SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-29 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,952 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026

25,049 results · page 389 of 501

CVESummaryPriorityPublished
CVE-2006-3653wksss.exe 8.4.702.0 in Microsoft Works Spreadsheet 8.0 allows remote attackers to cause a denial of service (CPU consumption or crash) via crafted (1) Works, (2) Excel, and (3) Lotus 1-2-3 files.EXPLOIT ✓LOW 2.6EPSS 14.9%18 July 2006
CVE-2006-3624Multiple cross-site scripting (XSS) vulnerabilities in FLV Players 8 allow remote attackers to inject arbitrary web script or HTML via the url parameter to (1) player.php or (2) popup.php.EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.72%18 July 2006
CVE-2006-3621SQL injection vulnerability in the showtopic module in Koobi Pro CMS 5.6 allows remote attackers to execute arbitrary SQL commands via the toid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.14%18 July 2006
CVE-2006-3616Multiple cross-site scripting (XSS) vulnerabilities in Carbonize Lazarus Guestbook 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the show parameter in codes-english.php and (2) the img parameter in picture.php,…EXPLOIT ×2 ✓MEDIUM 4.3EPSS 2.48%18 July 2006
CVE-2006-3611Directory traversal vulnerability in pm.php in Phorum 5 allows remote authenticated users to include and execute arbitrary local files via directory traversal sequences in the GLOBALS[template] parameter, as demonstrated by injecting PHP sequences into…EXPLOIT ✓MEDIUM 5.5EPSS 2.16%18 July 2006
CVE-2006-3608The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, which allows remote authenticated users to execute arbitrary PHP code via…EXPLOIT ✓MEDIUM 4.6EPSS 2.26%18 July 2006
CVE-2006-3607Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Banner Exchange Script (aka Banner Exchange Network Script) 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the city parameter in (a) insertmember.php, and (2) a…EXPLOIT ×4 ✓MEDIUM 4.3EPSS 1.76%18 July 2006
CVE-2006-3605Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Transition property on an uninitialized DXImageTransform.Microsoft.RevealTrans.1 ActiveX Object, which triggers a null dereference.EXPLOIT ✓MEDIUM 5.0EPSS 24.3%18 July 2006
CVE-2006-3604Directory traversal vulnerability in FlexWATCH Network Camera 3.0 and earlier allows remote attackers to bypass access restrictions for (1) admin/aindex.asp or (2) admin/aindex.html via a ..EXPLOIT ✓HIGH 7.5EPSS 3.11%18 July 2006
CVE-2006-3603Cross-site scripting (XSS) vulnerability in index.php in FlexWATCH Network Camera 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL.EXPLOIT ✓MEDIUM 5.8EPSS 2.02%18 July 2006
CVE-2006-3602Directory traversal vulnerability in jscripts/tiny_mce/tiny_mce_gzip.php in FarsiNews 3.0 BETA 1 allows remote attackers to include arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.75%18 July 2006
CVE-2006-3591Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (application crash) by accessing the URL property of a TriEditDocument.TriEditDocument object before it has been initialized, which triggers a NULL pointer dereference.EXPLOIT ✓MEDIUM 5.0EPSS 26.2%18 July 2006
CVE-2006-3581Multiple stack-based buffer overflows in Audacious AdPlug 2.0 and earlier allow remote user-assisted attackers to execute arbitrary code via large (1) DTM and (2) S3M files.EXPLOIT ✓MEDIUM 5.1EPSS 13.0%13 July 2006
CVE-2006-3580SQL injection vulnerability in pages.asp in ASP Stats Generator before 2.1.2 allows remote attackers to execute arbitrary SQL commands via the order parameter.EXPLOIT ✓HIGH 7.5EPSS 1.24%13 July 2006
CVE-2006-3577SQL injection vulnerability in index.php in LifeType 1.0.5 allows remote attackers to execute arbitrary SQL commands via the Date parameter in a Default op.EXPLOIT ✓HIGH 7.5EPSS 1.09%13 July 2006
CVE-2006-3572SQL injection vulnerability in forumthread.php in Papoo 3 RC3 and earlier allows remote attackers to execute arbitrary SQL commands via the msgid parameter.EXPLOIT ✓HIGH 7.5EPSS 2.01%13 July 2006
CVE-2006-3571Multiple cross-site scripting (XSS) vulnerabilities in interna/hilfe.php in Papoo 3 RC3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) titel or (2) ausgabe parameters.EXPLOIT ✓LOW 2.6EPSS 2.44%13 July 2006
CVE-2006-3568Multiple cross-site scripting (XSS) vulnerabilities in guestbook.php in Fantastic Guestbook 2.0.1, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) first_name, (2) last_name, or (3) nickname…EXPLOIT ✓MEDIUM 4.3EPSS 2.29%13 July 2006
CVE-2006-3563Cross-site scripting (XSS) vulnerability in gallery/thumb.php in Winged Gallery 1.0 allows remote attackers to inject arbitrary web script or HTML via the image parameter.EXPLOIT ✓LOW 2.6EPSS 1.77%13 July 2006
CVE-2006-3562PHP remote file inclusion vulnerabilities in plume cms 1.0.4 allow remote attackers to execute arbitrary PHP code via a URL in the _PX_config[manager_path] parameter to (1) index.php, (2) rss.php, or (3) search.php, a different set of vectors and…EXPLOIT ×3 ✓HIGH 7.5EPSS 3.12%13 July 2006
CVE-2006-3561BT Voyager 2091 Wireless firmware 2.21.05.08m_A2pB018c1.d16d and earlier, and 3.01m and earlier, allow remote attackers to bypass the authentication process and gain sensitive information, such as configuration information via (1)…EXPLOIT ✓MEDIUM 5.0EPSS 6.72%13 July 2006
CVE-2006-3560SQL injection vulnerability in topics.php in Blue Dojo Graffiti Forums 1.0 allows remote attackers to execute arbitrary SQL commands via the f parameter.EXPLOIT ✓HIGH 7.5EPSS 1.29%13 July 2006
CVE-2006-3556PHP remote file inclusion vulnerability in extcalendar.php in Mohamed Moujami ExtCalendar 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.EXPLOIT ✓MEDIUM 6.8EPSS 6.92%13 July 2006
CVE-2006-3546Patrice Freydiere ImgSvr (aka ADA Image Server) allows remote attackers to cause a denial of service (daemon crash) via a long HTTP POST request.EXPLOIT ×2 ✓MEDIUM 5.0EPSS 3.36%13 July 2006
CVE-2006-3543Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 1.x and 2.x allow remote attackers to execute arbitrary SQL commands via the (1) idcat and (2) code parameters in a ketqua action in index.php; the id parameter in a (3) Attach and (4)…EXPLOIT ✓HIGH 7.5EPSS 1.09%13 July 2006
CVE-2006-3533Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.30 RC2 and earlier, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) fg, (2) line1, (3) line2, (4) bg, (5) c1, (6) c2, (7) c3, and…EXPLOIT ✓MEDIUM 5.8EPSS 5.98%12 July 2006
CVE-2006-3532PHP file inclusion vulnerability in includes/edit_new.php in Pivot 1.30 RC2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a FTP URL or full file path in the Paths[extensions_path] parameter.EXPLOIT ✓MEDIUM 5.1EPSS 8.04%12 July 2006
CVE-2006-3531includes/editor/insert_image.php in Pivot 1.30 RC2 and earlier creates the authentication credentials from parameters, which allows remote attackers to obtain privileges and upload arbitrary files via modified (1) pass and (2) session parameters, and…EXPLOIT ✓HIGH 7.5EPSS 9.53%12 July 2006
CVE-2006-3530PHP remote file inclusion vulnerability in com_pccookbook/pccookbook.php in the PccookBook Component for Mambo and Joomla 0.3 and possibly up to 1.3.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the…EXPLOIT ✓MEDIUM 6.8EPSS 6.25%12 July 2006
CVE-2006-3528Multiple PHP remote file inclusion vulnerabilities in Simpleboard Mambo module 1.1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the sbp parameter to (1) image_upload.php and (2) file_upload.php.EXPLOIT ✓MEDIUM 6.8EPSS 3.62%12 July 2006
CVE-2006-3524Buffer overflow in SIPfoundry sipXtapi released before 20060324 allows remote attackers to execute arbitrary code via a long CSeq field value in an INVITE message.EXPLOIT ×4 ✓HIGH 7.5EPSS 67.5%12 July 2006
CVE-2006-3520PHP remote file inclusion vulnerability in skins/advanced/advanced1.php in Sabdrimer Pro 2.2.4, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pluginpath[0] parameter.EXPLOIT ✓HIGH 7.5EPSS 2.54%12 July 2006
CVE-2006-3518SQL injection vulnerability in SayfalaAltList.asp in Webvizyon Portal 2006 allows remote attackers to execute arbitrary SQL commands via the ID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.29%11 July 2006
CVE-2006-3517PHP remote file inclusion vulnerability in stats.php in RW::Download, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.EXPLOIT ✓HIGH 7.5EPSS 2.52%11 July 2006
CVE-2006-3513danim.dll in Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (application crash) by accessing the Data property of a DirectAnimation DAUserData object before it is initialized, which triggers a NULL pointer dereference.EXPLOIT ✓MEDIUM 5.0EPSS 22.7%11 July 2006
CVE-2006-3512Internet Explorer 6 on Windows XP allows remote attackers to cause a denial of service (crash) by setting the Enabled property of a DXTFilter ActiveX object to true, which triggers a null dereference.EXPLOIT ✓MEDIUM 5.0EPSS 24.3%11 July 2006
CVE-2006-3511Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by setting the fonts property of the HtmlDlgSafeHelper object, which triggers a null dereference.EXPLOIT ✓MEDIUM 5.0EPSS 21.6%11 July 2006
CVE-2006-3510The Remote Data Service Object (RDS.DataControl) in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (crash) via a series of operations that result in an invalid length calculation when using…EXPLOIT ✓LOW 2.6EPSS 14.8%11 July 2006
CVE-2006-0026Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP).EXPLOIT ✓MEDIUM 6.5EPSS 89.3%11 July 2006
CVE-2006-2389Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with a malformed property that triggers memory corruption…EXPLOIT ✓HIGH 9.3EPSS 38.7%11 July 2006
CVE-2006-2372Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a crafted DHCP response.EXPLOIT ✓HIGH 10.0EPSS 90.2%11 July 2006
CVE-2006-1315The Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to obtain sensitive information via crafted requests that leak information in SMB buffers, which are…EXPLOIT ✓MEDIUM 5.0EPSS 48.8%11 July 2006
CVE-2006-1314Heap-based buffer overflow in the Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to execute arbitrary code via crafted first-class Mailslot messages that…EXPLOIT ✓HIGH 7.5EPSS 61.2%11 July 2006
CVE-2006-3493Buffer overflow in LsCreateLine function (mso_203) in mso.dll and mso9.dll, as used by Microsoft Word and possibly other products in Microsoft Office 2003, 2002, and 2000, allows remote user-assisted attackers to cause a denial of service (crash) via a…EXPLOIT ✓MEDIUM 5.1EPSS 40.4%10 July 2006
CVE-2006-3491Stack-based buffer overflow in Kaillera Server 0.86 and earlier allows remote attackers to execute arbitrary code via a long nickname.EXPLOIT ✓HIGH 7.5EPSS 6.17%10 July 2006
CVE-2006-3484Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 1.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) show_courses or (2) current_cat parameters to (a) admin/create_course.php, show_courses parameter to (b)…EXPLOIT ×5 ✓LOW 2.6EPSS 2.69%10 July 2006
CVE-2006-3478PHP remote file inclusion vulnerability in styles/default/global_header.php in MyPHP CMS 0.3 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the domain parameter.EXPLOIT ✓HIGH 7.5EPSS 2.54%10 July 2006
CVE-2006-3476Cross-site scripting (XSS) vulnerability in comments.php in PhpWebGallery 1.5.2 and earlier, and possibly 1.6.0, allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.94%10 July 2006
CVE-2006-3475Multiple PHP remote file inclusion vulnerabilities in free QBoard 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the qb_path parameter to (1) index.php, (2) about.php, (3) contact.php, (4) delete.php, (5) faq.php, (6) features.php…EXPLOIT ×7 ✓HIGH 7.5EPSS 8.16%10 July 2006
CVE-2006-3474Multiple SQL injection vulnerabilities in Belchior Foundry vCard PRO allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to (a) gbrowse.php, (2) card_id parameter to (b) rating.php and (c) create.php, and the (3)…EXPLOIT ×4 ✓HIGH 7.5EPSS 1.15%10 July 2006

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.