Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
399,059 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026
25,049 results · page 394 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-2803 | Multiple cross-site scripting (XSS) vulnerabilities in PHP ManualMaker 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) id parameter to index.php, (2) search field (possibly the s parameter), or (3) comment field. | EXPLOIT ✓MEDIUM 6.8EPSS 2.10% | 3 June 2006 |
| CVE-2006-2802 | Buffer overflow in the HTTP Plugin (xineplug_inp_http.so) for xine-lib 1.1.1 allows remote attackers to cause a denial of service (application crash) via a long reply from an HTTP server, as demonstrated using gxine 0.5.6. | EXPLOIT ✓MEDIUM 5.0EPSS 11.1% | 3 June 2006 |
| CVE-2006-2798 | Multiple cross-site scripting (XSS) vulnerabilities in phpCommunityCalendar 4.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) LoName parameter in (a) week.php and (b) month.php and (2) AddressLink parameter in (c) event.php. | EXPLOIT ✓MEDIUM 6.8EPSS 2.23% | 3 June 2006 |
| CVE-2006-2797 | Multiple SQL injection vulnerabilities in phpCommunityCalendar 4.0.3 allow remote attackers to execute arbitrary SQL commands via the (1) CalendarDetailsID parameter in (a) month.php, (b) day.php, and (c) delCalendar.php; (2) ID parameter in (d)… | EXPLOIT ✓HIGH 7.5EPSS 2.06% | 3 June 2006 |
| CVE-2006-2794 | Hesabim.asp in ASPSitem 2.0 and earlier allows remote attackers to read private messages of other users via a modified id parameter. | EXPLOIT ✓HIGH 7.8EPSS 2.97% | 3 June 2006 |
| CVE-2006-2793 | SQL injection vulnerability in Anket.asp in ASPSitem 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the hid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.32% | 3 June 2006 |
| CVE-2006-2771 | admin/radera/tabort.asp in Hogstorps hogstorp guestbook 2.0 does not verify user credentials, which allows remote attackers to delete arbitrary posts via a modified delID parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 2.51% | 2 June 2006 |
| CVE-2006-2770 | Directory traversal vulnerability in randompic.php in pppBLOG 0.3.8 and earlier, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. | EXPLOIT ×2 ✓MEDIUM 5.4EPSS 3.48% | 2 June 2006 |
| CVE-2006-2769 | The HTTP Inspect preprocessor (http_inspect) in Snort 2.4.0 through 2.4.4 allows remote attackers to bypass "uricontent" rules via a carriage return (\r) after the URL and before the HTTP declaration. | EXPLOIT ✓MEDIUM 5.0EPSS 10.8% | 2 June 2006 |
| CVE-2006-2768 | PHP remote file inclusion vulnerability in METAjour 2.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the (1) system_path parameter in a large number of files in the (a) app/edocument/, (b) app/eproject/,… | EXPLOIT ✓MEDIUM 5.1EPSS 6.74% | 2 June 2006 |
| CVE-2006-2767 | PHP remote file inclusion vulnerability in Ottoman 1.1.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the default_path parameter in (1) error.php, (2) index.php, and (3) classes/main_class.php. | EXPLOIT ✓MEDIUM 5.1EPSS 3.38% | 2 June 2006 |
| CVE-2006-2766 | Buffer overflow in INETCOMM.DLL, as used in Microsoft Internet Explorer 6.0 through 6.0 SP2, Windows Explorer, Outlook Express 6, and possibly other programs, allows remote user-assisted attackers to cause a denial of service (application crash) via a… | EXPLOIT ✓LOW 2.6EPSS 47.9% | 2 June 2006 |
| CVE-2006-2763 | SQL injection vulnerability in Pre News Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) index.php, and the (2) nid parameter to (b) news_detail.php, (c) email_story.php, (d) thankyou.php, (e)… | EXPLOIT ×2 ✓MEDIUM 6.4EPSS 2.87% | 2 June 2006 |
| CVE-2006-2758 | Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a %2e%2e%5c (encoded ../) in the URL. | EXPLOITMEDIUM 5.0EPSS 4.01% | 2 June 2006 |
| CVE-2006-2755 | Cross-site scripting (XSS) vulnerability in index.php in UBBThreads 5.x and earlier allows remote attackers to inject arbitrary web script or HTML via the debug parameter, as demonstrated by stealing MD5 hashes of passwords. | EXPLOIT ✓MEDIUM 4.3EPSS 2.30% | 2 June 2006 |
| CVE-2006-2747 | Directory traversal vulnerability in index.php in PhpMyDesktop|arcade 1.0 FINAL allows remote attackers to read arbitrary files or execute PHP code via a .. | EXPLOIT ✓MEDIUM 5.1EPSS 2.72% | 1 June 2006 |
| CVE-2006-2746 | Multiple cross-site scripting (XSS) vulnerabilities in F@cile Interactive Web 0.8.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) lang parameter in index.php, and the (2) mytheme and (3) myskin parameters in… | EXPLOIT ✓MEDIUM 6.8EPSS 3.09% | 1 June 2006 |
| CVE-2006-2745 | Multiple PHP remote file inclusion vulnerabilities in F@cile Interactive Web 0.8.5 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) pathfile parameter in (a) p-editpage.php and (b)… | EXPLOIT ✓MEDIUM 5.1EPSS 6.80% | 1 June 2006 |
| CVE-2006-2744 | PHP remote file inclusion vulnerability in p-popupgallery.php in F@cile Interactive Web 0.8.41 through 0.8.5 allows remote attackers to execute arbitrary PHP code via a URL in the l parameter. | EXPLOIT ✓HIGH 7.5EPSS 9.86% | 1 June 2006 |
| CVE-2006-2743 | Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory. | EXPLOIT ✓MEDIUM 5.1EPSS 11.1% | 1 June 2006 |
| CVE-2006-2740 | Multiple SQL injection vulnerabilities in Epicdesigns tinyBB 0.3 allow remote attackers to execute arbitrary SQL commands via the (1) q parameter in (a) forgot.php, and the (2) username and (3) password parameters in (b) login.php, and other unspecified… | EXPLOIT ✓MEDIUM 6.8EPSS 3.97% | 1 June 2006 |
| CVE-2006-2739 | PHP remote file inclusion vulnerability in footers.php in Epicdesigns tinyBB 0.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the tinybb_footers parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 8.80% | 1 June 2006 |
| CVE-2006-2737 | utilities/register.asp in Nukedit 4.9.6 and earlier allows remote attackers to create new users as part of arbitrary groups, including the administrative group, via a modified groupid parameter when creating a user via the addDB action. | EXPLOIT ✓HIGH 7.5EPSS 3.35% | 1 June 2006 |
| CVE-2006-2736 | PHP remote file inclusion vulnerability in blend_data/blend_common.php in Blend Portal 1.2.0, as used with phpBB when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 4.35% | 1 June 2006 |
| CVE-2006-2735 | PHP remote file inclusion vulnerability in language/lang_english/lang_activity.php in Activity MOD Plus (Amod) 1.1.0, as used with phpBB when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the… | EXPLOIT ✓MEDIUM 5.1EPSS 7.02% | 1 June 2006 |
| CVE-2006-2732 | SQL injection vulnerability in Your_Account.asp in Mini-Nuke 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) yas_1, (2) yas_2, and (3) yas_3 parameters. | EXPLOIT ✓HIGH 7.5EPSS 2.01% | 1 June 2006 |
| CVE-2006-2731 | Multiple SQL injection vulnerabilities in Enigma Haber 4.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in (a) e_mesaj_yas.asp, (b) edi_haber.asp, and (c) haber_devam.asp; (2) hid parameter in (d)… | EXPLOIT ✓HIGH 7.5EPSS 4.06% | 1 June 2006 |
| CVE-2006-2730 | PHP remote file inclusion vulnerability in admin/lib_action_step.php in Hot Open Tickets (HOT) 11012004_ver2f, when register_globals is enabled, allows remote attackers to include arbitrary files via the GLOBALS[CLASS_PATH] parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 2.68% | 1 June 2006 |
| CVE-2006-2728 | Cross-site scripting (XSS) vulnerability in superalbum/index.php in Photoalbum B&W 1.3 allows remote attackers to inject arbitrary web script or HTML via the pic parameter. | EXPLOIT ✓LOW 2.6EPSS 1.95% | 1 June 2006 |
| CVE-2006-2726 | PHP remote file inclusion vulnerability in Fastpublish CMS 1.6.9.d allows remote attackers to include arbitrary files via the config[fsBase] parameter in (1) drucken.php, (2) drucken2.php, (3) email_an_benutzer.php, (4) rechnung.php, (5)… | EXPLOIT ✓HIGH 7.5EPSS 19.5% | 1 June 2006 |
| CVE-2006-2725 | SQL injection vulnerability in rss/posts.php in Eggblog before 3.07 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 1.77% | 1 June 2006 |
| CVE-2006-2439 | Stack-based buffer overflow in ZipCentral 4.01 allows remote user-assisted attackers to execute arbitrary code via a ZIP archive containing a long filename. | EXPLOIT ×3 ✓HIGH 7.6EPSS 7.30% | 1 June 2006 |
| CVE-2006-2723 | Unspecified versions of Mozilla Firefox allow remote attackers to cause a denial of service (crash) via a web page that contains a large number of nested marquee tags. | EXPLOIT ✓MEDIUM 5.0EPSS 3.00% | 1 June 2006 |
| CVE-2006-2699 | Cross-site scripting (XSS) vulnerability in getimage.php in Geeklog 1.4.0sr2 and earlier allows remote attackers to inject arbitrary HTML or web script via the image argument in a show action. | EXPLOIT ✓MEDIUM 6.8EPSS 2.44% | 31 May 2006 |
| CVE-2006-2697 | Multiple SQL injection vulnerabilities in Easy-Content Forums 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) startletter parameter in userview.asp and the (2) forumname parameter in topics.asp. | EXPLOIT ✓MEDIUM 6.4EPSS 1.11% | 31 May 2006 |
| CVE-2006-2696 | Cross-site scripting (XSS) vulnerabilities in Easy-Content Forums 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) startletter parameter in userview.asp and the (2) catid parameter in topics.asp. | EXPLOIT ✓MEDIUM 6.8EPSS 1.82% | 31 May 2006 |
| CVE-2006-2689 | Multiple cross-site scripting (XSS) vulnerabilities in EVA-Web 2.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) debut_image parameter in (a) article-album.php3, (2) date parameter in (b) rubrique.php3, and the… | EXPLOIT ×3 ✓MEDIUM 6.8EPSS 1.99% | 31 May 2006 |
| CVE-2006-2686 | PHP remote file inclusion vulnerabilities in ActionApps 2.8.1 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[AA_INC_PATH] parameter in (1) cached.php3, (2) cron.php3, (3) discussion.php3, (4) filldisc.php3, (5)… | EXPLOIT ✓MEDIUM 6.4EPSS 13.6% | 31 May 2006 |
| CVE-2006-2685 | PHP remote file inclusion vulnerability in Basic Analysis and Security Engine (BASE) 1.2.4 and earlier, with register_globals enabled, allows remote attackers to execute arbitrary PHP code via a URL in the BASE_path parameter to (1) base_qry_common.php,… | EXPLOIT ×3 ✓MEDIUM 4.0EPSS 49.2% | 31 May 2006 |
| CVE-2006-2683 | PHP remote file inclusion vulnerability in 404.php in open-medium.CMS 0.25 allows remote attackers to execute arbitrary PHP code via a URL in the REDSYS[MYPATH][TEMPLATES] parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 2.29% | 31 May 2006 |
| CVE-2006-2682 | PHP remote file inclusion vulnerability in BE_config.php in Back-End CMS 0.7.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _PSL[classdir] parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 2.44% | 31 May 2006 |
| CVE-2006-2681 | PHP remote file inclusion vulnerability in SocketMail Lite and Pro 2.2.6 and earlier, when register_globals and magic_quotes are enabled, allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter to (1) index.php and (2)… | EXPLOIT ✓MEDIUM 6.8EPSS 2.31% | 31 May 2006 |
| CVE-2006-2680 | Cross-site scripting (XSS) vulnerability in index.php in AZ Photo Album Script Pro allows remote attackers to inject arbitrary web script or HTML via the gazpart parameter. | EXPLOIT ✓MEDIUM 5.8EPSS 1.88% | 31 May 2006 |
| CVE-2006-2675 | PHP remote file inclusion vulnerability in ubbt.inc.php in UBBThreads 5.x and 6.x allows remote attackers to execute arbitrary PHP code via a URL in the (1) thispath or (2) configdir parameters. | EXPLOIT ✓MEDIUM 5.1EPSS 2.52% | 30 May 2006 |
| CVE-2006-2668 | Multiple PHP remote file inclusion vulnerabilities in Docebo LMS 2.05 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) modules/credits/business.php, (2) modules/credits/credits.php, or (3)… | EXPLOIT ✓HIGH 7.5EPSS 3.91% | 30 May 2006 |
| CVE-2006-2667 | Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary commands by inserting a carriage return and PHP code when updating a profile, which is appended after a special comment sequence into… | EXPLOIT ✓HIGH 7.5EPSS 14.5% | 30 May 2006 |
| CVE-2006-2666 | PHP remote file inclusion vulnerability in includes/mailaccess/pop3.php in V-Webmail 1.5 through 1.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[pear_dir] parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.56% | 30 May 2006 |
| CVE-2006-2665 | PHP remote file inclusion vulnerability in includes/mailaccess/pop3/core.php in V-Webmail 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[pear_dir] parameter. | EXPLOIT ✓HIGH 7.5EPSS 8.76% | 30 May 2006 |
| CVE-2006-2661 | ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a crafted font file that triggers a null dereference. | EXPLOIT ✓MEDIUM 5.0EPSS 16.5% | 30 May 2006 |
| CVE-2006-2656 | Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute arbitrary code via a long filename. | EXPLOIT ✓HIGH 7.5EPSS 14.4% | 30 May 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.