Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,903 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026
25,049 results · page 384 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-4285 | PHP remote file inclusion vulnerability in news.php in Fantastic News 2.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[script_path] parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.20% | 22 August 2006 |
| CVE-2006-4284 | SQL injection vulnerability in comments.asp in LBlog 1.05 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.86% | 22 August 2006 |
| CVE-2006-4282 | PHP remote file inclusion vulnerability in MamboLogin.php in the MamboWiki component (com_mambowiki) 0.9.6 and earlier for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the IP parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.23% | 22 August 2006 |
| CVE-2006-4279 | SQL injection vulnerability in topic_post.php in XennoBB 2.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the icon_topic parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.83% | 21 August 2006 |
| CVE-2006-4278 | PHP remote file inclusion vulnerability in includes/layout/plain.footer.php in SportsPHool 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the mainnav parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 3.53% | 21 August 2006 |
| CVE-2006-4277 | Multiple PHP remote file inclusion vulnerabilities in Tutti Nova 1.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the TNLIB_DIR parameter to (1) include/novalib/class.novaAdmin.mysql.php and (2)… | EXPLOIT ✓HIGH 7.5EPSS 3.25% | 21 August 2006 |
| CVE-2006-4276 | PHP remote file inclusion vulnerability in Tutti Nova 1.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the TNLIB_DIR parameter to novalib/class.novaEdit.mysql.php. | EXPLOIT ✓HIGH 7.5EPSS 3.25% | 21 August 2006 |
| CVE-2006-4273 | Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 3.5.4 and 3.6.0 allows remote attackers to inject arbitrary web script or HTML by uploading an attachment with a .pdf extension that contains JavaScript, which is processed as script by… | EXPLOIT ✓MEDIUM 6.8EPSS 2.15% | 21 August 2006 |
| CVE-2006-4270 | PHP remote file inclusion vulnerability in mambelfish.class.php in the mambelfish component (com_mambelfish) 1.1 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 3.03% | 21 August 2006 |
| CVE-2006-4267 | Multiple SQL injection vulnerabilities in CubeCart 3.0.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) oid parameter in modules/gateway/Protx/confirmed.php and the (2) x_invoice_num parameter in… | EXPLOIT ✓HIGH 7.5EPSS 3.64% | 21 August 2006 |
| CVE-2006-4261 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ✓UnscoredEPSS — | 21 August 2006 |
| CVE-2006-4254 | Unspecified vulnerability in setlocale in IBM AIX 5.1.0 through 5.3.0 allows local users to gain privileges via unspecified vectors. | EXPLOIT ✓HIGH 7.5EPSS 7.90% | 21 August 2006 |
| CVE-2006-4253 | Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events that load a deeply nested XML file, followed by… | EXPLOIT ✓HIGH 7.6EPSS 15.2% | 21 August 2006 |
| CVE-2006-4242 | PHP remote file inclusion vulnerability in install.jim.php in the JIM 1.0.1 component for Joomla or Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 3.42% | 21 August 2006 |
| CVE-2006-4241 | PHP remote file inclusion vulnerability in processor/reporter.sql.php in the Reporter Mambo component (com_reporter) allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.60% | 21 August 2006 |
| CVE-2006-4240 | PHP remote file inclusion vulnerability in index.php in Fusion News 3.7 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.25% | 21 August 2006 |
| CVE-2006-4239 | PHP remote file inclusion vulnerability in include/urights.php in Outreach Project Tool (OPT) Max 1.2.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CRM_inc parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.82% | 21 August 2006 |
| CVE-2006-4238 | SQL injection vulnerability in torrents.php in WebTorrent (WTcom) 0.2.4 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter in category mode. | EXPLOIT ✓HIGH 7.5EPSS 1.13% | 21 August 2006 |
| CVE-2006-4237 | PHP remote file inclusion vulnerability in pageheaderdefault.inc.php in Invisionix Roaming System Remote (IRSR) 0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _sysSessionPath parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.54% | 21 August 2006 |
| CVE-2006-4236 | Multiple PHP remote file inclusion vulnerabilities in POWERGAP allow remote attackers to execute arbitrary PHP code via a URL in the (1) shopid parameter to (a) s01.php, (b) s02.php, (c) s03.php, and (d) s04.php; and possibly a URL located after… | EXPLOIT ✓HIGH 7.5EPSS 15.6% | 21 August 2006 |
| CVE-2006-4234 | PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter. | EXPLOIT ✓HIGH 7.5EPSS 6.40% | 18 August 2006 |
| CVE-2006-4230 | Multiple PHP remote file inclusion vulnerabilities in index.php in Lizge V.20 Web Portal allow remote attackers to execute arbitrary PHP code via a URL in the (1) lizge or (2) bade parameters. | EXPLOIT ✓HIGH 7.5EPSS 2.60% | 18 August 2006 |
| CVE-2006-4227 | MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routine's caller, which allows remote authenticated users to gain privileges through a routine that has been… | EXPLOIT ✓MEDIUM 6.5EPSS 13.6% | 18 August 2006 |
| CVE-2006-4219 | The Terminal Services COM object (tsuserex.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by instantiating it as an ActiveX object in Internet Explorer 6.0 SP1 on Microsoft Windows 2003 EE SP1 CN. | EXPLOIT ✓HIGH 7.5EPSS 21.5% | 18 August 2006 |
| CVE-2006-4217 | PHP remote file inclusion vulnerability in modules/usersonline/users.php in WEBInsta CMS 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the module_dir parameter, a different vulnerability than CVE-2006-4196. | EXPLOIT ✓HIGH 7.5EPSS 2.17% | 17 August 2006 |
| CVE-2006-4216 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ✓UnscoredEPSS — | 17 August 2006 |
| CVE-2006-4215 | PHP remote file inclusion vulnerability in index.php in Zen Cart 1.3.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the autoLoadConfig[999][0][loadFile] parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 2.90% | 17 August 2006 |
| CVE-2006-4213 | PHP remote file inclusion vulnerability in config.php in David Kent Norman Thatware 0.4.6 and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.69% | 17 August 2006 |
| CVE-2006-4210 | nu_mail.inc.php in Andreas Kansok phPay 2.02 and 2.02.1, when register_globals is enabled, allows remote attackers to use the server as an open mail relay via modified mail_text2, user_row[5], nu_mail_1, and shop_mail parameters. | EXPLOIT ✓LOW 2.6EPSS 2.09% | 17 August 2006 |
| CVE-2006-4209 | PHP remote file inclusion vulnerability in install3.php in WEBInsta Mailing List Manager 1.3e allows remote attackers to execute arbitrary PHP code via a URL in the cabsolute_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.45% | 17 August 2006 |
| CVE-2006-4208 | Directory traversal vulnerability in wp-db-backup.php in Skippy WP-DB-Backup plugin for WordPress 1.7 and earlier allows remote authenticated users with administrative privileges to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 12.1% | 17 August 2006 |
| CVE-2006-4207 | Multiple PHP remote file inclusion vulnerabilities in Bob Jewell Discloser 0.0.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the fileloc parameter to (1) content/content.php or (2) /inc/indexhead.php. | EXPLOIT ✓HIGH 7.5EPSS 3.23% | 17 August 2006 |
| CVE-2006-4206 | Cross-site scripting (XSS) vulnerability in calendar.asp in ASPPlayground.NET Forum Advanced Edition 2.4.5 Unicode, and possibly other versions before October 15, 2006, allows remote attackers to inject arbitrary web script or HTML via the calendarID… | EXPLOIT ✓MEDIUM 4.3EPSS 2.56% | 17 August 2006 |
| CVE-2006-4205 | Multiple PHP remote file inclusion vulnerabilities in WebDynamite ProjectButler 0.8.4 allow remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter to /classes/ scripts including (1) Cache.class.php, (2) Customer.class.php, (3)… | EXPLOIT ✓HIGH 7.5EPSS 2.54% | 17 August 2006 |
| CVE-2006-4204 | Multiple PHP remote file inclusion vulnerabilities in PHProjekt 5.1 and possibly earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) path_pre parameter in lib/specialdays.php and the (2) lib_path parameter in… | EXPLOIT ✓HIGH 7.5EPSS 8.13% | 17 August 2006 |
| CVE-2006-4203 | PHP remote file inclusion vulnerability in help.mmp.php in the MMP Component (com_mmp) 1.2 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.10% | 17 August 2006 |
| CVE-2006-4202 | SQL injection vulnerability in proje_goster.php in Spidey Blog Script 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.31% | 17 August 2006 |
| CVE-2006-4198 | PHP remote file inclusion vulnerability in includes/session.php in Wheatblog (wB) 1.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the wb_class_dir parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 5.77% | 17 August 2006 |
| CVE-2006-4197 | Multiple buffer overflows in libmusicbrainz (aka mb_client or MusicBrainz Client Library) 2.1.2 and earlier, and SVN 8406 and earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) a long Location header… | EXPLOIT ✓HIGH 7.5EPSS 14.7% | 17 August 2006 |
| CVE-2006-4196 | PHP remote file inclusion vulnerability in index.php in WEBInsta CMS 0.3.1 and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the templates_dir parameter. | EXPLOIT ✓HIGH 7.5EPSS 9.86% | 17 August 2006 |
| CVE-2006-4195 | PHP remote file inclusion vulnerability in param.peoplebook.php in the Peoplebook Component for Mambo (com_peoplebook) 1.0 and earlier, and possibly 1.1.2, when register_globals and allow_url_fopen are enabled, allows remote attackers to execute… | EXPLOIT ✓MEDIUM 6.8EPSS 5.81% | 17 August 2006 |
| CVE-2006-4193 | Microsoft Internet Explorer 6.0 SP1 and possibly other versions allows remote attackers to cause a denial of service and possibly execute arbitrary code by instantiating COM objects as ActiveX controls, including (1) imskdic.dll (Microsoft IME), (2)… | EXPLOIT ×2 ✓HIGH 7.5EPSS 47.5% | 17 August 2006 |
| CVE-2006-4192 | Multiple buffer overflows in MODPlug Tracker (OpenMPT) 1.17.02.43 and earlier and libmodplug 0.8 and earlier, as used in GStreamer and possibly other products, allow user-assisted remote attackers to execute arbitrary code via (1) long strings in ITP… | EXPLOIT ✓MEDIUM 5.1EPSS 9.00% | 17 August 2006 |
| CVE-2006-4191 | Directory traversal vulnerability in memcp.php in XMB (Extreme Message Board) 1.9.6 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the langfilenew parameter, as demonstrated by… | EXPLOIT ✓MEDIUM 5.1EPSS 9.90% | 17 August 2006 |
| CVE-2006-4190 | Directory traversal vulnerability in autohtml.php in the AutoHTML module for PHP-Nuke allows local users to include arbitrary files via a .. | EXPLOIT ✓LOW 2.1EPSS 0.85% | 17 August 2006 |
| CVE-2006-3121 | The peel_netstring function in cl_netstring.c in the heartbeat subsystem in High-Availability Linux before 1.2.5, and 2.0 before 2.0.7, allows remote attackers to cause a denial of service (crash) via the length parameter in a heartbeat message. | EXPLOIT ✓MEDIUM 5.0EPSS 13.6% | 17 August 2006 |
| CVE-2006-4166 | PHP remote file inclusion vulnerability in TinyWebGallery 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the image parameter to (1) image.php or (2) image.php2. | EXPLOIT ✓HIGH 7.5EPSS 3.66% | 16 August 2006 |
| CVE-2006-4164 | PHP remote file inclusion vulnerability in inc/header.inc.php in phpPrintAnalyzer 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ficStyle parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.78% | 16 August 2006 |
| CVE-2006-4163 | PHP remote file inclusion vulnerability in cls_fast_template.php in myWebland miniBloggie 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the fname parameter. | EXPLOIT ✓HIGH 7.5EPSS 4.16% | 16 August 2006 |
| CVE-2006-4161 | Directory traversal vulnerability in the avatar_gallery action in profile.php in XennoBB 2.1.0 and earlier allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.43% | 16 August 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.