Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
399,059 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026
25,049 results · page 393 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-2901 | The web server for D-Link Wireless Access-Point (DWL-2100ap) firmware 2.10na and earlier allows remote attackers to obtain sensitive system information via a request to an arbitrary .cfg file, which returns configuration information including passwords. | EXPLOIT ✓MEDIUM 5.0EPSS 9.21% | 7 June 2006 |
| CVE-2006-2899 | Unspecified vulnerability in ESTsoft InternetDISK versions before 2006/04/20 allows remote authenticated users to execute arbitrary code, possibly by uploading a file with multiple extensions into the WebLink directory. | EXPLOIT ✓MEDIUM 6.5EPSS 3.80% | 7 June 2006 |
| CVE-2006-2896 | profile.php in FunkBoard CF0.71 allows remote attackers to change arbitrary passwords via a modified uid hidden form field in an Edit Profile action. | EXPLOIT ✓MEDIUM 5.0EPSS 9.36% | 7 June 2006 |
| CVE-2006-2894 | Mozilla Firefox 1.5.0.4, 2.0.x before 2.0.0.8, Mozilla Suite 1.7.13, Mozilla SeaMonkey 1.0.2 and other versions before 1.1.5, and Netscape 8.1 and earlier allow user-assisted remote attackers to read arbitrary files by tricking a user into typing the… | EXPLOIT ×2 ✓MEDIUM 4.0EPSS 9.83% | 7 June 2006 |
| CVE-2006-2892 | Cross-site scripting (XSS) vulnerability in index.php in GANTTy 1.0.3 allows remote attackers to inject arbitrary HTML and web script via the message parameter in a login action. | EXPLOIT ✓MEDIUM 4.3EPSS 3.82% | 7 June 2006 |
| CVE-2006-2889 | Multiple SQL injection vulnerabilities in index.php in Pixelpost 1-5rc1-2 and earlier allow remote attackers to execute arbitrary SQL commands, and leverage them to gain administrator privileges, via the (1) category or (2) archivedate parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 1.14% | 7 June 2006 |
| CVE-2006-2888 | PHP remote file inclusion vulnerability in _wk/wk_lang.php in Wikiwig 4.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the WK[wkPath] parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.81% | 7 June 2006 |
| CVE-2006-2887 | Multiple SQL injection vulnerabilities in myNewsletter 1.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the UserName parameter in (1) validatelogin.asp or (2) adminlogin.asp. | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.27% | 7 June 2006 |
| CVE-2006-2884 | SQL injection vulnerability in index.php in Kmita FAQ 1.0 allows remote attackers to execute arbitrary SQL commands via the catid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.29% | 7 June 2006 |
| CVE-2006-2883 | Cross-site scripting (XSS) vulnerability in search.php in Kmita FAQ 1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.94% | 7 June 2006 |
| CVE-2006-2881 | Multiple PHP remote file inclusion vulnerabilities in DreamAccount 3.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the da_path parameter in the (1) auth.cookie.inc.php, (2)… | EXPLOIT ✓MEDIUM 5.1EPSS 18.0% | 7 June 2006 |
| CVE-2006-2877 | PHP remote file inclusion vulnerability in Bookmark4U 2.0.0 and earlier allows remote attackers to include arbitrary PHP files via the include_prefix parameter in (1) inc/dbase.php, (2) inc/config.php, (3) inc/common.php, and (4) inc/function.php. | EXPLOIT ×4 ✓HIGH 7.5EPSS 7.61% | 7 June 2006 |
| CVE-2006-2875 | Stack-based buffer overflow in the CL_ParseDownload function of Quake 3 Engine 1.32c and earlier, as used in multiple products, allows remote attackers to execute arbitrary code via a svc_download command with compressed data that triggers the overflow… | EXPLOIT ✓HIGH 7.5EPSS 6.78% | 7 June 2006 |
| CVE-2006-2447 | SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafted message that is not properly handled when invoking spamd with the virtual pop username. | EXPLOIT ×2 ✓MEDIUM 5.1EPSS 75.8% | 6 June 2006 |
| CVE-2006-2873 | Cross-site scripting (XSS) vulnerability in hava.asp in Enigma Haber 4.2 allows remote attackers to inject arbitrary web script or HTML via the il parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.70% | 6 June 2006 |
| CVE-2006-2871 | PHP remote file inclusion vulnerability in include/common.php in CyBoards PHP Lite 1.25 allows remote attackers to execute arbitrary PHP code via a URL in the script_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.42% | 6 June 2006 |
| CVE-2006-2868 | Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.6 allow remote attackers to execute arbitrary PHP code via a URL in the includePath cookie to (1) auth/extauth/drivers/mambo.inc.php or (2) auth/extauth/drivers/postnuke.inc.php. | EXPLOIT ✓MEDIUM 5.1EPSS 11.1% | 6 June 2006 |
| CVE-2006-2867 | SQL injection vulnerability in editpost.php in CoolForum 0.8.3 beta and earlier allows remote attackers to execute arbitrary SQL commands via the post parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.25% | 6 June 2006 |
| CVE-2006-2866 | PHP remote file inclusion vulnerability in layout/prepend.php in DotClear 1.2.4 and earlier allows remote attackers to execute arbitrary PHP code via a FTP URL in the blog_dc_path parameter, which passes file_exists() and is_dir() tests on PHP 5. | EXPLOIT ✓MEDIUM 5.1EPSS 3.18% | 6 June 2006 |
| CVE-2006-2865 | PHP remote file inclusion vulnerability in template.php in phpBB 2 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.82% | 6 June 2006 |
| CVE-2006-2864 | Multiple PHP remote file inclusion vulnerabilities in BlueShoes Framework 4.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) APP[path][applications] parameter to (a) Bs_Faq.class.php, (2) APP[path][core] parameter to (b)… | EXPLOIT ✓MEDIUM 5.1EPSS 15.6% | 6 June 2006 |
| CVE-2006-2863 | PHP remote file inclusion vulnerability in class.cs_phpmailer.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in the classes_dir parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 9.55% | 6 June 2006 |
| CVE-2006-2861 | SQL injection vulnerability in index.php in Particle Wiki 1.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the version parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.24% | 6 June 2006 |
| CVE-2006-2860 | PHP remote file inclusion vulnerability in Webspotblogging 3.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) inc/logincheck.inc.php, (2) inc/adminheader.inc.php, (3) inc/global.php, or (4)… | EXPLOIT ✓MEDIUM 6.4EPSS 13.0% | 6 June 2006 |
| CVE-2006-2858 | SQL injection vulnerability in viewmsg.asp in LocazoList Classifieds 1.05e allows remote attackers to execute arbitrary SQL commands via the msgid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.82% | 6 June 2006 |
| CVE-2006-2857 | SQL injection vulnerability in index.php in LifeType 1.0.4 allows remote attackers to execute arbitrary SQL commands via the articleId parameter in a ViewArticle action (viewarticleaction.class.php). | EXPLOIT ✓HIGH 7.5EPSS 1.36% | 6 June 2006 |
| CVE-2006-2855 | SQL injection vulnerability in index.php in xueBook 1.0 allows remote attackers to execute arbitrary SQL commands via the start parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.14% | 6 June 2006 |
| CVE-2006-2854 | SQL injection vulnerability in index.php in iBWd Guestbook 1.0 allows remote attackers to execute arbitrary SQL commands via the offset parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.14% | 6 June 2006 |
| CVE-2006-2853 | SQL injection vulnerability in content.php in abarcar Realty Portal 5.1.5 allows remote attackers to execute arbitrary SQL commands via the cat parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.29% | 6 June 2006 |
| CVE-2006-2852 | PHP remote file inclusion vulnerability in dotWidget CMS 1.0.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the file_path parameter in (1) index.php, (2) feedback.php, and (3)… | EXPLOIT ✓MEDIUM 6.8EPSS 11.1% | 6 June 2006 |
| CVE-2006-2849 | PHP remote file inclusion vulnerability in includes/webdav/server.php in Bytehoard 2.1 Epsilon/Delta allows remote attackers to execute arbitrary PHP code via a URL in the bhconfig[bhfilepath] parameter. | EXPLOIT ✓HIGH 7.5EPSS 11.5% | 6 June 2006 |
| CVE-2006-2848 | links.asp in aspWebLinks 2.0 allows remote attackers to change the administrative password, possibly via a direct request with a modified txtAdministrativePassword field. | EXPLOIT ✓MEDIUM 5.0EPSS 1.80% | 6 June 2006 |
| CVE-2006-2847 | SQL injection vulnerability in links.asp in aspWebLinks 2.0 allows remote attackers to execute arbitrary SQL commands via the linkID parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.30% | 6 June 2006 |
| CVE-2006-2845 | PHP remote file inclusion vulnerability in Redaxo 3.0 up to 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the REX[INCLUDE_PATH] parameter to image_resize/pages/index.inc.php. | EXPLOIT ✓HIGH 7.5EPSS 3.84% | 6 June 2006 |
| CVE-2006-2844 | Multiple PHP remote file inclusion vulnerabilities in Redaxo 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the REX[INCLUDE_PATH] parameter to (1) simple_user/pages/index.inc.php and (2) stats/pages/index.inc.php. | EXPLOIT ✓HIGH 7.5EPSS 3.84% | 6 June 2006 |
| CVE-2006-2843 | PHP remote file inclusion vulnerability in Redaxo 2.7.4 allows remote attackers to execute arbitrary PHP code via a URL in the (1) REX[INCLUDE_PATH] parameter in (a) addons/import_export/pages/index.inc.php and (b) pages/community.inc.php. | EXPLOIT ✓HIGH 7.5EPSS 3.84% | 6 June 2006 |
| CVE-2006-2842 | PHP remote file inclusion vulnerability in functions/plugin.php in SquirrelMail 1.4.6 and earlier, if register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the plugins array… | EXPLOIT ✓HIGH 7.5EPSS 44.0% | 6 June 2006 |
| CVE-2006-2841 | Multiple PHP remote file inclusion vulnerabilities in AssoCIateD (aka ACID) CMS 1.1.3 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) menu.php, (2) profile.php, (3) users.php, (4) cache_mngt.php, and (5)… | EXPLOIT ✓HIGH 7.5EPSS 7.12% | 6 June 2006 |
| CVE-2006-2835 | SQL injection vulnerability in saphplesson 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) forumid parameter in add.php and (2) lessid parameter in show.php. | EXPLOIT ✓HIGH 7.5EPSS 1.28% | 6 June 2006 |
| CVE-2006-2834 | PHP remote file inclusion vulnerability in includes/common.php in gnopaste 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 8.25% | 6 June 2006 |
| CVE-2006-2828 | Global variable overwrite vulnerability in PHP-Nuke allows remote attackers to conduct remote PHP file inclusion attacks via a modified phpbb_root_path parameter to the admin scripts (1) index.php, (2) admin_ug_auth.php, (3) admin_board.php, (4)… | EXPLOIT ✓MEDIUM 6.4EPSS 2.53% | 5 June 2006 |
| CVE-2006-2826 | SQL injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a allows remote attackers to execute arbitrary SQL commands via the id variable, which is set by a client through a query string or a cookie. | EXPLOITHIGH 7.5EPSS 3.12% | 5 June 2006 |
| CVE-2006-2821 | Multiple cross-site scripting (XSS) vulnerabilities in DeltaScripts Pro Publish allow remote attackers to inject arbitrary web script or HTML via the (1) artid parameter in art.php and the (2) catname parameter in cat.php. | EXPLOIT ✓MEDIUM 6.8EPSS 1.93% | 5 June 2006 |
| CVE-2006-2819 | PHP remote file inclusion vulnerability in Wiki.php in Barnraiser Igloo 0.1.9 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the c_node[class_path] parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.54% | 5 June 2006 |
| CVE-2006-2818 | PHP remote file inclusion vulnerability in common-menu.php in Cameron McKay Informium 0.12.0 allows remote attackers to execute arbitrary PHP code via a URL in the CONF[local_path] parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.81% | 5 June 2006 |
| CVE-2006-2817 | SQL injection vulnerability in bolum.php in tekno.Portal allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.14% | 5 June 2006 |
| CVE-2006-2814 | Multiple buffer overflows in the (1) vGetPost and (2) main functions in easy-scart.c through easy-scart6.c in iShopCart allow remote attackers to execute arbitrary code by sending a large amount of data containing "Submit" in an sslinvoice action, and… | EXPLOIT ✓HIGH 7.5EPSS 5.68% | 5 June 2006 |
| CVE-2006-2811 | Multiple PHP remote file inclusion vulnerabilities in Cantico Ovidentia 5.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the babInstallPath parameter in (1) index.php, (2) topman.php, (3) approb.php, (4) vacadmb.php, (5)… | EXPLOIT ×8 ✓HIGH 7.5EPSS 17.4% | 5 June 2006 |
| CVE-2006-2807 | ASPwebSoft Speedy Asp Discussion Forum allows remote attackers to change the password of any account via a modified account id and possibly arbitrary values of the name, email, country, password, and passwordre parameters to profileupdate.asp. | EXPLOIT ✓HIGH 10.0EPSS 4.06% | 5 June 2006 |
| CVE-2006-2805 | SQL injection vulnerability in VBulletin 3.0.10 allows remote attackers to execute arbitrary SQL commands via the featureid parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 0.88% | 3 June 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.