Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
399,059 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026
25,049 results · page 395 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-2653 | Cross-site scripting (XSS) vulnerability in login_error.shtml for D-Link DSA-3100 allows remote attackers to inject arbitrary HTML or web script via an encoded uname parameter. | EXPLOIT ✓LOW 2.6EPSS 1.89% | 30 May 2006 |
| CVE-2006-2650 | SQL injection vulnerability in cosmicshop/search.php in CosmicShoppingCart allows remote attackers to execute arbitrary SQL commands via the max parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.82% | 30 May 2006 |
| CVE-2006-2648 | Cross-site scripting (XSS) vulnerability in perform_search.asp for ASPBB 0.52 and earlier allows remote attackers to inject arbitrary HTML or web script via the search parameter. | EXPLOIT ✓LOW 2.6EPSS 2.37% | 30 May 2006 |
| CVE-2006-2646 | Buffer overflow in Alt-N MDaemon, possibly 9.0.1 and earlier, allows remote attackers to execute arbitrary code via a long A0001 argument that begins with a '"' (double quote). | EXPLOIT ✓HIGH 7.5EPSS 4.55% | 30 May 2006 |
| CVE-2006-2645 | PHP remote file inclusion vulnerability in manager/frontinc/prepend.php for Plume 1.0.3 allows remote attackers to execute arbitrary code via a URL in the _PX_config[manager_path] parameter. | EXPLOIT ✓HIGH 7.5EPSS 5.60% | 30 May 2006 |
| CVE-2006-2638 | SQL injection vulnerability in member.asp in qjForum allows remote attackers to execute arbitrary SQL commands via the uName parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 1.21% | 30 May 2006 |
| CVE-2006-2636 | newsadmin.asp in Katy Whitton NewsCMSLite allows remote attackers to bypass authentication and gain administrative access by setting the loggedIn cookie to "xY1zZoPQ". | EXPLOIT ✓HIGH 7.5EPSS 3.63% | 30 May 2006 |
| CVE-2006-2635 | Multiple cross-site scripting (XSS) vulnerabilities in Tikiwiki (aka Tiki CMS/Groupware) 1.9.x allow remote attackers to inject arbitrary web script or HTML via malformed nested HTML tags such as "<scr<script>ipt>" in (1) offset and (2) days parameters… | EXPLOIT ✓MEDIUM 4.3EPSS 3.81% | 30 May 2006 |
| CVE-2006-2630 | Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitrary code via unknown attack vectors. | EXPLOIT ✓HIGH 10.0EPSS 73.6% | 27 May 2006 |
| CVE-2006-2629 | Race condition in Linux kernel 2.6.15 to 2.6.17, when running on SMP platforms, allows local users to cause a denial of service (crash) by creating and exiting a large number of tasks, then accessing the /proc entry of a task that is exiting, which… | EXPLOIT ✓MEDIUM 4.0EPSS 0.65% | 27 May 2006 |
| CVE-2006-2608 | artmedic newsletter 4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to modify arbitrary files and execute arbitrary PHP code via the logfile parameter in a direct request to log.php, which causes the $logfile… | EXPLOIT ✓MEDIUM 5.1EPSS 2.64% | 26 May 2006 |
| CVE-2006-2587 | Buffer overflow in the WebTool HTTP server component in (1) PunkBuster before 1.229, as used by multiple products including (2) America's Army 1.228 and earlier, (3) Battlefield 1942 1.158 and earlier, (4) Battlefield 2 1.184 and earlier, (5)… | EXPLOIT ✓MEDIUM 5.0EPSS 5.11% | 25 May 2006 |
| CVE-2006-2583 | PHP remote file inclusion vulnerability in nucleus/libs/PLUGINADMIN.php in Nucleus 3.22 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[DIR_LIBS] parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 7.07% | 25 May 2006 |
| CVE-2006-2444 | The snmp_trap_decode function in the SNMP NAT helper for Linux kernel before 2.6.16.18 allows remote attackers to cause a denial of service (crash) via unspecified remote attack vectors that cause failures in snmp_trap_decode that trigger (1) frees of… | EXPLOIT ✓HIGH 7.8EPSS 22.1% | 25 May 2006 |
| CVE-2006-2577 | Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in (1) where_cms, (2) where_lms, (3) where_upgrade, (4) BBC_LIB_PATH, and… | EXPLOIT ✓MEDIUM 5.1EPSS 2.41% | 24 May 2006 |
| CVE-2006-2576 | Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in (1) GLOBALS[where_framework] to (a) lib.simplesel.php, (b)… | EXPLOIT ✓MEDIUM 5.1EPSS 9.11% | 24 May 2006 |
| CVE-2006-2575 | The setFrame function in Lib/2D/Surface.hpp for NetPanzer 0.8 and earlier allows remote attackers to cause a denial of service (crash) via a client flag (frameNum) that is greater than 41, which triggers an assert error. | EXPLOIT ✓MEDIUM 5.0EPSS 4.65% | 24 May 2006 |
| CVE-2006-2570 | PHP remote file inclusion vulnerability in CaLogic Calendars 1.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS["CLPath"] parameter to (1) reconfig.php and (2) srxclr.php. | EXPLOIT ✓HIGH 7.5EPSS 2.54% | 24 May 2006 |
| CVE-2006-2569 | SQL injection vulnerability in links.php in 4R Linklist 1.0 RC2 and earlier, a module for Woltlab Burning Board, allows remote attackers to execute arbitrary SQL commands via the cat parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.14% | 24 May 2006 |
| CVE-2006-2568 | PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allows remote attackers to execute arbitrary PHP code via a URL in the thispath parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 7.87% | 24 May 2006 |
| CVE-2006-2557 | PHP remote file inclusion vulnerability in extras/poll/poll.php in Florian Amrhein NewsPortal before 0.37, and TR Newsportal (TRanx rebuilded), allows remote attackers to execute arbitrary PHP code via a URL in the file_newsportal parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 14.0% | 24 May 2006 |
| CVE-2006-2555 | The parse_command function in Genecys 0.2 and earlier allows remote attackers to cause a denial of service (crash) via a command with a missing ":" (colon) separator, which triggers a null dereference. | EXPLOIT ✓MEDIUM 5.0EPSS 8.90% | 24 May 2006 |
| CVE-2006-2554 | Buffer overflow in the tell_player_surr_changes function in Genecys 0.2 and earlier might allow remote attackers to execute arbitrary code via long arguments. | EXPLOIT ✓MEDIUM 6.4EPSS 12.5% | 24 May 2006 |
| CVE-2006-2552 | Jemscripts DownloadControl 1.0 allows remote attackers to obtain sensitive information via an invalid dcid parameter to dc.php, which leaks the pathname in an error message. | EXPLOIT ✓MEDIUM 5.0EPSS 1.46% | 24 May 2006 |
| CVE-2006-2548 | Prodder before 0.5, and perlpodder before 0.5, allows remote attackers to execute arbitrary code via shell metacharacters in the URL of a podcast (url attribute of an enclosure tag, or $enc_url variable), which is executed when running wget. | EXPLOIT ✓HIGH 7.5EPSS 13.3% | 23 May 2006 |
| CVE-2006-2541 | SQL injection vulnerability in settings.asp in Zixforum 1.12 allows remote attackers to execute arbitrary SQL commands via the layid parameter to (1) login.asp and (2) main.asp. | EXPLOIT ✓HIGH 7.5EPSS 2.13% | 23 May 2006 |
| CVE-2006-0747 | Integer underflow in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a font file with an odd number of blue values, which causes the underflow when decrementing by 2 in a context that assumes an even number of values. | EXPLOIT ✓MEDIUM 5.0EPSS 12.7% | 23 May 2006 |
| CVE-2006-2531 | Ipswitch WhatsUp Professional 2006 only verifies the user's identity via HTTP headers, which allows remote attackers to spoof being a trusted console and bypass authentication by setting HTTP User-Agent header to "Ipswitch/1.0" and the User-Application… | EXPLOIT ✓HIGH 7.5EPSS 7.36% | 22 May 2006 |
| CVE-2006-2528 | PHP remote file inclusion vulnerability in classified_right.php in phpBazar 2.1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the language_dir parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 2.98% | 22 May 2006 |
| CVE-2006-2527 | Admin/admin.php in phpBazar 2.1.0 and earlier allows remote attackers to bypass the authentication process and gain unauthorized access to the administrative section by setting the action parameter to edit_member and the value parameter to 1. | EXPLOIT ✓HIGH 7.5EPSS 3.35% | 22 May 2006 |
| CVE-2006-2523 | PHP remote file inclusion vulnerability in config.php in phpListPro 2.0.1 and earlier, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary PHP code via a URL in the Language cookie. | EXPLOIT ✓HIGH 7.5EPSS 3.00% | 22 May 2006 |
| CVE-2006-2521 | PHP remote file inclusion vulnerability in cron.php in phpMyDirectory 10.4.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ROOT_PATH parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.69% | 22 May 2006 |
| CVE-2006-2516 | mainfile.php in XOOPS 2.0.13.2 and earlier, when register_globals is enabled, allows remote attackers to overwrite variables such as $xoopsOption['nocommon'] and conduct directory traversal attacks or include PHP files via (1) xoopsConfig[language] to… | EXPLOIT ✓MEDIUM 5.1EPSS 6.35% | 22 May 2006 |
| CVE-2006-2507 | Multiple PHP remote file inclusion vulnerabilities in Teake Nutma Foing 0.2.0 through 0.7.0, as used with phpBB, allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) index.php, (2) song.php, (3) faq.php,… | EXPLOIT ✓HIGH 7.5EPSS 4.19% | 22 May 2006 |
| CVE-2006-2505 | Oracle Database Server 10g Release 2 allows local users to execute arbitrary SQL queries via a reference to a malicious package in the TYPE_NAME argument in the (1) GET_DOMAIN_INDEX_TABLES or (2) GET_V2_DOMAIN_INDEX_TABLES function in the… | EXPLOIT ×2 ✓LOW 3.6EPSS 2.09% | 22 May 2006 |
| CVE-2006-2503 | SQL injection vulnerability in misc.php in DeluxeBB 1.06 allows remote attackers to execute arbitrary SQL commands via the name parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.29% | 22 May 2006 |
| CVE-2006-2502 | Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allows remote attackers to execute arbitrary code via a long USER command. | EXPLOIT ×3 ✓MEDIUM 5.1EPSS 53.3% | 22 May 2006 |
| CVE-2006-2499 | SQL injection vulnerability in default.asp in CodeAvalanche News (CANews) 1.2 allows remote attackers to execute arbitrary SQL commands via the password field. | EXPLOIT ✓HIGH 7.5EPSS 1.29% | 20 May 2006 |
| CVE-2006-2497 | Multiple cross-site scripting (XSS) vulnerabilities in AspBB 0.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) action parameter to default.asp or (2) get parameter to profile.asp. | EXPLOIT ×2 ✓MEDIUM 5.8EPSS 2.07% | 20 May 2006 |
| CVE-2006-2494 | Stack-based buffer overflow in IntelliTamper 2.07 allows remote attackers to execute arbitrary code via a crafted .map file. | EXPLOIT ✓MEDIUM 5.1EPSS 5.27% | 20 May 2006 |
| CVE-2006-2491 | Cross-site scripting (XSS) vulnerability in (1) index.php and (2) bmc/admin.php in BoastMachine (bMachine) 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly filtered when it is… | EXPLOIT ✓MEDIUM 6.8EPSS 2.75% | 19 May 2006 |
| CVE-2006-2490 | Multiple cross-site scripting (XSS) vulnerabilities in Mobotix IP Network Cameras M1 1.9.4.7 and M10 2.0.5.2, and other versions before 2.2.3.18 for M10/D10 and 3.0.3.31 for M22, allow remote attackers to inject arbitrary web script or HTML via… | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 2.88% | 19 May 2006 |
| CVE-2006-2487 | Multiple PHP remote file inclusion vulnerabilities in ScozNews 1.2.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the CONFIG[main_path] parameter in (1) functions.php, (2) template.php, (3) news.php, (4) help.php, (5)… | EXPLOIT ✓HIGH 7.5EPSS 4.19% | 19 May 2006 |
| CVE-2006-2485 | PHP remote file inclusion vulnerability in includes/class_template.php in Quezza 1.0 and earlier, and possibly 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the quezza_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 4.43% | 19 May 2006 |
| CVE-2006-2483 | PHP remote file inclusion vulnerability in cart_content.php in Squirrelcart 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cart_isp_root parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 7.54% | 19 May 2006 |
| CVE-2006-2480 | Format string vulnerability in Dia 0.94 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering errors or warnings, as demonstrated via format string specifiers in a .bmp filename. | EXPLOIT ✓MEDIUM 5.1EPSS 7.63% | 19 May 2006 |
| CVE-2006-2474 | SQL injection vulnerability in lshop.cgi in Cosmoshop 8.11.106 and earlier allows remote attackers to execute arbitrary SQL commands via the artnum parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.25% | 19 May 2006 |
| CVE-2006-2473 | Cross-site scripting (XSS) vulnerability in ow.asp in OpenWiki 0.78 allows remote attackers to inject arbitrary web script or HTML via the p parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.94% | 19 May 2006 |
| CVE-2006-2465 | Buffer overflow in MP3Info 0.8.4 allows attackers to execute arbitrary code via a long command line argument. | EXPLOIT ×2 ✓MEDIUM 5.1EPSS 5.39% | 19 May 2006 |
| CVE-2006-2460 | Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variables such as $_GLOBALS and $_SESSION from modification, which allows remote attackers to conduct attacks such as directory traversal or… | EXPLOIT ✓MEDIUM 6.4EPSS 10.0% | 19 May 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.