Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,903 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026
25,049 results · page 382 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-4604 | PHP remote file inclusion vulnerability in LFXlib/access_manager.php in Lanifex Database of Managed Objects (DMO) 2.3 Beta and earlier allows remote attackers to execute arbitrary PHP code via the _incMgr parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.49% | 7 September 2006 |
| CVE-2006-4602 | Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execute arbitrary PHP code via a filepath parameter that contains a filename with a .php extension, which is uploaded to the img/wiki/… | EXPLOIT ×2 ✓HIGH 7.5EPSS 43.7% | 7 September 2006 |
| CVE-2006-4601 | SQL injection vulnerability in index.php in Annuaire 1Two 2.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.27% | 7 September 2006 |
| CVE-2006-4599 | SQL injection vulnerability in aut_verifica.inc.php in Autentificator 2.01 allows remote attackers to execute arbitrary SQL commands via the user parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.11% | 7 September 2006 |
| CVE-2006-4597 | SQL injection vulnerability in devam.asp in ICBlogger 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the YID parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.16% | 7 September 2006 |
| CVE-2006-4596 | PHP remote file inclusion in MyBace Light Skrip, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the (1) hauptverzeichniss parameter in includes/login_check.php and the (2) template_back parameter in… | EXPLOIT ✓MEDIUM 5.1EPSS 3.18% | 7 September 2006 |
| CVE-2006-4594 | Multiple PHP remote file inclusion vulnerabilities in PHP Advanced Transfer Manager (phpAtm) 1.21 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the include_location parameter in (1) confirm.php or (2) login.php. | EXPLOIT ✓HIGH 7.5EPSS 2.49% | 6 September 2006 |
| CVE-2006-4593 | Cross-site scripting (XSS) vulnerability in index.php in SoftBB 0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.92% | 6 September 2006 |
| CVE-2006-4592 | Incomplete blacklist vulnerability in default.asp in 8pixel.net Simple Blog 2.3 and earlier allows remote attackers to conduct SQL injection attacks via ">" characters in the id parameter, which are not filtered by the protection mechanism. | EXPLOIT ✓HIGH 7.5EPSS 1.23% | 6 September 2006 |
| CVE-2006-4591 | Multiple PHP remote file inclusion vulnerabilities in AlstraSoft Template Seller, and possibly AltraSoft Template Seller Pro 3.25, allow remote attackers to execute arbitrary PHP code via a URL in the config[template_path] parameter to (1)… | EXPLOIT ✓HIGH 7.5EPSS 2.53% | 6 September 2006 |
| CVE-2006-4589 | PHP remote file inclusion vulnerability in 0_admin/modules/Wochenkarte/frontend/index.php in DynCMS 6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the x_admindir parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.19% | 6 September 2006 |
| CVE-2006-4586 | The admin panel in Tr Forum 2.0 accepts a username and password hash for authentication, which allows remote authenticated users to perform unauthorized actions, as demonstrated by modifying user settings via the id parameter to… | EXPLOIT ✓MEDIUM 5.5EPSS 3.20% | 6 September 2006 |
| CVE-2006-4584 | Tr Forum 2.0 allows remote attackers to bypass authentication and add an administrative account via the login and password parameters to admin/insert_admin.php. | EXPLOIT ×2 ✓HIGH 7.5EPSS 4.69% | 6 September 2006 |
| CVE-2006-4583 | Multiple PHP remote file inclusion vulnerabilities in FlashChat before 4.6.2 allow remote attackers to execute arbitrary PHP code via a URL in the dir[inc] parameter in (1) inc/cmses/aedatingCMS.php, (2) inc/cmses/aedatingCMS2.php, or (3)… | EXPLOIT ✓HIGH 7.5EPSS 3.73% | 6 September 2006 |
| CVE-2006-4563 | Cross-site scripting (XSS) vulnerability in the MyHeadlines before 4.3.2 module for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the myh_op parameter to modules.php. | EXPLOIT ✓MEDIUM 6.8EPSS 2.09% | 6 September 2006 |
| CVE-2006-4559 | Multiple PHP remote file inclusion vulnerabilities in Yet Another Community System (YACS) CMS 6.6.1 allow remote attackers to execute arbitrary PHP code via a URL in the context[path_to_root] parameter in (1) articles/populate.php, (2)… | EXPLOIT ✓HIGH 7.5EPSS 7.42% | 6 September 2006 |
| CVE-2006-4558 | DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uploading files with double extensions via the fileupload parameter in a newthread action in newpost.php. | EXPLOIT ✓HIGH 7.5EPSS 4.17% | 6 September 2006 |
| CVE-2006-4553 | PHP remote file inclusion vulnerability in plugin.class.php in the com_comprofiler Components 1.0 RC2 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 4.90% | 6 September 2006 |
| CVE-2006-4545 | PHP remote file inclusion vulnerability in ModuleBased CMS Pre-Alpha allows remote attackers to execute arbitrary PHP code via the _SERVER parameter in (1) admin/avatar.php, (2) libs/archive.class.php, (3) libs/login.php, (4) libs/profiles.class.php,… | EXPLOIT ✓HIGH 7.5EPSS 2.76% | 6 September 2006 |
| CVE-2006-4543 | Cross-site scripting (XSS) vulnerability in index.php in HLStats 1.34 allows remote attackers to inject arbitrary web script or HTML via the (1) game parameter in players mode, the (2) weapon parameter in weaponinfo mode, the (3) st parameter in search… | EXPLOIT ✓MEDIUM 6.8EPSS 1.92% | 6 September 2006 |
| CVE-2006-3636 | Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.9rc1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | EXPLOIT ✓MEDIUM 6.8EPSS 6.82% | 6 September 2006 |
| CVE-2006-4541 | RapDrv.sys in BlackICE PC Protection 3.6.cpn, cpj, cpiE, and possibly 3.6 and earlier, allows local users to cause a denial of service (crash) via a NULL third argument to the NtOpenSection API function. | EXPLOIT ✓MEDIUM 4.6EPSS 0.73% | 5 September 2006 |
| CVE-2006-4540 | Cross-site scripting (XSS) vulnerability in learncenter.asp in Learn.com LearnCenter allows remote attackers to inject arbitrary web script or HTML via the id parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.16% | 5 September 2006 |
| CVE-2006-4536 | SQL injection vulnerability in module/rejestracja.php in CMS Frogss 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the podpis parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.11% | 5 September 2006 |
| CVE-2006-4532 | PHP remote file inclusion vulnerability in articles/article.php in Yet Another Community System (YACS) CMS 6.6.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the context[path_to_root] parameter. | EXPLOIT ✓HIGH 7.5EPSS 7.45% | 1 September 2006 |
| CVE-2006-4531 | PHP remote file inclusion vulnerability in lib/config.php in Pheap CMS 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lpref parameter. | EXPLOIT ✓HIGH 7.5EPSS 4.25% | 1 September 2006 |
| CVE-2006-4525 | Cross-site scripting (XSS) vulnerability in CubeCart 3.0.12 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the links array. | EXPLOITMEDIUM 4.3EPSS 3.46% | 1 September 2006 |
| CVE-2006-4524 | Multiple SQL injection vulnerabilities in login_verif.asp in Digiappz Freekot 1.01 allow remote attackers to execute arbitrary SQL commands via the (1) login or (2) password parameters. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.26% | 1 September 2006 |
| CVE-2006-4523 | HomePortal and OfficePortal Series modems and routers allows remote attackers to cause a denial of service (crash) via a CRLF sequence in a GET request. | EXPLOIT ✓MEDIUM 5.0EPSS 3.71% | 1 September 2006 |
| CVE-2006-4505 | CRLF injection vulnerability in links.php in NX5Linx 1.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a CRLF sequence in the url parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.94% | 31 August 2006 |
| CVE-2006-4504 | SQL injection vulnerability in NX5Linx 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) c and (2) l parameters. | EXPLOIT ✓HIGH 7.5EPSS 1.24% | 31 August 2006 |
| CVE-2006-4498 | PHP remote file inclusion vulnerability in sommaire_admin.php in PhpAlbum (mod_phpalbum) 2.15 for PortailPHP allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter, a different vector than CVE-2006-3922. | EXPLOIT ✓HIGH 7.5EPSS 3.00% | 31 August 2006 |
| CVE-2006-4497 | SQL injection vulnerability in comments.php in IwebNegar 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.13% | 31 August 2006 |
| CVE-2006-4495 | Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Windows 2000 ActiveX COM Objects including (1) ciodm.dll, (2) myinfo.dll, (3) msdxm.ocx,… | EXPLOIT ✓HIGH 7.5EPSS 20.7% | 31 August 2006 |
| CVE-2006-4494 | Microsoft Visual Studio 6.0 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Visual Studio 6.0 ActiveX COM Objects in Internet Explorer, including (1) tcprops.dll, (2)… | EXPLOIT ✓HIGH 7.5EPSS 22.1% | 31 August 2006 |
| CVE-2006-4490 | Multiple directory traversal vulnerabilities in Cybozu Office before 6.6 Build 1.3 and Share 360 before 2.5 Build 0.3 allow remote authenticated users to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 4.0EPSS 3.47% | 31 August 2006 |
| CVE-2006-4489 | Multiple PHP remote file inclusion vulnerabilities in MiniBill 2006-07-14 (1.2.2) allow remote attackers to execute arbitrary PHP code via (1) a URL in the config[include_dir] parameter in actions/ipn.php or (2) an FTP path in the config[plugin_dir]… | EXPLOIT ✓HIGH 7.5EPSS 15.7% | 31 August 2006 |
| CVE-2006-4488 | PHP remote file inclusion vulnerability in modules/userstop/userstop.php in ExBB Italia 0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the exbb[home_path] parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 3.18% | 31 August 2006 |
| CVE-2006-4479 | Cross-site scripting (XSS) vulnerability in loginreq2.php in Visual Shapers ezContents 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the subgroupname parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 2.08% | 31 August 2006 |
| CVE-2006-4478 | SQL injection vulnerability in headeruserdata.php in Visual Shapers ezContents 2.0.3 allows remote attackers to execute arbitrary SQL commands via the groupname parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.82% | 31 August 2006 |
| CVE-2006-4477 | Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute arbitrary PHP code via an empty GLOBALS[rootdp] parameter and an ftps URL in the (1) GLOBALS[admin_home] parameter in (a)… | EXPLOIT ×10 ✓HIGH 7.5EPSS 8.13% | 31 August 2006 |
| CVE-2006-4464 | The Nokia Browser, possibly Nokia Symbian 60 Browser 3rd edition, allows remote attackers to cause a denial of service (crash) via JavaScript that constructs a large Unicode string. | EXPLOIT ✓MEDIUM 5.0EPSS 2.98% | 31 August 2006 |
| CVE-2006-4458 | Directory traversal vulnerability in calendar/inc/class.holidaycalc.inc.php in phpGroupWare 0.9.16.010 and earlier allows remote attackers to include arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.4EPSS 3.33% | 31 August 2006 |
| CVE-2006-4456 | PHP remote file inclusion vulnerability in functions.php in phpECard 2.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.35% | 31 August 2006 |
| CVE-2006-4455 | Unspecified vulnerability in Xchat 2.6.7 and earlier allows remote attackers to cause a denial of service (crash) via unspecified vectors involving the PRIVMSG command. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 5.10% | 30 August 2006 |
| CVE-2006-4454 | Cross-site scripting (XSS) vulnerability in hlstats.php in HLstats 1.34 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.70% | 30 August 2006 |
| CVE-2006-4452 | PHP remote file inclusion vulnerability in security/include/_class.security.php in Web3news 0.95 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the PHPSECURITYADMIN_PATH parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.25% | 30 August 2006 |
| CVE-2006-4450 | usercp_avatar.php in PHPBB 2.0.20, when avatar uploading is enabled, allows remote attackers to use the server as a web proxy by submitting a URL to the avatarurl parameter, which is then used in an HTTP GET request. | EXPLOIT ✓MEDIUM 5.1EPSS 4.20% | 30 August 2006 |
| CVE-2006-4449 | Cross-site scripting (XSS) vulnerability in attachment.php in MyBulletinBoard (MyBB) 1.1.7 and possibly other versions allows remote attackers to inject arbitrary web script or HTML via a GIF image that contains URL-encoded Javascript, which is rendered… | EXPLOIT ✓MEDIUM 5.1EPSS 2.30% | 30 August 2006 |
| CVE-2006-4448 | Multiple PHP remote file inclusion vulnerabilities in interact 2.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) CONFIG[BASE_PATH] parameter in (a) admin/autoprompter.php and (b)… | EXPLOIT ✓MEDIUM 5.1EPSS 2.66% | 30 August 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.