Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
399,085 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026
25,049 results · page 397 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-2295 | Directory traversal vulnerability in Dynamic Galerie 1.0 allows remote attackers to access arbitrary files via an absolute path in the pfad parameter to (1) index.php and (2) galerie.php. | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.97% | 10 May 2006 |
| CVE-2006-2294 | Cross-site scripting (XSS) vulnerability in Dynamic Galerie 1.0 allows remote attackers to inject arbitrary web script or HTML via the pfad parameter in (1) index.php and (2) galerie.php. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 2.14% | 10 May 2006 |
| CVE-2006-2293 | SQL injection vulnerability in all_calendars.asp in MultiCalendars 3.0 allows remote attackers to execute arbitrary SQL commands via the calsids parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 1.21% | 10 May 2006 |
| CVE-2006-2285 | PHP remote file inclusion vulnerability in authldap.php in Dokeos 1.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the includePath parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 4.14% | 10 May 2006 |
| CVE-2006-2284 | Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) clarolineRepositorySys parameter in ldap.inc.php and the (2) claro_CasLibPath parameter in casProcess.inc.php. | EXPLOIT ✓MEDIUM 6.8EPSS 6.65% | 10 May 2006 |
| CVE-2006-2280 | Directory traversal vulnerability in website.php in openEngine 1.8 Beta 2 and earlier allows remote attackers to list arbitrary directories and read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.51% | 10 May 2006 |
| CVE-2006-2277 | Multiple Apple Mac OS X 10.4 applications might allow context-dependent attackers to cause a denial of service (application crash) via a crafted OpenEXR (.exr) image file, which triggers the crash when opening a folder using Finder, displaying the image… | EXPLOIT ✓MEDIUM 5.0EPSS 7.39% | 10 May 2006 |
| CVE-2006-2270 | PHP remote file inclusion vulnerability in includes/config.php in Jetbox CMS 2.1 allows remote attackers to execute arbitrary code via a URL in the relative_script_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 14.1% | 9 May 2006 |
| CVE-2006-2269 | Cross-site scripting (XSS) vulnerability in myWebland MyBloggie 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in a BBCode img tag. | EXPLOIT ✓MEDIUM 4.3EPSS 1.71% | 9 May 2006 |
| CVE-2006-2265 | Cross-site scripting vulnerability in admin/main.asp in Ocean12 Calendar Manager Pro 1.00 allows remote attackers to inject arbitrary web script or HTML via the date parameter. | EXPLOIT ✓LOW 2.6EPSS 2.01% | 9 May 2006 |
| CVE-2006-2264 | Multiple SQL injection vulnerabilities in Ocean12 Calendar Manager Pro 1.00 allow remote attackers to execute arbitrary SQL commands via the (1) date parameter to admin/main.asp, (2) SearchFor parameter to admin/view.asp, or (3) ID parameter to… | EXPLOIT ×3 ✓MEDIUM 6.5EPSS 1.14% | 9 May 2006 |
| CVE-2006-2263 | SQL injection vulnerability in shopcurrency.asp in VP-ASP 6.00 allows remote attackers to execute arbitrary SQL commands via the cid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.36% | 9 May 2006 |
| CVE-2006-2262 | Cross-site scripting (XSS) vulnerability in index.php in singapore 0.9.7 allows remote attackers to inject arbitrary web script or HTML via the image parameter. | EXPLOIT ✓LOW 2.6EPSS 2.17% | 9 May 2006 |
| CVE-2006-2261 | PHP remote file inclusion vulnerability in day.php in ACal 2.2.6 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.25% | 9 May 2006 |
| CVE-2006-2256 | PHP remote file inclusion vulnerability in includes/dbal.php in EQdkp 1.3.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the eqdkp_root_path parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 7.31% | 9 May 2006 |
| CVE-2006-2255 | Multiple SQL injection vulnerabilities in Creative Community Portal 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to (a) ArticleView.php, (2) forum_id parameter to (b) DiscView.php or (c)… | EXPLOIT ×6 ✓HIGH 7.5EPSS 2.38% | 9 May 2006 |
| CVE-2006-2254 | Buffer overflow in filecpnt.exe in FileCOPA 1.01 allows remote attackers to cause a denial of service (application crash) via a username with a large number of newline characters. | EXPLOIT ✓MEDIUM 5.0EPSS 3.87% | 9 May 2006 |
| CVE-2006-2253 | PHP remote file inclusion vulnerability in visible_count_inc.php in Statit 4 (060207) allows remote attackers to execute arbitrary PHP code via a URL in the statitpath parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.53% | 9 May 2006 |
| CVE-2006-2252 | Cross-site scripting vulnerability in submit.php in OpenFAQ 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 2.86% | 9 May 2006 |
| CVE-2006-2249 | Multiple cross-site scripting (XSS) vulnerabilities in search.php in CuteNews 1.4.1 and earlier, and possibly 1.4.5, allow remote attackers to inject arbitrary web script or HTML via the (1) user, (2) story, or (3) title parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 2.07% | 9 May 2006 |
| CVE-2006-2245 | PHP remote file inclusion vulnerability in auction\auction_common.php in Auction mod 1.3m for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 7.56% | 9 May 2006 |
| CVE-2006-2242 | acFTP 1.4 allows remote attackers to cause a denial of service (application crash) via a long string with "{" (brace) characters to the USER command. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 3.74% | 9 May 2006 |
| CVE-2006-2241 | PHP remote file inclusion vulnerability in show.php in Fast Click SQL Lite 1.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 3.76% | 9 May 2006 |
| CVE-2006-1172 | Stack-based buffer overflow in the createPKCS10 function in Cryptomathic Cenroll ActiveX Control 1.1.0.0 allows remote attackers to execute arbitrary code via vectors related to the TDC Digital signature. | EXPLOIT ✓MEDIUM 5.0EPSS 14.2% | 9 May 2006 |
| CVE-2006-0515 | Cisco PIX/ASA 7.1.x before 7.1(2) and 7.0.x before 7.0(5), PIX 6.3.x before 6.3.5(112), and FWSM 2.3.x before 2.3(4) and 3.x before 3.1(7), when used with Websense/N2H2, allows remote attackers to bypass HTTP access restrictions by splitting the GET… | EXPLOIT ✓HIGH 7.5EPSS 9.79% | 9 May 2006 |
| CVE-2006-2237 | The web interface for AWStats 6.4 and 6.5, when statistics updates are enabled, allows remote attackers to execute arbitrary code via shell metacharacters in the migrate parameter. | EXPLOIT ×3 ✓MEDIUM 5.1EPSS 58.4% | 8 May 2006 |
| CVE-2006-2236 | Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows remote attackers to execute arbitrary commands via a long remapShader command. | EXPLOIT ✓HIGH 7.6EPSS 7.59% | 8 May 2006 |
| CVE-2006-2233 | Buffer overflow in BankTown Client Control (aka BtCxCtl20Com) 1.4.2.51817, and possibly 1.5.2.50209, allows remote attackers to execute arbitrary code via a long string in the first argument to SetBannerUrl. | EXPLOIT ✓HIGH 7.5EPSS 7.15% | 5 May 2006 |
| CVE-2006-2230 | Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.4 might allow attackers to cause a denial of service via format string specifiers in an MP3 filename specified on the command line. | EXPLOIT ✓MEDIUM 5.0EPSS 7.09% | 5 May 2006 |
| CVE-2006-2228 | Cross-site scripting (XSS) vulnerability in w-Agora (aka Web-Agora) 4.2.0 allows remote attackers to inject arbitrary web script or HTML via a post with a BBCode tag that contains a JavaScript event name followed by whitespace before the '=' (equals)… | EXPLOIT ✓MEDIUM 4.3EPSS 2.06% | 5 May 2006 |
| CVE-2006-2226 | Buffer overflow in XM Easy Personal FTP Server 4.2 and 5.0.1 allows remote authenticated users to cause a denial of service via a long argument to the PORT command. | EXPLOIT ✓MEDIUM 5.0EPSS 3.50% | 5 May 2006 |
| CVE-2006-2225 | Buffer overflow in XM Easy Personal FTP Server 4.3 and earlier allows remote attackers to execute arbitrary code, probably via a USER command with a long username. | EXPLOIT ✓HIGH 7.5EPSS 6.03% | 5 May 2006 |
| CVE-2006-2224 | RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE packets. | EXPLOIT ✓MEDIUM 5.0EPSS 10.4% | 5 May 2006 |
| CVE-2006-2223 | RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote attackers to obtain sensitive information (routing state) via REQUEST… | EXPLOIT ✓MEDIUM 5.0EPSS 11.3% | 5 May 2006 |
| CVE-2006-2222 | Buffer overflow in zawhttpd 0.8.23, and possibly previous versions, allows remote attackers to cause a denial of service (daemon crash) via a request for a URI composed of several "\" (backslash) characters. | EXPLOIT ✓MEDIUM 5.0EPSS 4.00% | 5 May 2006 |
| CVE-2006-2217 | SQL injection vulnerability in index.php in Invision Power Board allows remote attackers to execute arbitrary SQL commands via the pid parameter in a reputation action. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 5 May 2006 |
| CVE-2006-2214 | Multiple SQL injection vulnerabilities in 4images 1.7.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sessionid parameter in (1) top.php and (2) member.php. | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.67% | 5 May 2006 |
| CVE-2006-2212 | Buffer overflow in KarjaSoft Sami FTP Server 2.0.2 and earlier allows remote attackers to execute arbitrary code via a long (1) USER or (2) PASS command. | EXPLOIT ✓MEDIUM 6.4EPSS 58.9% | 5 May 2006 |
| CVE-2006-2211 | Absolute path traversal vulnerability in index.php in 321soft PhP-Gallery 0.9 allows remote attackers to browse arbitrary directories via the path parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 3.23% | 5 May 2006 |
| CVE-2006-2210 | Cross-site scripting (XSS) vulnerability in index.php in 321soft PhP-Gallery 0.9 allows remote attackers to inject arbitrary web script or HTML via the path parameter. | EXPLOIT ✓MEDIUM 5.8EPSS 2.08% | 5 May 2006 |
| CVE-2006-2209 | Multiple SQL injection vulnerabilities in index.php in PHP Arena paCheckBook 1.1 allow remote attackers to execute arbitrary SQL commands via (1) the transtype parameter in an add action or (2) entry parameter in an edit action. | EXPLOIT ✓MEDIUM 6.4EPSS 1.22% | 5 May 2006 |
| CVE-2006-2208 | Multiple cross-site scripting (XSS) vulnerabilities in mynews.inc.php in MyNews 1.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) hash and (2) page parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 1.87% | 5 May 2006 |
| CVE-2006-1518 | Buffer overflow in the open_table function in sql_base.cc in MySQL 5.0.x up to 5.0.20 might allow remote attackers to execute arbitrary code via crafted COM_TABLE_DUMP packets with invalid length values. | EXPLOIT ✓MEDIUM 6.5EPSS 38.4% | 5 May 2006 |
| CVE-2006-1516 | The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to read portions of memory via a username without a trailing null byte, which causes a buffer over-read. | EXPLOIT ✓MEDIUM 5.0EPSS 35.8% | 5 May 2006 |
| CVE-2006-2187 | Multiple cross-site scripting (XSS) vulnerabilities in zenphoto 1.0.1 beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) a parameter in i.php, and the (2) album and (3) image parameters in index.php. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 2.04% | 4 May 2006 |
| CVE-2006-2182 | Multiple PHP remote file inclusion vulnerabilities in (1) eday.php, (2) eshow.php, or (3) forgot.php in albinator 2.0.8 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the Config_rootdir parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 7.59% | 4 May 2006 |
| CVE-2006-2181 | Multiple cross-site scripting (XSS) vulnerabilities in Albinator 2.0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) cid parameter to dlisting.php or (2) preloadSlideShow parameter to showpic.php. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 3.78% | 4 May 2006 |
| CVE-2006-2180 | Buffer overflow in Golden FTP Server Pro 2.70 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via a long argument to the (1) NLST or (2) APPE commands, as demonstrated by the Infigo FTPStress Fuzzer. | EXPLOIT ✓MEDIUM 6.4EPSS 6.84% | 4 May 2006 |
| CVE-2006-2179 | Multiple SQL injection vulnerabilities in CyberBuild allow remote attackers to execute arbitrary SQL commands via the (1) SessionID parameter to login.asp or (2) ProductIndex parameter to browse0.htm. | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.67% | 4 May 2006 |
| CVE-2006-2178 | Multiple cross-site scripting (XSS) vulnerabilities in CyberBuild allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to login.asp, (2) ProductIndex parameter to browse0.htm, (3) rowcolor parameter to… | EXPLOIT ×3 ✓MEDIUM 5.8EPSS 1.54% | 4 May 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.