Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,903 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026
25,049 results · page 385 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-4160 | Multiple PHP remote file inclusion vulnerabilities in Tony Bibbs and Vincent Furia MVCnPHP 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the glConf[path_library] parameter to (1) BaseCommand.php, (2) BaseLoader.php, and (3)… | EXPLOIT ✓HIGH 7.5EPSS 8.91% | 16 August 2006 |
| CVE-2006-4159 | Multiple PHP remote file inclusion vulnerabilities in Chaussette 080706 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the _BASE parameter to scripts in Classes/ including (1) Evenement.php, (2) Event.php, (3)… | EXPLOIT ✓HIGH 7.5EPSS 15.0% | 16 August 2006 |
| CVE-2006-4158 | PHP remote file inclusion vulnerability in Login.php in Spaminator 1.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 3.08% | 16 August 2006 |
| CVE-2006-4157 | Cross-site scripting (XSS) vulnerability in index.php in Yet another Bulletin Board (YaBB) allows remote attackers to inject arbitrary web script or HTML via the categories parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.95% | 16 August 2006 |
| CVE-2006-4156 | PHP remote file inclusion vulnerability in big.php in pearlabs mafia moblog 6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pathtotemplate parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.54% | 16 August 2006 |
| CVE-2006-4144 | Integer overflow in the ReadSGIImage function in sgi.c in ImageMagick before 6.2.9 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via large (1) bytes_per_pixel, (2) columns, and (3) rows values,… | EXPLOIT ✓LOW 2.6EPSS 11.0% | 15 August 2006 |
| CVE-2006-4142 | SQL injection vulnerability in extra/online.php in Virtual War (VWar) 1.5.0 R14 and earlier allows remote attackers to execute arbitrary SQL commands via the n parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.29% | 14 August 2006 |
| CVE-2006-4140 | Directory traversal vulnerability in IPCheck Server Monitor before 5.3.3.639/640 allows remote attackers to read arbitrary files via modified .. | EXPLOIT ✓MEDIUM 5.0EPSS 4.38% | 14 August 2006 |
| CVE-2006-4138 | Multiple unspecified vulnerabilities in Microsoft Windows Help File viewer (winhlp32.exe) allow user-assisted attackers to execute arbitrary code via crafted HLP files. | EXPLOIT ✓HIGH 7.6EPSS 20.1% | 14 August 2006 |
| CVE-2006-4131 | Multiple buffer overflows in ArcSoft MMS Composer 1.5.5.6, and possibly earlier, and 2.0.0.13, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via crafted MMS (Multimedia Messaging Service)… | EXPLOIT ✓HIGH 7.5EPSS 8.89% | 14 August 2006 |
| CVE-2006-4130 | PHP remote file inclusion vulnerability in admin.remository.php in the Remository Component (com_remository) 3.25 and earlier for Mambo and Joomla!, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the… | EXPLOIT ✓MEDIUM 6.8EPSS 3.24% | 14 August 2006 |
| CVE-2006-4129 | PHP remote file inclusion vulnerability in admin.webring.docs.php in the Webring Component (com_webring) 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the component_dir parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.35% | 14 August 2006 |
| CVE-2006-4126 | The dc_chat function in cmd.dc.c in DConnect Daemon 0.7.0 and earlier allows remote attackers to cause a denial of service (application crash) by sending a client message before providing the nickname, which triggers a null pointer dereference. | EXPLOIT ✓MEDIUM 5.0EPSS 9.00% | 14 August 2006 |
| CVE-2006-4125 | Stack-based buffer overflow in main.c in DConnect Daemon 0.7.0 and earlier allows remote attackers to execute arbitrary code via a large nickname, which is not properly handled by the listen_thread_udp function. | EXPLOIT ✓HIGH 7.5EPSS 7.99% | 14 August 2006 |
| CVE-2006-4123 | PHP remote file inclusion vulnerability in boitenews4/index.php in Boite de News 4.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the url_index parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.54% | 14 August 2006 |
| CVE-2006-4122 | Simple one-file guestbook 1.0 and earlier allows remote attackers to bypass authentication and delete guestbook entries via a modified id parameter to guestbook.php. | EXPLOIT ✓HIGH 7.5EPSS 3.17% | 14 August 2006 |
| CVE-2006-4121 | PHP remote file inclusion vulnerability in owimg.php3 in See-Commerce 1.0.625 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 2.68% | 14 August 2006 |
| CVE-2006-4115 | PHP remote file inclusion vulnerability in common.inc.php in PgMarket 2.2.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the CFG[libdir] parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 2.69% | 14 August 2006 |
| CVE-2006-4114 | SQL injection vulnerability in view_com.php in Nicolas Grandjean PHPMyRing 4.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idsite parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.25% | 14 August 2006 |
| CVE-2006-4113 | PHP remote file inclusion vulnerability in genpage-cgi.php in Brian Fraval hitweb 4.2 and possibly earlier versions allows remote attackers to execute arbitrary PHP code via the REP_INC parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 3.08% | 14 August 2006 |
| CVE-2006-4110 | Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or alternate case) characters that bypass the case-sensitive ScriptAlias directive, but allow access to the file on… | EXPLOIT ✓MEDIUM 4.3EPSS 40.0% | 14 August 2006 |
| CVE-2006-4103 | PHP remote file inclusion vulnerability in article-raw.php in Jason Alexander phNNTP 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file_newsportal parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.61% | 14 August 2006 |
| CVE-2006-4102 | PHP remote file inclusion vulnerability in tpl.inc.php in Falko Timme and Till Brehm SQLiteWebAdmin 0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the conf[classpath] parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.69% | 14 August 2006 |
| CVE-2006-4019 | Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary program variables and read or write the attachments and preferences of other users. | EXPLOITMEDIUM 6.4EPSS 9.98% | 11 August 2006 |
| CVE-2006-4089 | Multiple buffer overflows in Andy Lo-A-Foe AlsaPlayer 0.99.76 and earlier allow remote attackers to cause a denial of service (application crash), or have other unknown impact, via (1) a long Location field sent by a web server, which triggers an… | EXPLOIT ✓MEDIUM 5.0EPSS 11.3% | 11 August 2006 |
| CVE-2006-4085 | PHP remote file inclusion vulnerability in Olaf Noehring The Search Engine Project (TSEP) 0.942 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tsep_config[absPath] parameter to pagenavigation.php, a different vector… | EXPLOIT ✓HIGH 7.5EPSS 2.17% | 11 August 2006 |
| CVE-2006-4081 | preview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 allows remote attackers to execute commands via shell metacharacters ("|" pipe symbol) in the file parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 4.29% | 11 August 2006 |
| CVE-2006-4077 | PHP remote file inclusion vulnerability in CheckUpload.php in Vincenzo Valvano Comet WebFileManager (CWFM) 0.9.1, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the Language parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.25% | 11 August 2006 |
| CVE-2006-4075 | Multiple PHP remote file inclusion vulnerabilities in Wim Fleischhauer docpile: wim's edition (docpile:we) 0.2.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the INIT_PATH parameter to (1) lib/folder.class.php, (2)… | EXPLOIT ✓MEDIUM 5.1EPSS 17.2% | 11 August 2006 |
| CVE-2006-4074 | PHP remote file inclusion vulnerability in lib/tpl/default/main.php in the JD-Wiki Component (com_jd-wiki) 1.0.2 and earlier for Joomla!, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the… | EXPLOIT ✓MEDIUM 6.8EPSS 5.70% | 11 August 2006 |
| CVE-2006-4073 | Multiple PHP remote file inclusion vulnerabilities in Fabian Hainz phpCC Beta 4.2 allow remote attackers to execute arbitrary PHP code via a URL in the base_dir parameter to (1) login.php, (2) reactivate.php, or (3) register.php. | EXPLOIT ✓HIGH 7.5EPSS 3.23% | 11 August 2006 |
| CVE-2006-4072 | Multiple SQL injection vulnerabilities in Club-Nuke [XP] 2.0 LCID 2048 allow remote attackers to execute arbitrary SQL commands via the (1) haber_id parameter to haber_detay.asp, and allow remote authenticated users to execute arbitrary SQL commands via… | EXPLOIT ✓MEDIUM 6.5EPSS 1.00% | 11 August 2006 |
| CVE-2006-4071 | Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in Microsoft Windows XP, Server 2003, and possibly other versions, allows user-assisted attackers to cause a denial of service (application crash) via a… | EXPLOIT ✓LOW 2.6EPSS 24.0% | 10 August 2006 |
| CVE-2006-4068 | The pswd.js script relies on the client to calculate whether a username and password match hard-coded hashed values for a server, and uses a hashing scheme that creates a large number of collisions, which makes it easier for remote attackers to conduct… | EXPLOIT ✓MEDIUM 5.0EPSS 2.81% | 10 August 2006 |
| CVE-2006-4065 | Multiple PHP remote file inclusion vulnerabilities in Dmitry Sheiko SAPID Gallery 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) root_path parameter to (a) usr/extensions/get_calendar.inc.php or the (2)… | EXPLOIT ✓MEDIUM 5.1EPSS 2.42% | 10 August 2006 |
| CVE-2006-4064 | SQL injection vulnerability in default.asp in YenerTurk Haber Script 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.04% | 10 August 2006 |
| CVE-2006-4063 | Multiple PHP remote file inclusion vulnerabilities in Csaba Godor SAPID Blog Beta 2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) root_path parameter to (a) usr/extensions/get_blog_infochannel.inc.php, (b)… | EXPLOIT ×4 ✓HIGH 7.5EPSS 3.23% | 10 August 2006 |
| CVE-2006-4062 | PHP remote file inclusion vulnerability in usr/extensions/get_tree.inc.php in Dmitry Sheiko SAPID Shop 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[root_path] parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 3.85% | 10 August 2006 |
| CVE-2006-4061 | PHP remote file inclusion vulnerability in index.php in Thomas Pequet phpPrintAnalyzer 1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the rep_par_rapport_racine parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.17% | 10 August 2006 |
| CVE-2006-4060 | PHP remote file inclusion vulnerability in calendar.php in Visual Events Calendar 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_dir parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.96% | 10 August 2006 |
| CVE-2006-4059 | Multiple PHP remote file inclusion vulnerabilities in USOLVED NEWSolved Lite 1.9.2, and possibly earlier, allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) newsscript_lyt.php, (2)… | EXPLOIT ✓HIGH 7.5EPSS 15.5% | 10 August 2006 |
| CVE-2006-4055 | Multiple PHP remote file inclusion vulnerabilities in Olaf Noehring The Search Engine Project (TSEP) 0.942 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the tsep_config[absPath] parameter to (1) include/colorswitch.php,… | EXPLOIT ×2 ✓HIGH 7.5EPSS 3.92% | 10 August 2006 |
| CVE-2006-4053 | PHP remote file inclusion vulnerability in templates/header.php in ME Download System 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the Vb8878b936c2bd8ae0cab parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 3.42% | 10 August 2006 |
| CVE-2006-4052 | Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Simple Shop 2.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) admin/index.php, (2) admin/adminindex.php, (3)… | EXPLOIT ✓HIGH 7.5EPSS 16.4% | 10 August 2006 |
| CVE-2006-4051 | PHP remote file inclusion vulnerability in global.php in Turnkey Web Tools PHP Live Helper 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 8.29% | 10 August 2006 |
| CVE-2006-4050 | PHP remote file inclusion vulnerability in auto_check_renewals.php in phpAutoMembersArea (phpAMA) 3.2.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the installed_config_file parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.53% | 10 August 2006 |
| CVE-2006-4046 | Multiple stack-based buffer overflows in Open Cubic Player 2.6.0pre6 and earlier for Windows, and 0.1.10_rc5 and earlier on Linux/BSD, allow remote attackers to execute arbitrary code via (1) a large .S3M file handled by the mpLoadS3M function, (2) a… | EXPLOIT ✓HIGH 7.5EPSS 15.6% | 9 August 2006 |
| CVE-2006-4045 | PHP remote file inclusion vulnerability in news.php in Torbstoff News 4 allows remote attackers to execute arbitrary PHP code via a URL in the pfad parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.45% | 9 August 2006 |
| CVE-2006-4044 | PHP remote file inclusion vulnerability in Beautifier/Core.php in Brad Fears phpCodeCabinet 0.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the BEAUT_PATH parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.25% | 9 August 2006 |
| CVE-2006-4042 | Multiple SQL injection vulnerabilities in trackback.php in myWebland myBloggie 2.1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) title, (2) url, (3) excerpt, or (4) blog_name parameters. | EXPLOIT ✓HIGH 7.5EPSS 1.85% | 9 August 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.