Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,903 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026
25,049 results · page 383 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-4446 | Heap-based buffer overflow in DirectAnimation.PathControl COM object (daxctle.ocx) in Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a Spline function call whose first… | EXPLOIT ✓MEDIUM 5.0EPSS 62.2% | 30 August 2006 |
| CVE-2006-4305 | Buffer overflow in SAP DB and MaxDB before 7.6.00.30 allows remote attackers to execute arbitrary code via a long database name when connecting via a WebDBM client. | EXPLOIT ✓HIGH 10.0EPSS 71.7% | 30 August 2006 |
| CVE-2006-4444 | Multiple SQL injection vulnerabilities in Cybozu Garoon 2.1.0 for Windows allow remote authenticated users to execute arbitrary SQL commands via the (1) tid parameter in the (a) todo/view (aka TODO List View), (b) todo/modify (aka TODO List Modify), or… | EXPLOIT ✓MEDIUM 6.5EPSS 3.08% | 29 August 2006 |
| CVE-2006-4443 | PHP remote file inclusion vulnerability in myajaxphp.php in AlstraSoft Video Share Enterprise allows remote attackers to execute arbitrary PHP code via a URL in the config[BASE_DIR] parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.60% | 29 August 2006 |
| CVE-2006-4441 | Multiple PHP remote file inclusion vulnerabilities in Ay System Solutions CMS 2.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path[ShowProcessHandle] parameter to (1) home.php or (2) impressum.php. | EXPLOIT ✓HIGH 7.5EPSS 2.61% | 29 August 2006 |
| CVE-2006-4440 | PHP remote file inclusion vulnerability in main.php in Ay System Solutions CMS 2.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path[ShowProcessHandle] parameter. | EXPLOIT ✓HIGH 7.5EPSS 8.29% | 29 August 2006 |
| CVE-2006-4428 | PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5 allows remote attackers to execute arbitrary PHP code via a URL in the template parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 4.42% | 29 August 2006 |
| CVE-2006-4427 | index.php in eFiction before 2.0.7 allows remote attackers to bypass authentication and gain privileges by setting the (1) adminloggedin, (2) loggedin, and (3) level parameters to "1". | EXPLOIT ✓MEDIUM 5.1EPSS 3.04% | 29 August 2006 |
| CVE-2006-4426 | PHP remote file inclusion vulnerability in AES/modules/auth/phpsecurityadmin/include/logout.php in AlberT-EasySite (AES) 1.0a5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the PSA_PATH parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 3.08% | 29 August 2006 |
| CVE-2006-4425 | Multiple PHP remote file inclusion vulnerabilities in phpCOIN 1.2.3 allow remote attackers to execute arbitrary PHP code via the _CCFG[_PKG_PATH_INCL] parameter in coin_includes scripts including (1) api.php, (2) common.php, (3) core.php, (4)… | EXPLOIT ✓MEDIUM 5.1EPSS 4.25% | 29 August 2006 |
| CVE-2006-4424 | PHP remote file inclusion vulnerability in coin_includes/constants.php in phpCOIN 1.2.3 allows remote attackers to execute arbitrary PHP code via the _CCFG[_PKG_PATH_INCL] parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 7.63% | 29 August 2006 |
| CVE-2006-4423 | Multiple PHP remote file inclusion vulnerabilities in Bigace 1.8.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[_BIGACE][DIR][admin] parameter in (a) system/command/admin.cmd.php, (b) admin/include/upload_form.php,… | EXPLOIT ×4 ✓HIGH 7.5EPSS 3.15% | 29 August 2006 |
| CVE-2006-4422 | PHP remote file inclusion vulnerability in includes/phpdig/libs/search_function.php in Jetbox CMS 2.1 allows remote attackers to execute arbitrary PHP code via a URL in the relative_script_path parameter, a different vector than CVE-2006-2270. | EXPLOIT ✓HIGH 7.5EPSS 7.32% | 29 August 2006 |
| CVE-2006-4421 | Cross-site scripting (XSS) vulnerability in template/default/thanks_comment.php in Yet Another PHP Image Gallery (YaPIG) 0.95b allows remote attackers to inject arbitrary web script or HTML via the D_REFRESH_URL parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.71% | 29 August 2006 |
| CVE-2006-4420 | Directory traversal vulnerability in include_lang.php in Phaos 0.9.2 allows remote attackers to include arbitrary local files via ".." sequences in the lang parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 2.61% | 28 August 2006 |
| CVE-2006-4419 | SQL injection vulnerability in note.php in ProManager 0.73 allows remote attackers to execute arbitrary SQL commands via the note_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.17% | 28 August 2006 |
| CVE-2006-4418 | Directory traversal vulnerability in index.php for Wikepage 2006.2a Opus 10 allows remote attackers to include arbitrary local files via the lng parameter, as demonstrated by inserting PHP code into a log file. | EXPLOIT ✓MEDIUM 4.0EPSS 2.67% | 28 August 2006 |
| CVE-2006-4364 | Multiple heap-based buffer overflows in the POP3 server in Alt-N Technologies MDaemon before 9.0.6 allow remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via long strings that contain '@' characters in the… | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 57.3% | 27 August 2006 |
| CVE-2006-4363 | PHP remote file inclusion vulnerability in admin.cropcanvas.php in the CropImage component (com_cropimage) 1.0 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the cropimagedir parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.81% | 27 August 2006 |
| CVE-2006-4362 | Cross-site scripting (XSS) vulnerability in getad.php in Diesel Paid Mail allows remote attackers to inject arbitrary web script or HTML via the ps parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.95% | 27 August 2006 |
| CVE-2006-4359 | Stack-based buffer overflow in Trident Software PowerZip 7.06 Build 3895 on Windows 2000 allows remote attackers to execute arbitrary code via a ZIP archive containing a long filename. | EXPLOIT ✓MEDIUM 5.1EPSS 5.01% | 27 August 2006 |
| CVE-2006-4358 | Cross-site scripting (XSS) vulnerability in index.php in Diesel Pay allows remote attackers to inject arbitrary web script or HTML via the read parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.93% | 27 August 2006 |
| CVE-2006-4357 | PHP remote file inclusion vulnerability in clients/index.php in Diesel Smart Traffic allows remote attackers to execute arbitrary PHP code via a URL in the src parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.60% | 27 August 2006 |
| CVE-2006-4354 | PHP remote file inclusion vulnerability in e/class/CheckLevel.php in Phome Empire CMS 3.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the check_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.25% | 27 August 2006 |
| CVE-2006-4374 | IrfanView 3.98 (with plugins) allows user-assisted attackers to cause a denial of service (application crash) via a crafted ANI image file, possibly due to a buffer overflow. | EXPLOIT ✓LOW 2.6EPSS 2.70% | 26 August 2006 |
| CVE-2006-4373 | PHP remote file inclusion vulnerability in modules/visitors2/include/config.inc.php in pSlash 0.70 allows remote attackers to execute arbitrary PHP code via a URL in the lvc_include_dir parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.33% | 26 August 2006 |
| CVE-2006-4372 | PHP remote file inclusion vulnerability in admin.lurm_constructor.php in the Lurm Constructor component (com_lurm_constructor) 0.6b and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the lm_absolute_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.26% | 26 August 2006 |
| CVE-2006-4369 | Absolute path traversal vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via an absolute pathname in the phpbb_root_path parameter. | EXPLOIT ✓LOW 2.6EPSS 2.82% | 26 August 2006 |
| CVE-2006-4368 | PHP remote file inclusion vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.30% | 26 August 2006 |
| CVE-2006-4367 | SQL injection vulnerability in alltopics.php in the All Topics Hack 1.5.0 and earlier for phpBB 2.0.21 allows remote attackers to execute arbitrary SQL commands via the start parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.13% | 26 August 2006 |
| CVE-2006-4366 | PHP remote file inclusion vulnerability in index.php in RedBLoG 0.5 allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.52% | 26 August 2006 |
| CVE-2006-4365 | Multiple PHP remote file inclusion vulnerabilities in VistaBB 2.0.33 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) includes/functions_mod_user.php or (2) includes/functions_portal.php. | EXPLOIT ✓HIGH 7.5EPSS 3.61% | 26 August 2006 |
| CVE-2006-3124 | Buffer overflow in the HTTP header parsing in Streamripper before 1.61.26 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted HTTP headers. | EXPLOIT ×2 ✓HIGH 7.5EPSS 20.1% | 26 August 2006 |
| CVE-2006-4349 | PHP remote file inclusion vulnerability in ToendaCMS 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tcms_administer_site parameter to an unspecified script, probably index.php. | EXPLOIT ✓HIGH 7.5EPSS 2.89% | 24 August 2006 |
| CVE-2006-4348 | PHP remote file inclusion vulnerability in config.kochsuite.php in the Kochsuite (com_kochsuite) 0.9.4 component for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.23% | 24 August 2006 |
| CVE-2006-4329 | Multiple PHP remote file inclusion vulnerabilities in Shadows Rising RPG (Pre-Alpha) 0.0.5b and earlier allow remote attackers to execute arbitrary PHP code via a URL in the CONFIG[gameroot] parameter to (1) core/includes/security.inc.php, (2)… | EXPLOIT ✓HIGH 7.5EPSS 7.99% | 24 August 2006 |
| CVE-2006-4322 | PHP remote file inclusion vulnerability in estateagent.php in the EstateAgent component (com_estateagent) for Mambo, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path… | EXPLOIT ✓HIGH 7.5EPSS 2.58% | 24 August 2006 |
| CVE-2006-4321 | PHP remote file inclusion vulnerability in cpg.php in the Coppermine Photo Gallery component (com_cpg) 1.0 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.25% | 24 August 2006 |
| CVE-2006-4318 | Buffer overflow in WFTPD Server 3.23 allows remote attackers to execute arbitrary code via long SIZE commands. | EXPLOIT ×2 ✓MEDIUM 6.5EPSS 62.1% | 24 August 2006 |
| CVE-2006-4311 | PHP remote file inclusion vulnerability in Sonium Enterprise Adressbook 0.2 allows remote attackers to execute arbitrary PHP code via the folder parameter in multiple files in the plugins directory, as demonstrated by plugins/1_Adressbuch/delete.php. | EXPLOIT ✓HIGH 7.5EPSS 3.24% | 23 August 2006 |
| CVE-2006-4310 | Mozilla Firefox 1.5.0.6 allows remote attackers to cause a denial of service (crash) via a crafted FTP response, when attempting to connect with a username and password via the FTP URI. | EXPLOIT ✓MEDIUM 4.3EPSS 6.15% | 23 August 2006 |
| CVE-2006-4308 | Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Learning System 6, Blackboard Learning and Community Portal Suite 6.2.3.23, and Blackboard Vista 4 allow remote attackers to inject arbitrary Javascript, VBScript, or HTML via (1) data,… | EXPLOIT ✓MEDIUM 4.3EPSS 2.04% | 23 August 2006 |
| CVE-2006-4301 | Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) via a long Color attribute in multiple DirectX Media Image DirectX Transforms ActiveX COM Objects from (a) dxtmsft.dll and (b) dxtmsft3.dll, including (1)… | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 39.1% | 23 August 2006 |
| CVE-2006-4300 | SQL injection vulnerability in comments.asp in SimpleBlog 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.71% | 23 August 2006 |
| CVE-2006-4296 | PHP remote file inclusion vulnerability in classes/Tar.php in bigAPE-Backup component (com_babackup) for Mambo 1.1 allows remote attackers to include arbitrary files via the mosConfig_absolute_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.45% | 23 August 2006 |
| CVE-2006-4295 | Cross-site scripting (XSS) vulnerability in ascan_6.asp in Panda ActiveScan 5.53.00 allows remote attackers to inject arbitrary web script or HTML via the email parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.77% | 23 August 2006 |
| CVE-2006-4293 | Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote attackers to inject arbitrary web script or HTML via the (1) dir parameter in dohtaccess.html, or the (2) file parameter in (a) editit.html or (b) showfile.html. | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 2.13% | 22 August 2006 |
| CVE-2006-4291 | PHP remote file inclusion vulnerability in handlers/email/mod.listmail.php in PHlyMail Lite 3.4.4 and earlier (Build 3.04.04) allows remote attackers to execute arbitrary PHP code via a URL in the _PM_[path][handler] parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 3.08% | 22 August 2006 |
| CVE-2006-4288 | PHP remote file inclusion vulnerability in admin.a6mambocredits.php in the a6mambocredits component (com_a6mambocredits) 2.0.0 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 5.81% | 22 August 2006 |
| CVE-2006-4287 | Multiple PHP remote file inclusion vulnerabilities in NES Game and NES System c108122 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) phphtmllib parameter to (a) phphtmllib/includes.php; tag_utils/ scripts including… | EXPLOIT ✓HIGH 7.5EPSS 16.4% | 22 August 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.