Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,952 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026
25,049 results · page 390 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-3472 | Microsoft Internet Explorer 6.0 and 6.0 SP1 allows remote attackers to cause a denial of service via an HTML page with an A tag containing a long title attribute. | EXPLOIT ✓MEDIUM 5.0EPSS 10.6% | 10 July 2006 |
| CVE-2006-3471 | Microsoft Internet Explorer 6 on Windows XP allows remote attackers to cause a denial of service (crash) via a table with a frameset as a child, which triggers a null dereference, as demonstrated using the appendChild method. | EXPLOIT ✓MEDIUM 5.0EPSS 20.8% | 10 July 2006 |
| CVE-2006-3431 | Buffer overflow in certain Asian language versions of Microsoft Excel might allow user-assisted attackers to execute arbitrary code via a crafted STYLE record in a spreadsheet that triggers the overflow when the user attempts to repair the document or… | EXPLOIT ✓HIGH 7.5EPSS 28.3% | 7 July 2006 |
| CVE-2006-2451 | The suid_dumpable support in Linux kernel 2.6.13 up to versions before 2.6.17.4, and 2.6.16 before 2.6.16.24, allows a local user to cause a denial of service (disk consumption) and possibly gain privileges via the PR_SET_DUMPABLE argument of the prctl… | EXPLOIT ×5 ✓MEDIUM 4.6EPSS 4.39% | 7 July 2006 |
| CVE-2006-3427 | Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by declaring the sourceURL attribute on an uninitialized DirectAnimation.StructuredGraphicsControl ActiveX Object, which triggers a null dereference. | EXPLOIT ✓MEDIUM 5.0EPSS 24.3% | 7 July 2006 |
| CVE-2006-3422 | PHP remote file inclusion vulnerability in WonderEdit Pro CMS allows remote attackers to execute arbitrary PHP code via the config[template_path] parameter in user_bottom.php, as used by multiple templates including (1) rwb… | EXPLOIT ✓HIGH 7.5EPSS 2.54% | 7 July 2006 |
| CVE-2006-3421 | PHP remote file inclusion vulnerability in SmartSiteCMS 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the root parameter in (1) comment.php, (2) admin/comedit.php, (3) admin/test.php, (4)… | EXPLOIT ×2 ✓MEDIUM 5.1EPSS 4.23% | 7 July 2006 |
| CVE-2006-3405 | Cross-site scripting (XSS) vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) delete, (2) pathext, and (3) edit parameters. | EXPLOIT ✓MEDIUM 5.8EPSS 1.79% | 7 July 2006 |
| CVE-2006-3402 | SQL injection vulnerability in VirtuaStore 2.0 allows remote attackers to execute arbitrary SQL commands via the password parameter when logging in. | EXPLOIT ✓HIGH 7.5EPSS 1.12% | 6 July 2006 |
| CVE-2006-3401 | Stack-based buffer overflow in Quake 3 Engine as used by Quake 3: Arena 1.32b and 1.32c allows remote attackers to cause a denial of service and possibly execute code via long CS_ITEMS values. | EXPLOIT ✓HIGH 7.5EPSS 5.74% | 6 July 2006 |
| CVE-2006-3400 | Stack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP) GOLD 1.03 allows remote attackers to cause a denial of service and possibly execute code by sending a long command from the server. | EXPLOIT ✓HIGH 7.5EPSS 4.84% | 6 July 2006 |
| CVE-2006-3396 | PHP remote file inclusion vulnerability in galleria.html.php in Galleria Mambo Module 1.0 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 3.83% | 6 July 2006 |
| CVE-2006-3395 | PHP remote file inclusion vulnerability in top.php in SiteBuilder-FX 3.5 allows remote attackers to execute arbitrary PHP code via a URL in the admindir parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 3.14% | 6 July 2006 |
| CVE-2006-3394 | SQL injection vulnerability in the files mod in index.php in BXCP 0.3.0.4 allows remote attackers to execute arbitrary SQL commands via the where parameter in a view action. | EXPLOIT ✓HIGH 7.5EPSS 1.32% | 6 July 2006 |
| CVE-2006-3392 | Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes… | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 78.3% | 6 July 2006 |
| CVE-2006-3387 | Directory traversal vulnerability in sources/post.php in Fusion News 1.0, when register_globals is enabled, allows remote attackers to include arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.1EPSS 1.99% | 6 July 2006 |
| CVE-2006-3385 | Cross-site scripting (XSS) vulnerability in divers.php in Vincent Leclercq News 5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) id and (2) disabled parameters. | EXPLOIT ✓MEDIUM 5.8EPSS 1.97% | 6 July 2006 |
| CVE-2006-3381 | SturGeoN Upload allows remote attackers to execute arbitrary PHP code by uploading a file with a .php extension, then directly accessing the file. | EXPLOIT ✓HIGH 7.5EPSS 2.62% | 6 July 2006 |
| CVE-2006-3375 | PHP remote file inclusion vulnerability in includes/header.inc.php in Randshop 1.1.1 allows remote attackers to execute arbitrary PHP code via the dateiPfad parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.81% | 6 July 2006 |
| CVE-2006-3374 | PHP remote file inclusion vulnerability in index.php in Randshop 1.2 and earlier, including 0.9.3, allows remote attackers to execute arbitrary PHP code via a URL in the incl parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.61% | 6 July 2006 |
| CVE-2006-3372 | Apple Safari 2.0.4/419.3 allows remote attackers to cause a denial of service (application crash) via a DHTML setAttributeNode function call with zero arguments, which triggers a null dereference. | EXPLOIT ✓MEDIUM 5.0EPSS 9.20% | 6 July 2006 |
| CVE-2006-3366 | Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or HTML via crafted HTML tags, as demonstrated by the IMG tag, in the (1) id parameter in (a) mail/index.php and (b) mail/reply.php; (2)… | EXPLOIT ×7 ✓LOW 2.6EPSS 1.85% | 6 July 2006 |
| CVE-2006-3364 | SQL injection vulnerability in index.php in the NP_SEO plugin in BLOG:CMS before 4.1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.10% | 6 July 2006 |
| CVE-2006-3363 | PHP remote file inclusion vulnerability in index.php in the Glossaire module 1.7 for Xoops allows remote attackers to execute arbitrary PHP code via a URL in the pa parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 3.31% | 6 July 2006 |
| CVE-2006-3362 | Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 through 1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka Stable and earlier, (3) WeBid 0.5.4, and possibly other products, when… | EXPLOIT ✓MEDIUM 5.1EPSS 5.06% | 6 July 2006 |
| CVE-2006-3361 | PHP remote file inclusion vulnerability in Stud.IP 1.3.0-2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the (1) _PHPLIB[libdir] parameter in studip-phplib/oohforms.inc and (2)… | EXPLOIT ✓MEDIUM 5.1EPSS 2.70% | 6 July 2006 |
| CVE-2006-3359 | Multiple SQL injection vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) topmenuitem, and (4) cat_id parameters in (a) index.php; and the (5) category parameter… | EXPLOIT ✓HIGH 7.5EPSS 1.12% | 6 July 2006 |
| CVE-2006-3358 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) cat_id, and (4) tim parameters, which are not sanitized before being… | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 1.65% | 6 July 2006 |
| CVE-2006-3355 | Heap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to execute arbitrary code via a long URL, which is not properly terminated before being used with the strncpy function. | EXPLOIT ✓HIGH 7.5EPSS 6.52% | 6 July 2006 |
| CVE-2006-3354 | Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Filter property of an ADODB.Recordset ActiveX object to certain values multiple times, which triggers a null dereference. | EXPLOIT ✓MEDIUM 5.0EPSS 17.1% | 6 July 2006 |
| CVE-2006-3353 | Opera 9 allows remote attackers to cause a denial of service (crash) via a crafted web page that triggers an out-of-bounds memory access, related to an iframe and JavaScript that accesses certain style sheets properties. | EXPLOIT ✓MEDIUM 5.0EPSS 8.36% | 6 July 2006 |
| CVE-2006-3347 | SQL injection vulnerability in index.php in deV!Lz Clanportal DZCP 1.3.4 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.25% | 3 July 2006 |
| CVE-2006-3343 | PHP remote file inclusion vulnerability in recipe/cookbook.php in CrisoftRicette 1.0pre15b allows remote attackers to execute arbitrary PHP code via a URL in the crisoftricette parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.54% | 3 July 2006 |
| CVE-2006-3341 | SQL injection vulnerability in annonces-p-f.php in MyAds module 2.04jp for Xoops allows remote attackers to execute arbitrary SQL commands via the lid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.14% | 3 July 2006 |
| CVE-2006-3340 | Multiple PHP remote file inclusion vulnerabilities in Pearl For Mambo module 1.6 for Mambo, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via the (1) phpbb_root_path parameter in (a) includes/functions_cms.php… | EXPLOIT ✓MEDIUM 5.1EPSS 15.6% | 3 July 2006 |
| CVE-2006-3337 | Cross-site scripting (XSS) vulnerability in frontend/x/files/select.html in cPanel 10.8.2-CURRENT 118 and earlier allows remote attackers to inject arbitrary web script or HTML via the file parameter. | EXPLOIT ✓LOW 2.6EPSS 2.16% | 3 July 2006 |
| CVE-2006-3329 | SQL injection vulnerability in search.php in PHP/MySQL Classifieds (PHP Classifieds) allows remote attackers to execute arbitrary SQL commands via the rate parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.12% | 30 June 2006 |
| CVE-2006-3325 | client/cl_parse.c in the id3 Quake 3 Engine 1.32c and the Icculus Quake 3 Engine (ioquake3) revision 810 and earlier allows remote malicious servers to overwrite arbitrary write-protected cvars variables on the client, such as cl_allowdownload for… | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 4.76% | 30 June 2006 |
| CVE-2006-3324 | The Automatic Downloading option in the id3 Quake 3 Engine and the Icculus Quake 3 Engine (ioquake3) before revision 804 allows remote attackers to overwrite arbitrary files in the quake3 directory (fs_homepath cvar) via a long string of filenames, as… | EXPLOIT ✓MEDIUM 5.0EPSS 4.44% | 30 June 2006 |
| CVE-2006-3323 | PHP remote file inclusion vulnerability in admin/admin.php in MF Piadas 1.0 allows remote attackers to execute arbitrary PHP code via the page parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 7.76% | 30 June 2006 |
| CVE-2006-3317 | PHP remote file inclusion vulnerability in phpRaid 3.0.6 allows remote attackers to execute arbitrary code via a URL in the phpraid_dir parameter to (1) announcements.php and (2) rss.php, a different set of vectors and affected versions than… | EXPLOIT ✓MEDIUM 5.1EPSS 17.1% | 29 June 2006 |
| CVE-2006-3315 | PHP remote file inclusion vulnerability in page.php in an unspecified RahnemaCo.com product, possibly eShop, allows remote attackers to execute arbitrary PHP code via a URL in the osCsid parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.60% | 29 June 2006 |
| CVE-2006-3314 | PHP remote file inclusion vulnerability in page.php in an unspecified RahnemaCo.com product, possibly eShop, allows remote attackers to execute arbitrary PHP code via a URL in the pageid parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.89% | 29 June 2006 |
| CVE-2006-3309 | SQL injection vulnerability in SPT--ForumTopics.php in Scout Portal Toolkit (SPT) 1.4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the forumid parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.56% | 29 June 2006 |
| CVE-2006-3304 | SQL injection vulnerability in cp.php in DeluxeBB 1.07 and earlier allows remote attackers to execute arbitrary SQL commands via the xmsn parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.62% | 29 June 2006 |
| CVE-2006-3300 | PHP remote file inclusion vulnerability in sms_config/gateway.php in PhpMySms 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ROOT_PATH parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.45% | 29 June 2006 |
| CVE-2006-3299 | Cross-site scripting (XSS) vulnerability in index.php in Usenet Script 0.5 allows remote attackers to inject arbitrary web script or HTML via the group parameter. | EXPLOIT ✓LOW 2.6EPSS 1.95% | 29 June 2006 |
| CVE-2006-3298 | Messenger 7.5.0.814 and 7.0.438 allows remote attackers to cause a denial of service (crash) via messages that contain non-ASCII characters, which triggers the crash in jscript.dll. | EXPLOIT ✓MEDIUM 5.0EPSS 2.99% | 29 June 2006 |
| CVE-2006-3296 | SQL injection vulnerability in view.php in Open Guestbook 0.5 allows remote attackers to execute arbitrary SQL commands via the offset parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.25% | 29 June 2006 |
| CVE-2006-3295 | Cross-site scripting (XSS) vulnerability in header.php in Open Guestbook 0.5 allows remote attackers to inject arbitrary web script or HTML via the title parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 2.31% | 29 June 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.