Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
399,059 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026
25,049 results · page 396 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-2459 | SQL injection vulnerability in messages.php in PHP-Fusion 6.00.307 and earlier allows remote authenticated users to execute arbitrary SQL commands via the srch_where parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 2.07% | 19 May 2006 |
| CVE-2006-2458 | Multiple heap-based buffer overflows in Libextractor 0.5.13 and earlier allow remote attackers to execute arbitrary code via (1) the asf_read_header function in the ASF plugin (plugins/asfextractor.c), and (2) the parse_trak_atom function in the QT… | EXPLOIT ✓MEDIUM 4.0EPSS 8.93% | 18 May 2006 |
| CVE-2006-2437 | The viewfile servlet in the documentation package (resin-doc) for Caucho Resin 3.0.17 and 3.0.18 allows remote attackers to obtain the source code for file under the web root via the file parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 6.75% | 17 May 2006 |
| CVE-2006-2431 | Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (8880/tcp) in IBM WebSphere Application Server 5.0.2 and earlier, 5.1.x before 5.1.1.12, and 6.0.2 up to 6.0.2.7, allows remote attackers to inject arbitrary… | EXPLOIT ✓MEDIUM 4.3EPSS 3.01% | 17 May 2006 |
| CVE-2006-2426 | Sun Java Runtime Environment (JRE) 1.5.0_6 and earlier, JDK 1.5.0_6 and earlier, and SDK 1.5.0_6 and earlier allows remote attackers to cause a denial of service (disk consumption) by using the Font.createFont function to create temporary files of… | EXPLOIT ✓MEDIUM 6.4EPSS 12.7% | 17 May 2006 |
| CVE-2006-2425 | Multiple cross-site scripting (XSS) vulnerabilities in PRV.php in PhpRemoteView, possibly 2003-10-23 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) f, (2) d, and (3) ref parameters, and the (4) "MAKE DIR" and (5)… | EXPLOIT ✓MEDIUM 4.3EPSS 2.07% | 17 May 2006 |
| CVE-2006-2424 | PHP remote file inclusion vulnerability in ezUserManager 1.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the ezUserManager_Path parameter to ezusermanager_pwd_forgott.php, possibly… | EXPLOIT ✓MEDIUM 5.1EPSS 3.28% | 17 May 2006 |
| CVE-2006-2423 | Cross-site scripting (XSS) vulnerability in ftplogin/index.php in Confixx 3.1.2 allows remote attackers to inject arbitrary web script or HTML via the login parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 2.09% | 17 May 2006 |
| CVE-2006-2413 | GNUnet before SVN revision 2781 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an empty UDP datagram, possibly involving FIONREAD errors. | EXPLOIT ✓MEDIUM 5.0EPSS 5.04% | 16 May 2006 |
| CVE-2006-2412 | The raydium_network_read function in network.c in Raydium SVN revision 312 and earlier allows remote attackers to cause a denial of service (application crash) via a large ID, which causes an invalid memory access (buffer over-read). | EXPLOIT ✓MEDIUM 5.0EPSS 3.70% | 16 May 2006 |
| CVE-2006-2411 | Buffer overflow in raydium_network_read function in network.c in Raydium SVN revision 312 and earlier allows remote attackers to execute arbitrary code by sending packets with long global variables to the client. | EXPLOIT ✓HIGH 7.5EPSS 5.61% | 16 May 2006 |
| CVE-2006-2410 | raydium_network_netcall_exec function in network.c in Raydium SVN revision 312 and earlier allows remote attackers to cause a denial of service (application crash) via a packet of type 0xFF, which causes a null dereference. | EXPLOIT ✓MEDIUM 5.0EPSS 3.70% | 16 May 2006 |
| CVE-2006-2409 | Format string vulnerability in the raydium_log function in console.c in Raydium before SVN revision 310 allows local users to execute arbitrary code via format string specifiers in the format parameter, which are not properly handled in a call to… | EXPLOIT ✓MEDIUM 4.6EPSS 0.89% | 16 May 2006 |
| CVE-2006-2408 | Multiple buffer overflows in Raydium before SVN revision 310 allow remote attackers to execute arbitrary code via a large packet when logged via (1) the raydium_log function in log.c or (2) the raydium_console_line_add function in console.c, possibly… | EXPLOIT ✓HIGH 7.5EPSS 6.03% | 16 May 2006 |
| CVE-2006-2407 | Stack-based buffer overflow in (1) WeOnlyDo wodSSHServer ActiveX Component 1.2.7 and 1.3.3 DEMO, as used in other products including (2) FreeSSHd 1.0.9 and (3) freeFTPd 1.0.10, allows remote attackers to execute arbitrary code via a long key exchange… | EXPLOIT ×3 ✓HIGH 7.5EPSS 71.4% | 16 May 2006 |
| CVE-2006-2406 | Directory traversal vulnerability in bb_lib/abbc.css.php in Unclassified NewsBoard (UNB) 1.5.3-d and possibly earlier versions, when register_globals is enabled, allows remote attackers to include arbitrary files via .. | EXPLOIT ✓LOW 2.6EPSS 2.31% | 16 May 2006 |
| CVE-2006-2405 | Directory traversal vulnerability in unb_lib/abbc.conf.php in Unclassified NewsBoard (UNB) 1.6.1 patch 1 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via .. | EXPLOIT ✓MEDIUM 6.8EPSS 3.37% | 16 May 2006 |
| CVE-2006-2404 | Directory traversal vulnerability in popup.php in RadScripts RadLance Gold 7.0 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.4EPSS 3.27% | 16 May 2006 |
| CVE-2006-2402 | Buffer overflow in the changeRegistration function in servernet.cpp for Outgun 1.0.3 bot 2 and earlier allows remote attackers to change the registration information of other players via a long string. | EXPLOIT ✓MEDIUM 5.0EPSS 2.95% | 16 May 2006 |
| CVE-2006-2401 | The leetnet functions (leetnet/rudp.cpp) in Outgun 1.0.3 bot 2 and earlier allow remote attackers to cause a denial of service (application crash) via packets with incorrect message sizes, which triggers a buffer over-read. | EXPLOIT ✓HIGH 7.8EPSS 4.09% | 16 May 2006 |
| CVE-2006-2400 | The leetnet functions (leetnet/rudp.cpp) in Outgun 1.0.3 bot 2 and earlier allow remote attackers to cause a denial of service (game interruption) via large packets, which cause an exception to be thrown. | EXPLOIT ✓HIGH 7.8EPSS 4.09% | 16 May 2006 |
| CVE-2006-2399 | Stack-based buffer overflow in the ServerNetworking::incoming_client_data function in servnet.cpp in Outgun 1.0.3 bot 2 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a… | EXPLOIT ✓HIGH 7.5EPSS 5.74% | 16 May 2006 |
| CVE-2006-2398 | Directory traversal vulnerability in index.php in GPhotos 1.5 and earlier allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 4.23% | 16 May 2006 |
| CVE-2006-2397 | Multiple cross-site scripting (XSS) vulnerabilities in GPhotos 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) rep parameter to (a) index.php or (b) diapo.php or (2) image parameter to (c) affich.php. | EXPLOIT ×3 ✓MEDIUM 5.8EPSS 2.76% | 16 May 2006 |
| CVE-2006-2396 | Cross-site scripting (XSS) vulnerability in phpODP 1.5h allows remote attackers to inject arbitrary web script via the browse parameter. | EXPLOIT ✓MEDIUM 5.8EPSS 1.95% | 16 May 2006 |
| CVE-2006-2395 | PHP remote file inclusion vulnerability in resources/includes/popp.config.loader.inc.php in PopSoft Digital PopPhoto Studio 3.5.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter… | EXPLOIT ✓MEDIUM 5.0EPSS 3.58% | 16 May 2006 |
| CVE-2006-2393 | The client_cmd function in Empire 4.3.2 and earlier allows remote attackers to cause a denial of service (application crash) by causing long text strings to be appended to the player->client buffer, which causes an invalid memory access. | EXPLOIT ✓MEDIUM 5.0EPSS 3.76% | 16 May 2006 |
| CVE-2006-2392 | PHP remote file inclusion vulnerability in public_includes/pub_popup/popup_finduser.php in PHP Blue Dragon Platinum 2.8.0 allows remote attackers to execute arbitrary PHP code via a URL in the vsDragonRootPath parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 7.67% | 16 May 2006 |
| CVE-2006-2390 | Cross-site scripting (XSS) vulnerability in OZJournals 1.2 allows remote attackers to inject arbitrary web script or HTML via the vname parameter in the comments functionality. | EXPLOIT ✓MEDIUM 5.8EPSS 1.77% | 16 May 2006 |
| CVE-2006-2369 | RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as "Type 1 - None", which is… | EXPLOIT ×4 ✓HIGH 7.5EPSS 92.4% | 15 May 2006 |
| CVE-2006-2365 | Cross-site scripting (XSS) vulnerability in a_login.php in Vizra allows remote attackers to inject arbitrary web script or HTML via the message parameter. | EXPLOIT ✓MEDIUM 5.8EPSS 1.55% | 15 May 2006 |
| CVE-2006-2363 | SQL injection vulnerability in the weblinks option (weblinks.html.php) in Limbo CMS allows remote attackers to execute arbitrary SQL commands via the catid parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 2.27% | 15 May 2006 |
| CVE-2006-2362 | Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via… | EXPLOIT ✓HIGH 7.3EPSS 14.5% | 15 May 2006 |
| CVE-2006-2361 | PHP remote file inclusion vulnerability in pafiledb_constants.php in Download Manager (mxBB pafiledb) integration, as used with phpBB, allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.25% | 15 May 2006 |
| CVE-2006-2360 | SQL injection vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.12% | 15 May 2006 |
| CVE-2006-2359 | Cross-site scripting (XSS) vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to inject arbitrary web script or HTML via the id parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.00% | 15 May 2006 |
| CVE-2006-2351 | Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow remote attackers to inject arbitrary web script or HTML via the (1) sDeviceView or (2) nDeviceID parameter to (a)… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 4.55% | 15 May 2006 |
| CVE-2006-2341 | The HTTP proxy in Symantec Gateway Security 5000 Series 2.0.1 and 3.0, and Enterprise Firewall 8.0, when NAT is being used, allows remote attackers to determine internal IP addresses by using malformed HTTP requests, as demonstrated using a get request… | EXPLOIT ✓MEDIUM 5.0EPSS 3.79% | 12 May 2006 |
| CVE-2006-2339 | SQL injection vulnerability in index.php in evoTopsites 2.x and evoTopsites Pro 2.x allows remote attackers to execute arbitrary SQL commands via the (1) cat_id and (2) id parameters. | EXPLOIT ✓MEDIUM 6.4EPSS 1.26% | 12 May 2006 |
| CVE-2006-2336 | SQL injection vulnerability in showthread.php in MyBB (aka MyBulletinBoard) 1.1.1 allows remote attackers to execute arbitrary SQL commands via the comma parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 1.10% | 12 May 2006 |
| CVE-2006-2334 | The RtlDosPathNameToNtPathName_U API function in NTDLL.DLL in Microsoft Windows 2000 SP4 and XP SP2 does not properly convert DOS style paths with trailing spaces into NT style paths, which allows context-dependent attackers to create files that cannot… | EXPLOIT ✓LOW 2.1EPSS 3.35% | 12 May 2006 |
| CVE-2006-2331 | Multiple directory traversal vulnerabilities in PHP-Fusion 6.00.306 allow remote attackers to include and execute arbitrary local files via (1) a .. | EXPLOIT ✓MEDIUM 6.4EPSS 4.36% | 12 May 2006 |
| CVE-2006-2330 | PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of arbitrary types using a filename that contains two or more extensions that ends in an assumed-valid extension… | EXPLOIT ✓MEDIUM 6.4EPSS 7.83% | 12 May 2006 |
| CVE-2006-2323 | Multiple PHP remote file inclusion vulnerabilities in SmartISoft phpListPro 2.01 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the returnpath parameter in (1) editsite.php, (2) addsite.php, and (3) in.php. | EXPLOIT ✓MEDIUM 5.1EPSS 9.85% | 12 May 2006 |
| CVE-2006-2316 | S24EvMon.exe in the Intel PROset/Wireless software, possibly 10.1.0.33, uses a S24EventManagerSharedMemory shared memory section with weak permissions, which allows local users to read or modify passwords or other data, or cause a denial of service. | EXPLOIT ✓MEDIUM 4.9EPSS 0.87% | 12 May 2006 |
| CVE-2006-2315 | PHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the go_info[server][classes_root] parameter. | EXPLOIT ✓HIGH 7.5EPSS 4.83% | 12 May 2006 |
| CVE-2006-2306 | Cross-site scripting (XSS) vulnerability in moreinfo.asp in EPublisherPro allows remote attackers to inject arbitrary web script or HTML via the title parameter. | EXPLOIT ✓HIGH 9.3EPSS 2.91% | 11 May 2006 |
| CVE-2006-2300 | Multiple SQL injection vulnerabilities in EImagePro allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter to subList.asp, (2) SubjectID parameter to imageList.asp, or (3) Pic parameter to view.asp. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.74% | 11 May 2006 |
| CVE-2006-2297 | Heap-based buffer overflow in Microsoft Infotech Storage System Library (itss.dll) allows user-assisted attackers to execute arbitrary code via a crafted CHM / ITS file that triggers the overflow while decompiling. | EXPLOIT ✓MEDIUM 4.0EPSS 19.4% | 10 May 2006 |
| CVE-2006-2296 | SQL injection vulnerability in search_result.asp in EDirectoryPro 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the keyword parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 1.21% | 10 May 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.