Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,903 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026
25,049 results · page 381 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-4720 | PHP remote file inclusion vulnerability in random2.php in mcGalleryPRO 2006 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.54% | 12 September 2006 |
| CVE-2006-4719 | Multiple PHP remote file inclusion vulnerabilities in MyABraCaDaWeb 1.0.3, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the base parameter to (1) index.php or (2) pop.php. | EXPLOIT ✓MEDIUM 5.1EPSS 3.02% | 12 September 2006 |
| CVE-2006-4716 | PHP remote file inclusion vulnerability in demarrage.php in Fire Soft Board (FSB) RC3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the racine parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.49% | 12 September 2006 |
| CVE-2006-4715 | SQL injection vulnerability in pdf_version.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.56% | 12 September 2006 |
| CVE-2006-4714 | PHP remote file inclusion vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the classified_path… | EXPLOIT ×2 ✓MEDIUM 5.1EPSS 3.40% | 12 September 2006 |
| CVE-2006-4713 | PHP remote file inclusion vulnerability in config.php in PSYWERKS PUMA 1.0 RC2 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.27% | 12 September 2006 |
| CVE-2006-4709 | SQL injection vulnerability in topic.php in Vikingboard 0.1b allows remote attackers to execute arbitrary SQL commands via the s parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 1.04% | 12 September 2006 |
| CVE-2006-4708 | Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1b allow remote attackers to inject arbitrary web script or HTML via the (1) act parameter in (a) help.php and (b) search.php, and the (2) p parameter in report.php. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 1.93% | 12 September 2006 |
| CVE-2006-4625 | PHP 4.x up to 4.4.4 and PHP 5 up to 5.1.6 allows local users to bypass certain Apache HTTP Server httpd.conf options, such as safe_mode and open_basedir, via the ini_restore function, which resets the values to their php.ini (Master Value) defaults. | EXPLOIT ✓LOW 3.6EPSS 1.19% | 12 September 2006 |
| CVE-2006-4681 | Directory traversal vulnerability in Redirect.bat in IBM Director before 5.10 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.59% | 11 September 2006 |
| CVE-2006-4678 | PHP remote file inclusion vulnerability in News Evolution 3.0.3 allows remote attackers to execute arbitrary PHP code via the _NE[AbsPath] parameter in (1) install.php and (2) migrateNE2toNE3.php. | EXPLOIT ✓HIGH 7.5EPSS 2.47% | 11 September 2006 |
| CVE-2006-4676 | TIBCO RendezVous 7.4.11 and earlier logs base64-encoded usernames and passwords in rvrd.db, which allows local users to obtain sensitive information by decoding the log file. | EXPLOIT ✓LOW 1.2EPSS 0.73% | 11 September 2006 |
| CVE-2006-4673 | Global variable overwrite vulnerability in maincore.php in PHP-Fusion 6.01.4 and earlier uses the extract function on the superglobals, which allows remote attackers to conduct SQL injection attacks via the _SERVER[REMOTE_ADDR] parameter to news.php. | EXPLOIT ✓LOW 2.6EPSS 1.15% | 11 September 2006 |
| CVE-2006-4672 | PHP remote file inclusion vulnerability in profitCode ppalCart 2.5 EE, possibly a component of PayProCart, allows remote attackers to execute arbitrary PHP code via a URL in the (1) proMod parameter to (a) index.php, or the (2) docroot parameter to (b)… | EXPLOIT ✓HIGH 7.5EPSS 3.26% | 11 September 2006 |
| CVE-2006-4671 | PHP remote file inclusion vulnerability in headlines.php in Fantastic News 2.1.4, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[script_path] parameter, a different vector than CVE-2006-1154. | EXPLOIT ✓MEDIUM 6.8EPSS 2.75% | 11 September 2006 |
| CVE-2006-4670 | Multiple PHP remote file inclusion vulnerabilities in PhotoKorn Gallery 1.52 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the dir_path parameter in (1) includes/cart.inc.php or (2) extras/ext_cats.php. | EXPLOIT ✓HIGH 7.5EPSS 10.3% | 9 September 2006 |
| CVE-2006-4669 | PHP remote file inclusion vulnerability in admin/system/include.php in Somery 0.4.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the skindir parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 3.05% | 9 September 2006 |
| CVE-2006-4668 | Cross-site scripting (XSS) vulnerability in index.php in Rob Hensley AckerTodo 4.0 allows remote attackers to inject arbitrary web script or HTML via the task_id parameter in an edit_task command. | EXPLOIT ✓MEDIUM 4.3EPSS 2.04% | 9 September 2006 |
| CVE-2006-4666 | Multiple PHP remote file inclusion vulnerabilities in Stefan Ernst Newsscript (aka WM-News) 0.5 beta allow remote attackers to execute arbitrary PHP code via a URL in the (1) ide parameter in (a) article.php; or the (2) pwfile parameter in (b)… | EXPLOIT ×2 ✓HIGH 7.5EPSS 4.44% | 9 September 2006 |
| CVE-2006-4664 | PHP remote file inclusion vulnerability in includes/functions_portal.php in Premod Shadow 2.7.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 3.36% | 9 September 2006 |
| CVE-2006-4656 | PHP remote file inclusion vulnerability in admin/editeur/spaw_control.class.php in Web Provence SL_Site 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 10.9% | 9 September 2006 |
| CVE-2006-4655 | Buffer overflow in the Strcmp function in the XKEYBOARD extension in X Window System X11R6.4 and earlier, as used in SCO UnixWare 7.1.3 and Sun Solaris 8 through 10, allows local users to gain privileges via a long _XKB_CHARSET environment variable value. | EXPLOIT ×4 ✓MEDIUM 4.6EPSS 0.90% | 9 September 2006 |
| CVE-2006-4654 | Format string vulnerability in Easy Address Book Web Server 1.2 allows remote attackers to cause a denial of service (crash) or "compromise the server" via encoded format string specifiers in the query string. | EXPLOIT ✓MEDIUM 5.1EPSS 2.12% | 9 September 2006 |
| CVE-2006-4294 | Directory traversal vulnerability in viewfile in TWiki 4.0.0 through 4.0.4 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.85% | 9 September 2006 |
| CVE-2006-4649 | PHP remote file inclusion vulnerability in bp_news.php in BinGo News (BP News) 3.01 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the bnrep parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.44% | 8 September 2006 |
| CVE-2006-4648 | PHP remote file inclusion vulnerability in bp_ncom.php in BinGo News (BP News) 3.01 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the bnrep parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.36% | 8 September 2006 |
| CVE-2006-4647 | PHP remote file inclusion vulnerability in news.php in Sponge News 2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sndir parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.19% | 8 September 2006 |
| CVE-2006-4645 | PHP remote file inclusion vulnerability in akarru.gui/main_content.php in Akarru Social BookMarking Engine 0.4.3.34 and earlier, and possibly 0.4.4.120, allows remote attackers to execute arbitrary PHP code via a URL in the bm_content parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.29% | 8 September 2006 |
| CVE-2006-4644 | PHP remote file inclusion vulnerability in modules/home.module.php in phpFullAnnu 5.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the repmod parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.77% | 8 September 2006 |
| CVE-2006-4643 | SQL injection vulnerability in consult/joueurs.php in Uni-Vert PhpLeague 0.82 and earlier allows remote attackers to execute arbitrary SQL commands via the id_joueur parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.10% | 8 September 2006 |
| CVE-2006-4641 | SQL injection vulnerability in kategori.asp in Muratsoft Haber Portal 3.6 allows remote attackers to execute arbitrary SQL commands via the kat parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.13% | 8 September 2006 |
| CVE-2006-4379 | Stack-based buffer overflow in the SMTP Daemon in Ipswitch Collaboration 2006 Suite Premium and Standard Editions, IMail, IMail Plus, and IMail Secure allows remote attackers to execute arbitrary code via a long string located after an '@' character and… | EXPLOIT ×3 ✓HIGH 7.5EPSS 61.1% | 8 September 2006 |
| CVE-2006-4638 | PHP remote file inclusion vulnerability in article.php in ACGV News 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the PathNews parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 3.02% | 8 September 2006 |
| CVE-2006-4637 | Multiple PHP remote file inclusion vulnerabilities in ACGV News 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the PathNews parameter in (1) header.php or (2) news.php. | EXPLOIT ✓MEDIUM 5.1EPSS 3.01% | 8 September 2006 |
| CVE-2006-4636 | Directory traversal vulnerability in SZEWO PhpCommander 3.0 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Directory parameter, as demonstrated by parameter values naming Apache… | EXPLOIT ✓HIGH 7.5EPSS 2.63% | 8 September 2006 |
| CVE-2006-4634 | Cross-site scripting (XSS) vulnerability in index.php in VBZooM allows remote attackers to inject arbitrary web script or HTML via the UserID parameter, a different vector than CVE-2006-1133 and CVE-2005-2441. | EXPLOIT ✓MEDIUM 4.3EPSS 1.68% | 8 September 2006 |
| CVE-2006-4633 | index.php in SoftBB 0.1, and possibly earlier, allows remote attackers to obtain the installation path via a null or invalid page[] parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 3.48% | 8 September 2006 |
| CVE-2006-4632 | Multiple SQL injection vulnerabilities in SoftBB 0.1, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) groupe parameter in addmembre.php and the (2) select parameter in moveto.php. | EXPLOIT ✓HIGH 7.5EPSS 4.03% | 8 September 2006 |
| CVE-2006-4631 | Direct static code injection vulnerability in admin/save_opt.php in SoftBB 0.1, and possibly earlier, allows remote authenticated users to upload and execute arbitrary PHP code via the cache_forum parameter, which saves the code to info_options.php,… | EXPLOIT ✓MEDIUM 6.5EPSS 3.02% | 8 September 2006 |
| CVE-2006-4630 | PHP remote file inclusion vulnerability in jscript.php in Sky GUNNING MySpeach 3.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the my_ms[root] parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.39% | 8 September 2006 |
| CVE-2006-4629 | PHP remote file inclusion vulnerability in affichage/commentaires.php in C-News.fr C-News 1.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.39% | 8 September 2006 |
| CVE-2006-4622 | PHP remote file inclusion vulnerability in annonce.php in AnnonceV (aka annoncesV) 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.37% | 7 September 2006 |
| CVE-2006-4612 | SQL injection vulnerability in ReplyNew.asp in ZIXForum 1.12 allows remote attackers to execute arbitrary SQL commands via the RepId parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.26% | 7 September 2006 |
| CVE-2006-4611 | Buffer overflow in the _tor_resolve function in dsocks.c in dsocks before 1.4 allows remote attackers to execute arbitrary code via unspecified vectors, possibly involving a long node name. | EXPLOIT ✓HIGH 7.5EPSS 7.84% | 7 September 2006 |
| CVE-2006-4610 | PHP remote file inclusion vulnerability in index.php in GrapAgenda 0.11 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the page parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 4.14% | 7 September 2006 |
| CVE-2006-4609 | Multiple PHP remote file inclusion vulnerabilities in the Content Management module ("Content manager") for PHProjekt 0.6.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via the path_pre parameter in (1)… | EXPLOIT ✓MEDIUM 5.1EPSS 2.97% | 7 September 2006 |
| CVE-2006-4608 | Multiple cross-site scripting (XSS) vulnerabilities in Longino Jacome php-Revista 1.1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) cadena parameter in busqueda.php and the (2) email parameter in lista.php. | EXPLOIT ✓MEDIUM 6.8EPSS 4.88% | 7 September 2006 |
| CVE-2006-4607 | admin/index.php in Longino Jacome php-Revista 1.1.2 allows remote attackers to bypass authentication controls by setting the ID_ADMIN and SUPER_ADMIN parameters to 1. | EXPLOIT ✓HIGH 7.5EPSS 3.51% | 7 September 2006 |
| CVE-2006-4606 | Multiple SQL injection vulnerabilities in Longino Jacome php-Revista 1.1.2 allow remote attackers to execute arbitrary SQL commands via the (1) id_temas parameter in busqueda_tema.php, the (2) cadena parameter in busqueda.php, the (3) id_autor parameter… | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.52% | 7 September 2006 |
| CVE-2006-4605 | PHP remote file inclusion vulnerability in index.php in Longino Jacome php-Revista 1.1.2 allows remote attackers to execute arbitrary PHP code via the adodb parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 3.84% | 7 September 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.