Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,952 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026
25,049 results · page 391 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-3294 | PHP remote file inclusion vulnerability in mod_cbsms_messages.php in CBSMS Mambo Module 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 3.08% | 29 June 2006 |
| CVE-2006-3292 | SQL injection vulnerability in the Search gadget in Jaws 0.6.2 allows remote attackers to execute arbitrary SQL commands via queries with the "LIKE" keyword in the searchdata parameter (search field). | EXPLOIT ✓HIGH 7.5EPSS 4.67% | 28 June 2006 |
| CVE-2006-3281 | Microsoft Internet Explorer 6.0 does not properly handle Drag and Drop events, which allows remote user-assisted attackers to execute arbitrary code via a link to an SMB file share with a filename that contains encoded ..\ (%2e%2e%5c) sequences and… | EXPLOIT ✓MEDIUM 5.1EPSS 48.2% | 28 June 2006 |
| CVE-2006-3280 | Cross-domain vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a… | EXPLOIT ✓HIGH 7.5EPSS 55.9% | 28 June 2006 |
| CVE-2006-3277 | The SMTP service of MailEnable Standard 1.92 and earlier, Professional 2.0 and earlier, and Enterprise 2.0 and earlier before the MESMTPC hotfix, allows remote attackers to cause a denial of service (application crash) via a HELO command with a null… | EXPLOIT ✓MEDIUM 5.0EPSS 6.11% | 28 June 2006 |
| CVE-2006-3271 | Multiple SQL injection vulnerabilities in Softbiz Dating 1.0 allow remote attackers to execute SQL commands via the (1) country and (2) sort_by parameters in (a) search_results.php; (3) browse parameter in (b) featured_photos.php; (4) cid parameter in… | EXPLOIT ×5 ✓HIGH 7.5EPSS 1.33% | 28 June 2006 |
| CVE-2006-3269 | PHP remote file inclusion vulnerability in includes/functions_cms.php in THoRCMS 1.3.1 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 3.08% | 28 June 2006 |
| CVE-2006-3256 | SQL injection vulnerability in report.php in Woltlab Burning Board (WBB) 2.3.1 allows remote attackers to execute arbitrary SQL commands via the postid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.14% | 28 June 2006 |
| CVE-2006-3255 | SQL injection vulnerability in showmods.php in Woltlab Burning Board (WBB) 1.2 allows remote attackers to execute arbitrary SQL commands via the boardid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.13% | 28 June 2006 |
| CVE-2006-3254 | SQL injection vulnerability in newthread.php in Woltlab Burning Board (WBB) 2.0 RC2 allows remote attackers to execute arbitrary SQL commands via the boardid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.13% | 28 June 2006 |
| CVE-2006-3253 | Cross-site scripting (XSS) vulnerability in member.php in vBulletin 3.5.x allows remote attackers to inject arbitrary web script or HTML via the u parameter. | EXPLOIT ✓LOW 2.6EPSS 2.00% | 28 June 2006 |
| CVE-2006-1470 | OpenLDAP in Apple Mac OS X 10.4 up to 10.4.6 allows remote attackers to cause a denial of service (crash) via an invalid LDAP request that triggers an assert error. | EXPLOIT ✓MEDIUM 5.0EPSS 8.13% | 27 June 2006 |
| CVE-2006-3266 | Multiple PHP remote file inclusion vulnerabilities in Bee-hive Lite 1.2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) header parameter to (a) conad/include/rootGui.inc.php and… | EXPLOIT ✓MEDIUM 5.1EPSS 18.0% | 27 June 2006 |
| CVE-2006-3262 | SQL injection vulnerability in the Weblinks module (weblinks.php) in Mambo 4.6rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.49% | 27 June 2006 |
| CVE-2006-3259 | Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.5 allow remote attackers to inject arbitrary web script or HTML via the (1) ep parameter to search.php and the (2) subject parameter in comment.php (aka the Subject field when posting a… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 4.29% | 27 June 2006 |
| CVE-2006-3252 | Buffer overflow in the Online Registration Facility for Algorithmic Research PrivateWire VPN software up to 3.7 allows remote attackers to execute arbitrary code via a long GET request. | EXPLOIT ×2 ✓HIGH 7.5EPSS 62.2% | 27 June 2006 |
| CVE-2006-3245 | Multiple cross-site scripting (XSS) vulnerabilities in activatemember in mvnForum 1.0 GA and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) member and (2) activatecode parameters. | EXPLOIT ✓LOW 2.6EPSS 1.77% | 27 June 2006 |
| CVE-2006-3011 | The error_log function in basic_functions.c in PHP before 4.4.4 and 5.x before 5.1.5 allows local users to bypass safe mode and open_basedir restrictions via a "php://" or other scheme in the third argument, which disables safe mode. | EXPLOIT ✓MEDIUM 4.6EPSS 1.34% | 26 June 2006 |
| CVE-2006-3228 | Buffer overflow in in_midi.dll for WinAmp 2.90 up to 5.23, including 5.21, allows remote attackers to execute arbitrary code via a crafted .mid (MIDI) file. | EXPLOIT ✓HIGH 9.3EPSS 11.7% | 26 June 2006 |
| CVE-2006-2310 | BlueDragon Server and Server JX 6.2.1.286 for Windows allows remote attackers to cause a denial of service (hang) via a request for a .cfm file whose name contains an MS-DOS device name such as (1) con, (2) aux, (3) com1, and (4) com2. | EXPLOIT ✓MEDIUM 5.0EPSS 6.80% | 26 June 2006 |
| CVE-2006-3221 | SQL injection vulnerability in index.php in DataLife Engine 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via double-encoded values in the user parameter in a userinfo subaction. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.26% | 24 June 2006 |
| CVE-2006-3213 | SQL injection vulnerability in WeBBoA Hosting 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter to an unspecified script, possibly host/yeni_host.asp. | EXPLOIT ✓HIGH 7.5EPSS 1.25% | 24 June 2006 |
| CVE-2006-3210 | Ralf Image Gallery (RIG) 0.7.4 and other versions before 1.0, when register_globals is enabled, allows remote attackers to conduct PHP remote file inclusion and directory traversal attacks via URLs or ".." sequences in the (1) dir_abs_src parameter in… | EXPLOIT ✓MEDIUM 5.1EPSS 13.5% | 24 June 2006 |
| CVE-2006-3199 | Opera 9 allows remote attackers to cause a denial of service (crash) via an A tag with an href attribute with a URL containing a long hostname, which triggers an out-of-bounds operation. | EXPLOIT ✓MEDIUM 5.0EPSS 14.6% | 23 June 2006 |
| CVE-2006-2914 | PHP remote file inclusion vulnerability in DeluxeBB 1.06 allows remote attackers to execute arbitrary code via a URL in the templatefolder parameter to (1) postreply.php, (2) posting.php, (3) and pm/newpm.php in the deluxe/ directory, and (4)… | EXPLOIT ✓MEDIUM 5.1EPSS 20.7% | 23 June 2006 |
| CVE-2006-3195 | Cross-site scripting (XSS) vulnerability in index.php in singapore 0.10.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the template parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.70% | 23 June 2006 |
| CVE-2006-3194 | Directory traversal vulnerability in index.php in singapore 0.10.0 and earlier allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.4EPSS 2.95% | 23 June 2006 |
| CVE-2006-3193 | Multiple PHP remote file inclusion vulnerabilities in Grayscale BandSite CMS 1.1.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) includes/content/contact_content.php;… | EXPLOIT ✓MEDIUM 5.1EPSS 14.8% | 23 June 2006 |
| CVE-2006-3192 | PHP remote file inclusion vulnerability in Ad Manager Pro 2.6 allows remote attackers to execute arbitrary PHP code via a URL in the (1) ipath parameter in common.php and (2) unspecified vectors in ad.php. | EXPLOIT ✓HIGH 7.5EPSS 9.46% | 23 June 2006 |
| CVE-2006-3191 | Cross-site scripting (XSS) vulnerability in comment.php in MPCS 0.2 allows remote attackers to inject arbitrary web script or HTML via the pageid parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.77% | 23 June 2006 |
| CVE-2006-3189 | Cross-site scripting (XSS) vulnerability in administration/tblcontent/login1.php in HotPlug CMS 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | EXPLOIT ✓MEDIUM 5.8EPSS 1.71% | 23 June 2006 |
| CVE-2006-3186 | Multiple cross-site scripting (XSS) vulnerabilities in CMS Faethon 1.3.2 allow remote attackers to inject arbitrary web script or HTML via the mainpath parameter to (1) data/footer.php and (2) admin/header.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.71% | 23 June 2006 |
| CVE-2006-3185 | PHP remote file inclusion vulnerability in data/header.php in CMS Faethon 1.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the mainpath parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.43% | 23 June 2006 |
| CVE-2006-3184 | Direct static code injection vulnerability in ASP Stats Generator before 2.1.2 allows remote authenticated attackers to execute arbitrary ASP code via the strAsgSknPageBgColour parameter to settings_skin.asp, which is stored in inc_skin_file.asp. | EXPLOIT ✓MEDIUM 4.0EPSS 2.29% | 23 June 2006 |
| CVE-2006-3177 | PHP remote file inclusion vulnerability in Admin/rtf_parser.php in The Bible Portal Project 2.12 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the destination parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.45% | 23 June 2006 |
| CVE-2006-3176 | SQL injection vulnerability in xarancms_haupt.php in xarancms 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.24% | 23 June 2006 |
| CVE-2006-3175 | Multiple PHP remote file inclusion vulnerabilities in mcGuestbook 1.3 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) admin.php, (2) ecrire.php, and (3) lire.php. | EXPLOIT ×3 ✓HIGH 7.5EPSS 9.01% | 23 June 2006 |
| CVE-2006-3173 | Multiple PHP remote file inclusion vulnerabilities in Content*Builder 0.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) path[cb] parameter to (a) libraries/comment/postComment.php and (b) modules/poll/poll.php, (2) rel… | EXPLOIT ✓HIGH 7.5EPSS 2.54% | 23 June 2006 |
| CVE-2006-3172 | Multiple PHP remote file inclusion vulnerabilities in Content*Builder 0.7.5 allow remote attackers to execute arbitrary PHP code via a URL with a trailing slash (/) character in the (1) lang_path parameter to (a) cms/plugins/col_man/column.inc.php, (b)… | EXPLOIT ✓HIGH 7.5EPSS 15.6% | 23 June 2006 |
| CVE-2006-3162 | PHP remote file inclusion vulnerability in include/inc_foot.php in SmartSiteCMS 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter. | EXPLOIT ✓HIGH 7.5EPSS 7.07% | 22 June 2006 |
| CVE-2006-3161 | SQL injection vulnerability in misc.php in SaphpLesson 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the action parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.14% | 22 June 2006 |
| CVE-2006-3158 | index.php in Eduha Meeting does not properly restrict file extensions before permitting a file upload, which allows remote attackers to bypass security checks and upload or execute arbitrary php code via the add action. | EXPLOIT ✓HIGH 7.5EPSS 3.18% | 22 June 2006 |
| CVE-2006-3151 | Cross-site scripting (XSS) vulnerability in index.php in AssoCIateD (aka ACID) 1.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the menu parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.88% | 22 June 2006 |
| CVE-2006-3147 | Unspecified vulnerability in Hosting Controller before 6.1 (aka Hotfix 3.2) allows remote authenticated attackers to gain host admin privileges, list all resellers, or change resellers' passwords via unspecified vectors. | EXPLOIT ✓MEDIUM 6.5EPSS 2.67% | 22 June 2006 |
| CVE-2006-3144 | PHP remote file inclusion vulnerability in micro_cms_files/microcms-include.php in Implied By Design (IBD) Micro CMS 3.5 (aka 0.3.5) and earlier allows remote attackers to execute arbitrary PHP code via a URL in the microcms_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 8.99% | 22 June 2006 |
| CVE-2006-3143 | Cross-site scripting (XSS) vulnerability in icue_login.asp in Maximus SchoolMAX 4.0.1 and earlier iCue and iParent applications allows remote attackers to inject arbitrary web script or HTML via the error_msg parameter. | EXPLOIT ✓MEDIUM 4.0EPSS 1.77% | 22 June 2006 |
| CVE-2006-3142 | SQL injection vulnerability in forum.php in VBZooM 1.11 allows remote attackers to execute arbitrary SQL commands via the MainID parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.14% | 22 June 2006 |
| CVE-2006-3014 | Microsoft Excel allows user-assisted attackers to execute arbitrary javascript and redirect users to arbitrary sites via an Excel spreadsheet with an embedded Shockwave Flash Player ActiveX Object, which is automatically executed when the user opens the… | EXPLOIT ✓MEDIUM 5.1EPSS 30.1% | 22 June 2006 |
| CVE-2006-3109 | Cross-site scripting (XSS) vulnerability in Cisco CallManager 3.3 before 3.3(5)SR3, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3), and 4.3 before 4.3(1), allows remote attackers to inject arbitrary web script or HTML via the (1) pattern parameter in… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 13.7% | 21 June 2006 |
| CVE-2006-3105 | CRLF injection vulnerability in Bitweaver 1.3 allows remote attackers to conduct HTTP response splitting attacks by via CRLF sequences in multiple unspecified parameters that are injected into HTTP headers, as demonstrated by the BWSESSION parameter in… | EXPLOIT ✓MEDIUM 5.0EPSS 2.67% | 21 June 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.