerabilities in Patrick Michaelis Wili-CMS allow remote attackers to inject arbitrary web script or HTML via (1) the query string to relocate.php, (2) the globals[pageid] parameter in… | EXPLOIT ✓MEDIUM 4.3EPSS 1.68% | 26 September 2006 |
| CVE-2006-4987 | Multiple PHP remote file inclusion vulnerabilities in Patrick Michaelis Wili-CMS allow remote attackers to execute arbitrary PHP code via a URL in the globals[content_dir] parameter in (1) example-view/templates/article.php, (2)… | EXPLOIT ✓HIGH 7.5EPSS 2.56% | 26 September 2006 |
| CVE-2006-4985 | Multiple cross-site scripting (XSS) vulnerabilities in Grayscale BandSite CMS allow remote attackers to inject arbitrary web script or HTML via (1) the max_file_size_purdy parameter in adminpanel/includes/helpfiles/help_mp3.php, (2) the message_text… | EXPLOIT ×22 ✓MEDIUM 4.3EPSS 1.67% | 26 September 2006 |
| CVE-2006-4178 | Integer signedness error in the i386_set_ldt call in FreeBSD 5.5, and possibly earlier versions down to 5.2, allows local users to cause a denial of service (crash) via unspecified arguments that use negative signed integers to cause the bzero function… | EXPLOIT ✓MEDIUM 4.9EPSS 0.79% | 26 September 2006 |
| CVE-2006-4979 | Direct static code injection vulnerability in cfgphpquiz/install.php in Walter Beschmout PhpQuiz 1.2 and earlier allows remote attackers to inject arbitrary PHP code in config.inc.php via modified configuration settings. | EXPLOIT ✓MEDIUM 5.0EPSS 2.76% | 25 September 2006 |
| CVE-2006-4978 | Multiple SQL injection vulnerabilities in Walter Beschmout PhpQuiz 1.2 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the univers parameter in score.php and (2) the quiz_id parameter in home.php, accessed through the front/… | EXPLOIT ✓HIGH 7.5EPSS 1.79% | 25 September 2006 |
| CVE-2006-4977 | Multiple unrestricted file upload vulnerabilities in (1) back/upload_img.php and (2) admin/upload_img.php in Walter Beschmout PhpQuiz 1.2 and earlier allow remote attackers to upload arbitrary PHP code to the phpquiz/img_quiz folder via the (a) upload,… | EXPLOIT ✓MEDIUM 5.0EPSS 3.00% | 25 September 2006 |
| CVE-2006-4974 | Buffer overflow in Ipswitch WS_FTP Limited Edition (LE) 5.08 allows remote FTP servers to execute arbitrary code via a long response to a PASV command. | EXPLOIT ✓HIGH 7.5EPSS 4.20% | 25 September 2006 |
| CVE-2006-4973 | Cross-site scripting (XSS) vulnerability in Default.aspx in Perpetual Motion Interactive Systems DotNetNuke before 3.3.5, and 4.x before 4.3.5, allows remote attackers to inject arbitrary HTML via the error parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.89% | 25 September 2006 |
| CVE-2006-4970 | PHP remote file inclusion vulnerability in enc/content.php in WAHM E-Commerce Pie Cart Pro allows remote attackers to execute arbitrary PHP code via a URL in the Home_Path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.76% | 25 September 2006 |
| CVE-2006-4969 | Multiple PHP remote file inclusion vulnerabilities in WAHM E-Commerce Pie Cart Pro allow remote attackers to execute arbitrary PHP code via a URL in the Inc_Dir parameter in (1) affiliates.php, (2) orders.php, (3) events.php, (4) index.php, (5)… | EXPLOIT ✓HIGH 7.5EPSS 12.1% | 25 September 2006 |
| CVE-2006-4968 | PHP remote file inclusion vulnerability in includes/functions_admin.php in PNphpBB 1.2g allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 9.73% | 25 September 2006 |
| CVE-2006-4966 | PHP remote file inclusion vulnerability in inc/ifunctions.php in chumpsoft phpQuestionnaire (phpQ) 3.12 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[phpQRootDir] parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.29% | 25 September 2006 |
| CVE-2006-4965 | Apple QuickTime 7.1.3 Player and Plug-In allows remote attackers to execute arbitrary JavaScript code and possibly conduct other attacks via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter that identifies resources… | EXPLOIT ✓MEDIUM 5.0EPSS 13.1% | 25 September 2006 |
| CVE-2006-4963 | Directory traversal vulnerability in index.php in Exponent CMS 0.96.3 allows remote attackers to read and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.4EPSS 7.01% | 23 September 2006 |
| CVE-2006-4962 | Directory traversal vulnerability in pbd_engine.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to read and execute arbitrary local files via a .. | EXPLOIT ×2 ✓MEDIUM 6.4EPSS 3.29% | 23 September 2006 |
| CVE-2006-4961 | SQL injection vulnerability in the GetModuleConfig function in public_includes/pub_kernel/pbd_modules.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.16% | 23 September 2006 |
| CVE-2006-4960 | Cross-site scripting (XSS) vulnerability in index.php Php Blue Dragon 2.9.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the m parameter, which is reflected in an error message resulting from a failed SQL query. | EXPLOIT ✓MEDIUM 6.8EPSS 2.19% | 23 September 2006 |
| CVE-2006-4957 | SQL injection vulnerability in the GetMember function in functions.php in MyReview 1.9.4 allows remote attackers to execute arbitrary SQL commands via the email parameter to Admin.php. | EXPLOIT ✓HIGH 7.5EPSS 1.11% | 23 September 2006 |
| CVE-2006-4956 | Cross-site scripting (XSS) vulnerability in the updateuser servlet in Neon WebMail for Java before 5.08 allows remote attackers to inject arbitrary web script or HTML via the in_name parameter, as used by the Name field. | EXPLOIT ✓MEDIUM 6.8EPSS 4.75% | 23 September 2006 |
| CVE-2006-4955 | Directory traversal vulnerability in the downloadfile servlet in Neon WebMail for Java before 5.08 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 8.09% | 23 September 2006 |
| CVE-2006-4954 | The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote attackers to modify information of arbitrary users, as demonstrated by modifying (1) passwords and (2) permissions, (3) viewing… | EXPLOIT ✓HIGH 7.5EPSS 7.98% | 23 September 2006 |
| CVE-2006-4953 | Multiple SQL injection vulnerabilities in Neon WebMail for Java before 5.08 allow remote attackers to execute arbitrary SQL commands via the (1) adr_sortkey and (2) adr_sortkey_desc parameters in the (a) addrlist servlet, and the (3) sortkey and (4)… | EXPLOIT ×2 ✓HIGH 7.5EPSS 3.76% | 23 September 2006 |
| CVE-2006-4952 | The updatemail servlet in Neon WebMail for Java before 5.08 allows remote attackers to move e-mail messages of arbitrary users between different mail folders, specified by the folderid and tofolderid parameters, via the ID parameter. | EXPLOIT ✓HIGH 7.5EPSS 7.98% | 23 September 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.