Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,952 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026
25,049 results · page 388 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-3832 | SQL injection vulnerability in index.php in Gerrit van Aaken Loudblog 0.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.12% | 25 July 2006 |
| CVE-2006-3824 | systeminfo.c for Sun Solaris allows local users to read kernel memory via a 0 variable count argument to the sysinfo system call, which causes a -1 argument to be used by the copyout function. | EXPLOIT ×2 ✓MEDIUM 4.9EPSS 0.98% | 25 July 2006 |
| CVE-2006-3823 | SQL injection vulnerability in index.php in GeodesicSolutions (1) GeoAuctions Premier 2.0.3 and (2) GeoClassifieds Basic 2.0.3 allows remote attackers to execute arbitrary SQL commands via the b parameter. | EXPLOIT ×2 ✓MEDIUM 5.1EPSS 1.89% | 25 July 2006 |
| CVE-2006-3822 | SQL injection vulnerability in index.php in GeodesicSolutions GeoAuctions Enterprise 1.0.6 allows remote attackers to execute arbitrary SQL commands via the d parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 1.03% | 25 July 2006 |
| CVE-2006-3815 | heartbeat.c in heartbeat before 2.0.6 sets insecure permissions in a shmget call for shared memory, which allows local users to cause an unspecified denial of service via unknown vectors, possibly during a short time window on startup. | EXPLOIT ✓LOW 2.1EPSS 0.78% | 25 July 2006 |
| CVE-2006-3814 | Buffer overflow in the Loader_XM::load_instrument_internal function in loader_xm.cpp for Cheese Tracker 0.9.9 and earlier allows user-assisted attackers to execute arbitrary code via a crafted file with a large amount of extra data. | EXPLOIT ✓MEDIUM 5.1EPSS 6.73% | 25 July 2006 |
| CVE-2006-3793 | PHP remote file inclusion vulnerability in constants.php in SiteDepth CMS 3.01 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the SD_DIR parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 4.19% | 24 July 2006 |
| CVE-2006-3787 | kpf4ss.exe in Sunbelt Kerio Personal Firewall 4.3.x before 4.3.268 does not properly hook the CreateRemoteThread API function, which allows local users to cause a denial of service (crash) and bypass protection mechanisms by calling CreateRemoteThread. | EXPLOIT ✓LOW 2.1EPSS 0.71% | 24 July 2006 |
| CVE-2006-3777 | PHP remote file inclusion vulnerability in index.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.21% | 24 July 2006 |
| CVE-2006-3776 | PHP remote file inclusion vulnerability in order/index.php in IDevSpot (1) PhpHostBot 1.0 and (2) AutoHost 3.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.29% | 24 July 2006 |
| CVE-2006-3775 | SQL injection vulnerability in the init function in class_session.php in MyBB (aka MyBulletinBoard) 1.1.5 allows remote attackers to execute arbitrary SQL commands via the CLIENT-IP HTTP header ($_SERVER['HTTP_CLIENT_IP'] variable), as utilized by… | EXPLOIT ✓HIGH 7.5EPSS 2.48% | 24 July 2006 |
| CVE-2006-3774 | PHP remote file inclusion vulnerability in performs.php in the perForms component (com_performs) 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 5.86% | 24 July 2006 |
| CVE-2006-3773 | PHP remote file inclusion vulnerability in smf.php in the SMF-Forum 1.3.1.3 Bridge Component (com_smf) For Joomla! and Mambo 4.5.3+ allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 5.90% | 24 July 2006 |
| CVE-2006-3772 | PHP-Post 0.21 and 1.0, and possibly earlier versions, when auto-login is enabled, allows remote attackers to bypass security restrictions and obtain administrative privileges by modifying the logincookie[user] setting in the login cookie. | EXPLOIT ✓MEDIUM 5.1EPSS 16.8% | 24 July 2006 |
| CVE-2006-3771 | Multiple PHP remote file inclusion vulnerabilities in component.php in iManage CMS 4.0.12 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to (1) articles.php, (2) contact.php, (3)… | EXPLOIT ✓HIGH 7.5EPSS 16.3% | 24 July 2006 |
| CVE-2006-3763 | SQL injection vulnerability in category.php in Diesel Joke Site allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.29% | 21 July 2006 |
| CVE-2006-3755 | PHP remote file inclusion vulnerability in Include/editor/class.rich.php in FlushCMS 1.0.0-pre2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the class_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.52% | 21 July 2006 |
| CVE-2006-3754 | PHP remote file inclusion vulnerability in Include/editor/rich_files/class.rich.php in FlushCMS 1.0.0-pre2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the class_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.82% | 21 July 2006 |
| CVE-2006-3751 | PHP remote file inclusion vulnerability in popups/ImageManager/config.inc.php in the HTMLArea3 Addon Component (com_htmlarea3_xtd-c) for ImageManager 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path… | EXPLOIT ✓MEDIUM 6.8EPSS 5.63% | 21 July 2006 |
| CVE-2006-3750 | PHP remote file inclusion vulnerability in server.php in the Hashcash Component (com_hashcash) 1.2.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 5.81% | 21 July 2006 |
| CVE-2006-3749 | PHP remote file inclusion vulnerability in sitemap.xml.php in Sitemap component (com_sitemap) 2.0.0 for Mambo 4.5.1 CMS, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path… | EXPLOIT ✓MEDIUM 6.8EPSS 3.62% | 21 July 2006 |
| CVE-2006-3748 | PHP remote file inclusion vulnerability in includes/abbc/abbc.class.php in the LoudMouth Component for Mambo 4.0j, and possibly other versions including 4.1, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path… | EXPLOIT ✓MEDIUM 6.8EPSS 4.98% | 21 July 2006 |
| CVE-2006-3736 | PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.29% | 21 July 2006 |
| CVE-2006-3735 | Multiple PHP remote file inclusion vulnerabilities in Mail2Forum (module for phpBB) 1.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the m2f_root_path parameter to (1) m2f/m2f_phpbb204.php, (2) m2f/m2f_forum.php, (3)… | EXPLOIT ✓MEDIUM 5.1EPSS 9.36% | 21 July 2006 |
| CVE-2006-3734 | Multiple unspecified vulnerabilities in the Command Line Interface (CLI) for Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1, allow local CS-MARS administrators to execute arbitrary commands as root. | EXPLOIT ✓HIGH 7.2EPSS 3.00% | 21 July 2006 |
| CVE-2006-3733 | jmx-console/HtmlAdaptor in the jmx-console in the JBoss web application server, as shipped with Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1, allows remote attackers to gain privileges as the CS-MARS administrator and… | EXPLOIT ✓HIGH 7.5EPSS 12.0% | 21 July 2006 |
| CVE-2006-3730 | Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which… | EXPLOIT ×5 ✓HIGH 8.8EPSS 63.8% | 21 July 2006 |
| CVE-2006-3729 | DataSourceControl in Internet Explorer 6 on Windows XP SP2 with Office installed allows remote attackers to cause a denial of service (crash) via a large negative integer argument to the getDataMemberName method of a OWC11.DataSourceControl.11 object,… | EXPLOIT ✓LOW 2.6EPSS 20.6% | 21 July 2006 |
| CVE-2006-3727 | Multiple SQL injection vulnerabilities in Eskolar CMS 0.9.0.0 allow remote attackers to execute arbitrary SQL commands via the (1) gr_1_id, (2) gr_2_id, (3) gr_3_id, and (4) doc_id parameters in (a) index.php; the (5) uid and (6) pwd parameters in (b)… | EXPLOIT ✓HIGH 7.5EPSS 4.30% | 21 July 2006 |
| CVE-2006-3726 | Buffer overflow in FileCOPA FTP Server before 1.01 released on 18th July 2006, allows remote authenticated attackers to execute arbitrary code via a long argument to the LIST command. | EXPLOIT ×2 ✓MEDIUM 6.5EPSS 63.7% | 21 July 2006 |
| CVE-2006-3698 | Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB01 for Change Data Capture (CDC) component and (2) DB03 for Data Pump Metadata API. | EXPLOIT ×3 ✓HIGH 10.0EPSS 6.98% | 21 July 2006 |
| CVE-2006-3696 | filtnt.sys in Outpost Firewall Pro before 3.51.759.6511 (462) allows local users to cause a denial of service (crash) via long arguments to mshta.exe. | EXPLOIT ✓LOW 2.1EPSS 0.73% | 21 July 2006 |
| CVE-2006-3693 | Rocks Clusters 4.1 and earlier allows local users to gain privileges via commands enclosed with escaped backticks (\`) in an argument to the (1) mount-loop (mount-loop.c) or (2) umount-loop (umount-loop.c) command, which is not filtered in a system… | EXPLOIT ×2 ✓MEDIUM 4.6EPSS 0.93% | 21 July 2006 |
| CVE-2006-3692 | PHP remote file inclusion vulnerability in enduser/listmessenger.php in ListMessenger 0.9.3 allows remote attackers to execute arbitrary PHP code via a URL in the lm_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.65% | 21 July 2006 |
| CVE-2006-3690 | Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to (1) components/com_minibb.php or (2) components/minibb/index.php. | EXPLOIT ✓HIGH 7.5EPSS 3.84% | 21 July 2006 |
| CVE-2006-3689 | PHP remote file inclusion vulnerability in user-func.php in Codeworks Gnomedia SubberZ[Lite] allows remote attackers to execute arbitrary PHP code via a URL in the myadmindir parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.63% | 21 July 2006 |
| CVE-2006-3687 | Stack-based buffer overflow in the Universal Plug and Play (UPnP) service in D-Link DI-524, DI-604 Broadband Router, DI-624, D-Link DI-784, WBR-1310 Wireless G Router, WBR-2310 RangeBooster G Router, and EBR-2310 Ethernet Broadband Router allows remote… | EXPLOIT ✓HIGH 7.5EPSS 19.5% | 21 July 2006 |
| CVE-2006-3685 | PHP remote file inclusion vulnerability in CzarNews 1.12 through 1.14 allows remote attackers to execute arbitrary PHP code via a URL in the tpath parameter to cn_config.php. | EXPLOIT ✓MEDIUM 5.1EPSS 2.81% | 21 July 2006 |
| CVE-2006-3683 | PHP remote file inclusion vulnerability in poll.php in Flipper Poll 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 4.29% | 21 July 2006 |
| CVE-2006-3682 | awstats.pl in AWStats 6.5 build 1.857 and earlier allows remote attackers to obtain the installation path via the (1) year, (2) pluginmode or (3) month parameters. | EXPLOIT ✓MEDIUM 5.0EPSS 9.72% | 21 July 2006 |
| CVE-2006-3680 | Cross-site scripting (XSS) vulnerability in photocycle in Photocycle 1.0 allows remote attackers to inject arbitrary web script or HTML via the phpage parameter. | EXPLOIT ✓LOW 2.6EPSS 2.24% | 21 July 2006 |
| CVE-2006-3469 | Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 allows remote authenticated users to cause a denial of service (crash) via a format string instead of a date as the first parameter to the date_format… | EXPLOIT ✓MEDIUM 4.0EPSS 29.0% | 21 July 2006 |
| CVE-2006-3468 | Linux kernel 2.6.x, when using both NFS and EXT3, allows remote attackers to cause a denial of service (file system panic) via a crafted UDP packet with a V2 lookup procedure that specifies a bad file handle (inode number), which triggers an error and… | EXPLOIT ✓HIGH 7.8EPSS 16.0% | 21 July 2006 |
| CVE-2006-3672 | KDE Konqueror 3.5.1 and earlier allows remote attackers to cause a denial of service (application crash) by calling the replaceChild method on a DOM object, which triggers a null dereference, as demonstrated by calling document.replaceChild with a 0… | EXPLOIT ✓LOW 2.6EPSS 6.87% | 18 July 2006 |
| CVE-2006-3670 | Stack-based buffer overflow in Winlpd 1.26 allows remote attackers to execute arbitrary code via a long string in a request to TCP port 515. | EXPLOIT ✓HIGH 7.5EPSS 7.43% | 18 July 2006 |
| CVE-2006-3668 | Heap-based buffer overflow in the it_read_envelope function in Dynamic Universal Music Bibliotheque (DUMB) 0.9.3 and earlier and current CVS as of 20060716, including libdumb, allows user-assisted attackers to execute arbitrary code via a ".it" (Impulse… | EXPLOIT ✓HIGH 7.6EPSS 10.1% | 18 July 2006 |
| CVE-2006-3662 | SQL injection vulnerability in index.php in ATutor 1.5.3 allows remote attackers to execute arbitrary SQL commands via the fid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.25% | 18 July 2006 |
| CVE-2006-3660 | Unspecified vulnerability in Microsoft PowerPoint 2003 has unknown impact and user-assisted attack vectors related to powerpnt.exe. | EXPLOIT ✓HIGH 7.6EPSS 18.2% | 18 July 2006 |
| CVE-2006-3656 | Unspecified vulnerability in Microsoft PowerPoint 2003 allows user-assisted attackers to cause memory corruption via a crafted PowerPoint file, which triggers the corruption when the file is closed. | EXPLOIT ✓LOW 2.6EPSS 20.5% | 18 July 2006 |
| CVE-2006-3655 | Unspecified vulnerability in mso.dll in Microsoft PowerPoint 2003 allows user-assisted attackers to execute arbitrary code via a crafted PowerPoint file. | EXPLOIT ✓MEDIUM 5.1EPSS 20.9% | 18 July 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.