SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-29 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,952 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026

25,049 results · page 387 of 501

CVESummaryPriorityPublished
CVE-2006-3960SQL injection vulnerability in top.php in X-Scripts X-Poll, probably 2.30, allows remote attackers to execute arbitrary SQL commands via the poll parameter.EXPLOIT ✓HIGH 7.5EPSS 1.22%1 August 2006
CVE-2006-3959SQL injection vulnerability in protect.php in X-Scripts X-Protection 1.10, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameter.EXPLOIT ✓HIGH 7.5EPSS 1.25%1 August 2006
CVE-2006-3957PHP remote file inclusion vulnerability in payment.php in BosDev BosDates allows remote attackers to execute arbitrary PHP code via a URL in the insPath parameter.EXPLOIT ✓HIGH 7.5EPSS 2.52%1 August 2006
CVE-2006-3955Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to (1) news.php, (2) search.php, or (3) whosOnline.php.EXPLOIT ✓HIGH 7.5EPSS 9.81%1 August 2006
CVE-2006-3952Stack-based buffer overflow in EFS Software Easy File Sharing FTP Server 2.0 allows remote attackers to execute arbitrary code via a long argument to the PASS command.EXPLOIT ×4 ✓HIGH 7.5EPSS 66.8%1 August 2006
CVE-2006-3951PHP remote file inclusion vulnerability in moodle.php in Mam-moodle alpha component (com_moodle) for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.EXPLOIT ✓HIGH 7.5EPSS 2.71%1 August 2006
CVE-2006-3949PHP remote file inclusion vulnerability in artlinks.dispnew.php in the Artlinks component (com_artlinks) for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.EXPLOIT ✓MEDIUM 6.8EPSS 4.52%1 August 2006
CVE-2006-3948Cross-site scripting (XSS) vulnerability in modules.php in PHP-Nuke INP allows remote attackers to inject arbitrary web script or HTML via the query parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.70%1 August 2006
CVE-2006-3947PHP remote file inclusion vulnerability in components/com_mambatstaff/mambatstaff.php in the Mambatstaff 3.1b and earlier component for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.EXPLOIT ✓MEDIUM 6.8EPSS 3.11%1 August 2006
CVE-2006-3944Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) via a (1) Forms.ListBox.1 or (2) Forms.ListBox.1 object with the ListWidth property set to (a) 0x7fffffff, which triggers an integer overflow…EXPLOIT ✓MEDIUM 5.0EPSS 17.5%31 July 2006
CVE-2006-3943Stack-based buffer overflow in NDFXArtEffects in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) via long (1) RGBExtraColor, (2) RGBForeColor, and (3) RGBBackColor properties.EXPLOIT ✓LOW 2.6EPSS 15.6%31 July 2006
CVE-2006-3942The server driver (srv.sys) in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (system crash) via an SMB_COM_TRANSACTION SMB message that contains a string without null character termination,…EXPLOIT ✓HIGH 7.8EPSS 75.0%31 July 2006
CVE-2006-3940Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via (1) the ar parameter in auction_room.php and (2) the u parameter in auction_store.php.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.14%31 July 2006
CVE-2006-3931Buffer overflow in the daemon function in midirecord.cc in Tuomas Airaksinen Midirecord 2.0 allows local users to execute arbitrary code via a long command line argument (filename).EXPLOIT ✓MEDIUM 4.6EPSS 1.05%31 July 2006
CVE-2006-3930PHP remote file inclusion vulnerability in admin.a6mambohelpdesk.php in a6mambohelpdesk Mambo Component 18RC1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.EXPLOIT ✓HIGH 7.5EPSS 3.93%31 July 2006
CVE-2006-3929Cross-site scripting (XSS) vulnerability in the Forms/rpSysAdmin script on the Zyxel Prestige 660H-61 ADSL Router running firmware 3.40(PT.0)b32 allows remote attackers to inject arbitrary web script or HTML via hex-encoded values in the a parameter.EXPLOITMEDIUM 4.3EPSS 3.42%31 July 2006
CVE-2006-3928PHP remote file inclusion vulnerability in index.php in WMNews 0.2a and earlier allows remote attackers to execute arbitrary PHP code via a URL in the base_datapath parameter.EXPLOIT ✓HIGH 7.5EPSS 3.25%31 July 2006
CVE-2006-3927Cross-site scripting (XSS) vulnerability in auctionsearch.php in PhpProBid 5.24 allows remote attackers to inject arbitrary web script or HTML via the advsrc parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.93%31 July 2006
CVE-2006-3926Multiple SQL injection vulnerabilities in PhpProBid 5.24 allow remote attackers to execute arbitrary SQL commands via the (1) view or (2) start parameters to (a) viewfeedback.php or the (3) orderType parameter to (b) categories.php.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.74%31 July 2006
CVE-2006-2481VMware ESX Server 2.0.x before 2.0.2 and 2.x before 2.5.2 patch 4 stores authentication credentials in base 64 encoded format in the vmware.mui.kid and vmware.mui.sid cookies, which allows attackers to gain privileges by obtaining the cookies using…EXPLOIT ✓MEDIUM 5.0EPSS 7.19%31 July 2006
CVE-2006-3922PHP remote file inclusion vulnerability in mod_membre/inscription.php in PortailPHP 1.7 allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter.EXPLOIT ✓HIGH 7.5EPSS 3.57%28 July 2006
CVE-2006-3746Integer overflow in parse_comment in GnuPG (gpg) 1.4.4 allows remote attackers to cause a denial of service (segmentation fault) via a crafted message.EXPLOIT ✓MEDIUM 5.0EPSS 7.21%28 July 2006
CVE-2006-3747Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service…EXPLOIT ×4 ✓HIGH 7.6EPSS 96.6%28 July 2006
CVE-2006-3918http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back…EXPLOIT ✓MEDIUM 4.3EPSS 95.1%28 July 2006
CVE-2006-3917PHP remote file inclusion vulnerability in inc/gabarits.php in R.EXPLOIT ✓HIGH 7.5EPSS 2.54%28 July 2006
CVE-2006-3915Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by iterating over any native function, as demonstrated with the window.alert function, which triggers a null dereference.EXPLOIT ✓MEDIUM 5.0EPSS 21.6%28 July 2006
CVE-2006-3912Stack-based buffer overflow in the SFX module in WinRAR before 3.60 beta 8 has unspecified vectors and impact.EXPLOIT ×3 ✓LOW 2.1EPSS 5.67%28 July 2006
CVE-2006-3911PHP remote file inclusion vulnerability in OSI Codes PHP Live!EXPLOIT ✓HIGH 7.5EPSS 16.3%28 July 2006
CVE-2006-3910Internet Explorer 6 on Windows XP SP2, when Outlook is installed, allows remote attackers to cause a denial of service (crash) by calling the NewDefaultItem function of an OVCtl (OVCtl.OVCtl.1) ActiveX object, which triggers a null dereference.EXPLOIT ✓MEDIUM 5.0EPSS 17.1%28 July 2006
CVE-2006-3909Cross-site scripting (XSS) vulnerability in calendar.php in WWWthreads allows remote attackers to inject arbitrary web script or HTML via the week parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.20%27 July 2006
CVE-2006-3904SQL injection vulnerability in manager/index.php in Etomite CMS 0.6.1 and earlier, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.88%27 July 2006
CVE-2006-3677Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properties of the window navigator object (window.navigator) that are accessed when Java starts up, which causes a crash…EXPLOIT ×3 ✓HIGH 7.5EPSS 78.7%27 July 2006
CVE-2006-3899Microsoft Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to cause a denial of service (application crash) by calling the stringToBinary function of the CEnroll.CEnroll.2 ActiveX object with a long second argument, which triggers an…EXPLOIT ✓MEDIUM 5.0EPSS 24.3%27 July 2006
CVE-2006-3898Microsoft Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to cause a denial of service (application crash) by calling the Click method of the Internet.HHCtrl.1 ActiveX object before initializing the URL, which triggers a null dereference.EXPLOIT ✓MEDIUM 5.0EPSS 24.3%27 July 2006
CVE-2006-3897Stack overflow in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (application crash) by creating an NMSA.ASFSourceMediaDescription.1 ActiveX object with a long dispValue property.EXPLOIT ✓MEDIUM 5.0EPSS 23.3%27 July 2006
CVE-2006-3886SQL injection vulnerability in Shalwan MusicBox 2.3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter in a viewgallery action in a request for the top-level URI.EXPLOIT ✓HIGH 7.5EPSS 1.14%27 July 2006
CVE-2006-3884Multiple SQL injection vulnerabilities in links.php in Gonafish LinksCaffe 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) offset and (2) limit parameters, (3) newdays parameter in a new action, and the (4) link_id parameter in…EXPLOIT ✓HIGH 7.5EPSS 3.93%27 July 2006
CVE-2006-3883Multiple cross-site scripting (XSS) vulnerabilities in Gonafish LinksCaffe 3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the tablewidth parameter in (a) counter.php; (2) the newdays parameter in (b) links.php; and the (3)…EXPLOIT ×3 ✓MEDIUM 4.3EPSS 4.77%27 July 2006
CVE-2006-3880Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Small Business Server 2003 allow remote attackers to cause a denial of service (IP stack hang) via a continuous stream of packets on TCP port 135 that have incorrect TCP header checksums…EXPLOIT ✓MEDIUM 5.0EPSS 24.7%27 July 2006
CVE-2006-3879Integer overflow in the loadChunk function in loaders/load_gt2.c in libmikmod in Mikmod Sound System 3.2.2 allows remote attackers to cause a denial of service via a GRAOUMF TRACKER (GT2) module file with a large (0xffffffff) comment length value in an…EXPLOIT ✓MEDIUM 5.0EPSS 9.46%27 July 2006
CVE-2006-3838Multiple stack-based buffer overflows in eIQnetworks Enterprise Security Analyzer (ESA) before 2.5.0, as used in products including (a) Sidewinder, (b) iPolicy Security Manager, (c) Astaro Report Manager, (d) Fortinet FortiReporter, (e) Top Layer…EXPLOIT ×6 ✓HIGH 10.0EPSS 73.6%27 July 2006
CVE-2006-3819Eval injection vulnerability in the configure script in TWiki 4.0.0 through 4.0.4 allows remote attackers to execute arbitrary Perl code via an HTTP POST request containing a parameter name starting with "TYPEOF".EXPLOIT ✓HIGH 7.5EPSS 4.10%27 July 2006
CVE-2006-3851SQL injection vulnerability in upgradev1.php in X7 Chat 2.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the old_prefix parameter.EXPLOIT ✓HIGH 7.5EPSS 1.13%25 July 2006
CVE-2006-3850PHP remote file inclusion vulnerability in upgrader.php in Vanilla CMS 1.0.1 and earlier, when /conf/old_settings.php exists, allows remote attackers to execute arbitrary PHP code via a URL in the RootDirectory parameter.EXPLOIT ✓MEDIUM 5.1EPSS 3.45%25 July 2006
CVE-2006-3847PHP remote file inclusion vulnerability in (1) admin.php, and possibly (2) details.php, (3) modify.php, (4) newgroup.php, (5) newtask.php, and (6) rss.php, in MoSpray (aka com_mospray) 1.8 RC1 allows remote attackers to execute arbitrary PHP code via a…EXPLOIT ✓MEDIUM 5.1EPSS 3.14%25 July 2006
CVE-2006-3846PHP remote file inclusion vulnerability in extadminmenus.class.php in the MultiBanners 1.0.1 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.91%25 July 2006
CVE-2006-3845Stack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary code via a long filename in a LHA archive.EXPLOIT ✓HIGH 9.3EPSS 7.89%25 July 2006
CVE-2006-3843PHP remote file inclusion vulnerability in com_calendar.php in Calendar Mambo Module 1.5.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter.EXPLOIT ✓HIGH 7.5EPSS 2.58%25 July 2006
CVE-2006-3836Directory traversal vulnerability in index.php in UNIDOmedia Chameleon LE 1.203 and earlier, and possibly Chameleon PRO, allows remote attackers to read arbitrary files via the rmid parameter.EXPLOIT ✓MEDIUM 5.0EPSS 3.50%25 July 2006
CVE-2006-3835Apache Tomcat 5 before 5.5.17 allows remote attackers to list directories via a semicolon (;) preceding a filename with a mapped extension, as demonstrated by URLs ending with /;index.jsp and /;help.do.EXPLOIT ✓MEDIUM 5.0EPSS 46.2%25 July 2006

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.