Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,952 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026
25,049 results · page 392 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-3104 | users/index.php in Bitweaver 1.3 allows remote attackers to obtain sensitive information via an invalid sort_mode parameter, which reveals the installation path and database information in the resultant error message. | EXPLOIT ✓MEDIUM 5.0EPSS 8.87% | 21 June 2006 |
| CVE-2006-3103 | Cross-site scripting (XSS) vulnerability in Bitweaver 1.3 allows remote attackers to inject arbitrary web script or HTML via the (1) error parameter in users/login.php and the (2) feedback parameter in articles/index.php. | EXPLOIT ✓MEDIUM 4.3EPSS 4.74% | 21 June 2006 |
| CVE-2006-3102 | Race condition in articles/BitArticle.php in Bitweaver 1.3, when run on Apache with the mod_mime extension, allows remote attackers to execute arbitrary PHP code by uploading arbitrary files with double extensions, which are stored for a small period of… | EXPLOIT ✓MEDIUM 5.1EPSS 8.45% | 21 June 2006 |
| CVE-2006-3101 | Cross-site scripting (XSS) vulnerability in LogonProxy.cgi in Cisco Secure ACS for UNIX 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) error, (2) SSL, and (3) Ok parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 24.0% | 21 June 2006 |
| CVE-2006-3086 | Stack-based buffer overflow in the HrShellOpenWithMonikerDisplayName function in Microsoft Hyperlink Object Library (hlink.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long hyperlink, as… | EXPLOIT ✓HIGH 9.3EPSS 56.5% | 19 June 2006 |
| CVE-2006-3082 | parse-packet.c in GnuPG (gpg) 1.4.3 and 1.9.20, and earlier versions, allows remote attackers to cause a denial of service (gpg crash) and possibly overwrite memory via a message packet with a large length (long user ID string), which could lead to an… | EXPLOIT ✓MEDIUM 5.0EPSS 7.31% | 19 June 2006 |
| CVE-2006-3081 | mysqld in MySQL 4.1.x before 4.1.18, 5.0.x before 5.0.19, and 5.1.x before 5.1.6 allows remote authorized users to cause a denial of service (crash) via a NULL second argument to the str_to_date function. | EXPLOIT ✓MEDIUM 4.0EPSS 25.8% | 19 June 2006 |
| CVE-2006-3076 | PHP remote file inclusion vulnerability in software_upload/public_includes/pub_templates/vphptree/template.php in PhpBlueDragon CMS 2.9.1 allows remote attackers to execute arbitrary PHP code via a URL in the vsDragonRootPath parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 2.57% | 19 June 2006 |
| CVE-2006-3074 | klif.sys in Kaspersky Internet Security 6.0 and 7.0, Kaspersky Anti-Virus (KAV) 6.0 and 7.0, KAV 6.0 for Windows Workstations, and KAV 6.0 for Windows Servers does not validate certain parameters to the (1) NtCreateKey, (2) NtCreateProcess, (3)… | EXPLOIT ✓MEDIUM 5.0EPSS 7.18% | 19 June 2006 |
| CVE-2006-3069 | PHP remote file inclusion vulnerability in DoubleSpeak 0.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the config[private] parameter in multiple files, as demonstrated by (1) index.php, (2) faq.php, and… | EXPLOIT ✓HIGH 7.5EPSS 3.25% | 19 June 2006 |
| CVE-2006-3065 | SQL injection vulnerability in engine/shards/blog.php in blur6ex 0.3.462 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a proc_reply action in the blog shard. | EXPLOIT ✓HIGH 7.5EPSS 1.48% | 19 June 2006 |
| CVE-2006-3061 | Multiple cross-site scripting (XSS) vulnerabilities in 5 Star Review allow remote attackers to inject arbitrary web script or HTML via the (1) sort parameter in index2.php, (2) item_id parameter in report.php, (3) search_term parameter (aka the "search… | EXPLOIT ×2 ✓LOW 2.6EPSS 6.81% | 19 June 2006 |
| CVE-2006-3059 | Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors. | EXPLOIT ✓HIGH 9.3EPSS 41.1% | 17 June 2006 |
| CVE-2006-3053 | PHP remote file inclusion vulnerability in common.php in PHORUM 5.1.13 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the PHORUM[http_path] parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.89% | 16 June 2006 |
| CVE-2006-3052 | Cross-site scripting (XSS) vulnerability in Event Registration allows remote attackers to inject arbitrary web script or HTML via the (1) event_id parameter to view-event-details.php or (2) select_events parameter to event-registration.php. | EXPLOIT ✓MEDIUM 6.8EPSS 1.84% | 16 June 2006 |
| CVE-2006-3051 | Cross-site scripting (XSS) vulnerability in list.php in SixCMS 6.0, and other versions before 6.0.6patch2, allows remote attackers to inject arbitrary script code or HTML via the page parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 2.85% | 16 June 2006 |
| CVE-2006-3050 | Directory traversal vulnerability in detail.php in SixCMS 6.0, and other versions before 6.0.6patch2, allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓LOW 2.6EPSS 3.11% | 16 June 2006 |
| CVE-2006-2909 | Stack-based buffer overflow in the info tip shell extension (zipinfo.dll) in PicoZip 4.01 allows remote attackers to execute arbitrary code via a long filename in an (1) ACE, (2) RAR, or (3) ZIP archive, which is triggered when the user moves the mouse… | EXPLOIT ✓HIGH 7.5EPSS 9.03% | 16 June 2006 |
| CVE-2006-3042 | Multiple PHP remote file inclusion vulnerabilities in ISPConfig 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) go_info[isp][classes_root] parameter in (a) server.inc.php, and the (2) go_info[server][classes_root]… | EXPLOIT ✓HIGH 7.5EPSS 2.88% | 15 June 2006 |
| CVE-2006-3036 | Multiple cross-site scripting (XSS) vulnerabilities in 35mmslidegallery 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) imgdir parameter in (a) index.php, and the (2) w, (3) h, and (4) t parameters in (b) popup.php. | EXPLOIT ×2 ✓MEDIUM 5.8EPSS 4.35% | 15 June 2006 |
| CVE-2006-3028 | PHP remote file inclusion vulnerability in stat_modules/users_age/module.php in Minerva 2.0.8a Build 237 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.56% | 15 June 2006 |
| CVE-2006-3027 | Multiple SQL injection vulnerabilities in Enthrallwebe ePhotos 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) CAT_ID parameter in (a) subphotos.asp and (b) subLevel2.asp, the (2) AL_ID parameter in (c) photo.asp,… | EXPLOIT ✓HIGH 7.5EPSS 2.69% | 15 June 2006 |
| CVE-2006-3019 | Multiple PHP remote file inclusion vulnerabilities in phpCMS 1.2.1pl2 allow remote attackers to execute arbitrary PHP code via a URL in the PHPCMS_INCLUDEPATH parameter to files in parser/include/ including (1) class.parser_phpcms.php, (2)… | EXPLOIT ×10 ✓HIGH 7.5EPSS 7.88% | 15 June 2006 |
| CVE-2006-3015 | Argument injection vulnerability in WinSCP 3.8.1 build 328 allows remote attackers to upload or download arbitrary files via encoded spaces and double-quote characters in a scp or sftp URI. | EXPLOIT ✓HIGH 7.1EPSS 6.45% | 14 June 2006 |
| CVE-2006-3009 | Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers to inject arbitrary HTML or web script via the (1) tf_lang, (2) tf_name, (3) tf_user, (4) tf_lastname, (5) tf_contact, (6)… | EXPLOIT ×5 ✓MEDIUM 5.8EPSS 5.14% | 13 June 2006 |
| CVE-2006-2383 | Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via "unexpected data" related to "parameter validation" in the DXImageTransform.Microsoft.Light ActiveX control,… | EXPLOIT ✓HIGH 9.3EPSS 40.3% | 13 June 2006 |
| CVE-2006-2379 | Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via unknown vectors related to IP source routing. | EXPLOIT ✓HIGH 9.3EPSS 54.1% | 13 June 2006 |
| CVE-2006-2374 | The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) by calling the MrxSmbCscIoctlCloseForCopyChunk with the file handle… | EXPLOIT ×2 ✓MEDIUM 5.5EPSS 1.75% | 13 June 2006 |
| CVE-2006-2373 | The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to execute arbitrary code by calling the MrxSmbCscIoctlOpenForCopyChunk function with the METHOD_NEITHER… | EXPLOIT ×2 ✓HIGH 10.0EPSS 29.2% | 13 June 2006 |
| CVE-2006-2370 | Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC… | EXPLOIT ×4 ✓HIGH 7.5EPSS 70.1% | 13 June 2006 |
| CVE-2006-1193 | Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA), allows user-assisted remote attackers to inject arbitrary HTML or web script via unknown vectors related to "HTML parsing." | EXPLOIT ✓LOW 2.6EPSS 39.8% | 13 June 2006 |
| CVE-2006-3006 | Cross-site scripting (XSS) vulnerability in iFoto 0.20, and possibly other versions before 0.50, allows remote attackers to inject arbitrary HTML or web script via a base64-encoded file parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 3.89% | 13 June 2006 |
| CVE-2006-2998 | PHP remote file inclusion vulnerability in board/post.php in free QBoard 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the qb_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 7.11% | 13 June 2006 |
| CVE-2006-2996 | PHP remote file inclusion vulnerability in inc/design.inc.php in LoveCompass aePartner 0.8.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the dir[data] parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.82% | 13 June 2006 |
| CVE-2006-2995 | Multiple PHP remote file inclusion vulnerabilities in WebprojectDB 0.1.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the INCDIR parameter in (1) include/nav.php and (2) include/lang.php. | EXPLOIT ✓HIGH 7.5EPSS 8.29% | 13 June 2006 |
| CVE-2006-2986 | Multiple cross-site scripting (XSS) vulnerabilities in Baby Katie Media (a) very Simple Car Lister (vSCAL) 1.0 and (b) very simple Realty Lister (vsREAL) 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) lid parameter in… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 3.89% | 13 June 2006 |
| CVE-2006-2982 | Multiple PHP remote file inclusion vulnerabilities in Enterprise Timesheet and Payroll Systems (EPS) 1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the absolutepath parameter in (1) footer.php and (2) admin/footer.php. | EXPLOIT ✓HIGH 7.5EPSS 3.57% | 13 June 2006 |
| CVE-2006-2908 | The domecode function in inc/functions_post.php in MyBulletinBoard (MyBB) 1.1.2, and possibly other versions, allows remote attackers to execute arbitrary PHP code via the username field, which is used in a preg_replace function call with a /e… | EXPLOIT ✓HIGH 7.5EPSS 4.40% | 13 June 2006 |
| CVE-2006-2973 | Multiple SQL injection vulnerabilities in month.php in PHP Lite Calendar Express 2.2 allow remote attackers to execute arbitrary SQL commands via the (1) catid and (2) cid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.11% | 12 June 2006 |
| CVE-2006-2971 | Integer overflow in the recv_packet function in 0verkill 0.16 allows remote attackers to cause a denial of service (daemon crash) via a UDP packet with fewer than 12 bytes, which results in a long length value to the crc32 function. | EXPLOIT ✓MEDIUM 5.0EPSS 4.55% | 12 June 2006 |
| CVE-2006-2962 | PHP remote file inclusion vulnerability in sql_fcnsOLD.php in Emergenices Personnel Information System (Empris) 20020923 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phormationdir parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.69% | 12 June 2006 |
| CVE-2006-2961 | Stack-based buffer overflow in CesarFTP 0.99g and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long MKD command. | EXPLOIT ×3 ✓HIGH 7.5EPSS 61.7% | 12 June 2006 |
| CVE-2006-2955 | Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice 7.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) New Category (newcategory) or (2) apage parameter to (a) edtalbum.asp, or the (3) cat or (4)… | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 4.31% | 12 June 2006 |
| CVE-2006-2947 | Dmx Forum 2.1a allows remote attackers to obtain username and password information via a direct request to pops/edit.php with a modified membre parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 2.80% | 12 June 2006 |
| CVE-2006-2946 | Dmx Forum 2.1a stores _includes/bd.inc under the web root with insufficient access control, which allows remote attackers to obtain database username and password information. | EXPLOIT ✓MEDIUM 5.0EPSS 2.77% | 12 June 2006 |
| CVE-2006-2929 | PHP remote file inclusion vulnerability in contrib/forms/evaluation/C_FormEvaluation.class.php in OpenEMR 2.8.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[fileroot]… | EXPLOIT ✓MEDIUM 6.8EPSS 6.06% | 9 June 2006 |
| CVE-2006-2928 | Multiple PHP remote file inclusion vulnerabilities in CMS-Bandits 2.5 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter in (1) dialogs/img.php and (2) dialogs/td.php. | EXPLOIT ✓MEDIUM 5.1EPSS 4.58% | 9 June 2006 |
| CVE-2006-2926 | Stack-based buffer overflow in the WWW Proxy Server of Qbik WinGate 6.1.1.1077 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long URL HTTP request. | EXPLOIT ×2 ✓HIGH 7.5EPSS 70.7% | 9 June 2006 |
| CVE-2006-2922 | Multiple PHP remote file inclusion vulnerabilities in MiraksGalerie 2.62 allow remote attackers to execute arbitrary PHP code via a URL in the (1) g_pcltar_lib_dir parameter in (a) pcltar.lib.php when register_globals is enabled, and (2)… | EXPLOIT ×2 ✓MEDIUM 5.1EPSS 4.46% | 9 June 2006 |
| CVE-2006-2906 | The LZW decoding in the gdImageCreateFromGifPtr function in the Thomas Boutell graphics draw (GD) library (aka libgd) 2.0.33 allows remote attackers to cause a denial of service (CPU consumption) via malformed GIF data that causes an infinite loop. | EXPLOIT ✓MEDIUM 5.4EPSS 10.4% | 8 June 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.