Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
399,085 CVEs1,728 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026
25,049 results · page 398 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-2177 | Cross-site scripting (XSS) vulnerability in viewcat.php in geoBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via the cat parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.69% | 4 May 2006 |
| CVE-2006-2176 | Multiple cross-site scripting (XSS) vulnerabilities in links.php in PHP Linkliste 1.0b allow remote attackers to inject arbitrary web script or HTML via the (1) new_input, (2) new_url, or (3) new_name parameter. | EXPLOIT ✓MEDIUM 5.8EPSS 1.79% | 4 May 2006 |
| CVE-2006-2175 | PHP remote file inclusion vulnerability in FtrainSoft Fast Click 2.3.8 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) show.php or (2) top.php. | EXPLOIT ✓MEDIUM 6.4EPSS 8.87% | 4 May 2006 |
| CVE-2006-2174 | Multiple cross-site scripting (XSS) vulnerabilities in admin/server_day_stats.php in Virtual Hosting Control System (VHCS) allow remote attackers to inject arbitrary web script or HTML via the (1) day, (2) month, or (3) year parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.93% | 4 May 2006 |
| CVE-2006-2163 | Cross-site scripting (XSS) vulnerability in index.php in Pinnacle Cart 3.33 and earlier allows remote attackers to inject arbitrary web script or HTML via the setbackurl parameter. | EXPLOIT ✓LOW 2.6EPSS 1.77% | 4 May 2006 |
| CVE-2006-2156 | Directory traversal vulnerability in help/index.php in X7 Chat 2.0 and earlier allows remote attackers to include arbitrary files via .. | EXPLOIT ✓MEDIUM 6.4EPSS 7.92% | 3 May 2006 |
| CVE-2006-2152 | PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via the phpbb_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 8.34% | 3 May 2006 |
| CVE-2006-2151 | PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via the phpbb_root_path parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 11.0% | 3 May 2006 |
| CVE-2006-2149 | PHP remote file inclusion vulnerability in sources/lostpw.php in Aardvark Topsites PHP 4.2.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the CONFIG[path] parameter, as demonstrated by… | EXPLOIT ✓MEDIUM 6.4EPSS 7.67% | 3 May 2006 |
| CVE-2006-2144 | PHP remote file inclusion vulnerability in kopf.php in DMCounter 0.9.2-b allows remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 3.83% | 2 May 2006 |
| CVE-2006-2143 | Multiple cross-site scripting (XSS) vulnerabilities in TextFileBB 1.0.16 allow remote attackers to inject arbitrary web script or HTML via Javascript events such as "onmouseover" in the (1) color, (2) size, or (3) url bbcode tags. | EXPLOIT ✓MEDIUM 4.3EPSS 1.93% | 2 May 2006 |
| CVE-2006-2142 | PHP remote file inclusion vulnerability in classes/adodbt/sql.php in Limbo CMS 1.04 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the classes_dir parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 7.92% | 2 May 2006 |
| CVE-2006-2141 | Cross-site scripting (XSS) vulnerability in popup_image in Collaborative Portal Server (CPS) 3.4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the pos argument. | EXPLOIT ✓MEDIUM 4.3EPSS 3.82% | 2 May 2006 |
| CVE-2006-2140 | Multiple cross-site scripting (XSS) vulnerabilities in OrbitHYIP 2.0 and earlier allow remote attackers to inject arbitrary web script via the (1) referral parameter to signup.php or (2) id parameter to members.php. | EXPLOIT ×2 ✓MEDIUM 5.8EPSS 1.98% | 2 May 2006 |
| CVE-2006-2138 | Cross-site scripting (XSS) vulnerability in neomail.pl in NeoMail 1.29 allows remote attackers to inject arbitrary web script or HTML via the sessionid parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.93% | 2 May 2006 |
| CVE-2006-2137 | PHP remote file inclusion vulnerability in master.php in OpenPHPNuke and 2.3.3 earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.64% | 2 May 2006 |
| CVE-2006-2134 | PHP remote file inclusion vulnerability in /includes/kb_constants.php in Knowledge Base Mod for PHPbb 2.0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 9.50% | 2 May 2006 |
| CVE-2006-2109 | Cross-site scripting (XSS) vulnerability in the parse_query_str function in include/print.php in JSBoard 2.0.10 and 2.0.11, and possibly other versions before 2.0.12, allows remote attackers to inject arbitrary web script or HTML via parameters that are… | EXPLOIT ✓MEDIUM 6.8EPSS 2.29% | 2 May 2006 |
| CVE-2006-2132 | SQL injection vulnerability in detail.asp in DUclassified allows remote attackers to execute arbitrary SQL commands via the iPro parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 0.90% | 1 May 2006 |
| CVE-2006-2127 | SQL injection vulnerability in weblog_posting.php in Blog Mod 0.2.x allows remote attackers to execute arbitrary SQL commands via the r parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 1.64% | 1 May 2006 |
| CVE-2006-2126 | SQL injection vulnerability in pocategories.php in MaxTrade 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) categori and (2) stranica parameters. | EXPLOIT ✓MEDIUM 6.4EPSS 1.21% | 1 May 2006 |
| CVE-2006-2124 | Multiple cross-site scripting (XSS) vulnerabilities in SunShop 3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) prevaction, (2) previd, (3) prevstart, (4) itemid, (5) id, and (6) action parameters in index.php. | EXPLOIT ✓MEDIUM 5.8EPSS 1.88% | 1 May 2006 |
| CVE-2006-2122 | PHP remote file inclusion vulnerability in index.php in CoolMenus allows remote attackers to execute arbitrary code via a URL in the page parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 4.30% | 1 May 2006 |
| CVE-2006-2121 | PHP remote file include vulnerability in admin/config_settings.tpl.php in I-RATER Platinum allows remote attackers to execute arbitrary code via a URL in the include_path parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 3.79% | 1 May 2006 |
| CVE-2006-2119 | PHP remote file inclusion vulnerability in event/index.php in Artmedic Event allows remote attackers to execute arbitrary code via a URL in the page parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 5.93% | 1 May 2006 |
| CVE-2006-2116 | planetGallery allows remote attackers to gain administrator privileges via a direct request to admin/gallery_admin.php. | EXPLOIT ✓HIGH 7.5EPSS 2.67% | 1 May 2006 |
| CVE-2006-2111 | A component in Microsoft Outlook Express 6 allows remote attackers to bypass domain restrictions and obtain sensitive information via redirections with the mhtml: URI handler, as originally reported for Internet Explorer 6 and 7, aka "URL Redirect Cross… | EXPLOIT ✓MEDIUM 4.3EPSS 40.3% | 1 May 2006 |
| CVE-2006-2108 | parser.exe in Océ (OCE) 3121/3122 Printer allows remote attackers to cause a denial of service (crash or reboot) via a long request, possibly triggering a buffer overflow. | EXPLOIT ✓HIGH 7.8EPSS 3.79% | 29 April 2006 |
| CVE-2006-2107 | Buffer overflow in BL4 SMTP Server 0.1.4 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long argument to the (1) EHLO, (2) MAIL FROM, and (3) RCPT TO commands. | EXPLOIT ✓HIGH 7.5EPSS 4.84% | 29 April 2006 |
| CVE-2006-2102 | Directory traversal vulnerability in PowerISO 2.9 allows remote attackers to write arbitrary files via a .. | EXPLOIT ✓HIGH 7.8EPSS 3.72% | 29 April 2006 |
| CVE-2006-2101 | Directory traversal vulnerability in WinISO 5.3 allows remote attackers to write arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.14% | 29 April 2006 |
| CVE-2006-2100 | Directory traversal vulnerability in Magic ISO 5.0 Build 0166 allows remote attackers to write arbitrary files via a .. | EXPLOIT ✓HIGH 7.8EPSS 3.72% | 29 April 2006 |
| CVE-2006-2099 | Directory traversal vulnerability in UltraISO 8.0.0.1392 allows remote attackers to write arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.14% | 29 April 2006 |
| CVE-2006-2097 | SQL injection vulnerability in func_msg.php in Invision Power Board (IPB) 2.1.4 allows remote attackers to execute arbitrary SQL commands via the from_contact field in a private message (PM). | EXPLOIT ✓HIGH 7.5EPSS 1.19% | 29 April 2006 |
| CVE-2006-2094 | Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, uses modal dialogs to verify that a user wishes to run an ActiveX control or perform other risky… | EXPLOIT ✓MEDIUM 5.1EPSS 23.1% | 29 April 2006 |
| CVE-2006-2089 | Multiple cross-site scripting (XSS) vulnerabilities in misc.php in MySmartBB 1.1.x allow remote attackers to inject arbitrary web script or HTML via the (1) id and (2) username parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 1.70% | 29 April 2006 |
| CVE-2006-2086 | Buffer overflow in JuniperSetupDLL.dll, loaded from JuniperSetup.ocx by the Juniper SSL-VPN Client when accessing a Juniper NetScreen IVE device running IVE OS before 4.2r8.1, 5.0 before 5.0r6.1, 5.1 before 5.1r8, 5.2 before 5.2r4.1, or 5.3 before… | EXPLOIT ✓HIGH 7.5EPSS 67.3% | 29 April 2006 |
| CVE-2006-2081 | Oracle Database Server 10g Release 2 allows local users to execute arbitrary SQL queries via the GET_DOMAIN_INDEX_METADATA function in the DBMS_EXPORT_EXTENSION package. | EXPLOIT ×2 ✓MEDIUM 4.6EPSS 21.6% | 27 April 2006 |
| CVE-2006-2079 | Cross-site scripting (XSS) vulnerability in portfolio.php in Verosky Media Instant Photo Gallery, possibly before 1.0.2, allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.87% | 27 April 2006 |
| CVE-2006-2070 | Cross-site scripting (XSS) vulnerability in member.php in DevBB 1.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the member parameter in a viewpro action. | EXPLOIT ✓MEDIUM 4.3EPSS 2.06% | 27 April 2006 |
| CVE-2006-2067 | SQL injection vulnerability in vb_board_functions.php in MKPortal 1.1, as used with vBulletin 3.5.4 and earlier, allows remote attackers to execute arbitrary SQL commands via the userid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.14% | 27 April 2006 |
| CVE-2006-2066 | Multiple cross-site scripting (XSS) vulnerabilities pm_popup.php in MKPortal 1.1 Rc1 and earlier, as used with vBulletin 3.5.4 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) u1, (2) m1, (3) m2, (4) m3, (5) m4… | EXPLOIT ✓MEDIUM 4.3EPSS 2.62% | 27 April 2006 |
| CVE-2006-2065 | SQL injection vulnerability in save.php in PHPSurveyor 0.995 and earlier allows remote attackers to execute arbitrary SQL commands via the surveyid cookie. | EXPLOIT ✓HIGH 7.5EPSS 1.71% | 27 April 2006 |
| CVE-2006-2061 | SQL injection vulnerability in lib/func_taskmanager.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary SQL commands via the ck parameter, which can inject at most 32 characters. | EXPLOIT ✓MEDIUM 5.0EPSS 1.57% | 26 April 2006 |
| CVE-2006-2059 | action_public/search.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary PHP code via a search with a crafted value of the lastdate parameter, which alters the behavior of a regular expression… | EXPLOIT ✓MEDIUM 5.0EPSS 7.85% | 26 April 2006 |
| CVE-2006-2052 | Cross-site scripting (XSS) vulnerability in Verosky Media Instant Photo Gallery allows remote attackers to inject arbitrary web script or HTML via the member parameter in a viewpro action in member.php. | EXPLOIT ×2 ✓MEDIUM 5.8EPSS 1.82% | 26 April 2006 |
| CVE-2006-2051 | Multiple cross-site scripting (XSS) vulnerabilities in myadmin/index.php in NextAge Shopping Cart allow remote attackers to inject arbitrary web script or HTML via the (1) username and (2) password parameters. | EXPLOIT ✓MEDIUM 5.8EPSS 1.79% | 26 April 2006 |
| CVE-2006-2048 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Edwin van Wijk phpWebFTP 2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) port, (2) server, and (3) user parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 2.09% | 26 April 2006 |
| CVE-2006-2046 | Multiple SQL injection vulnerabilities in Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) category and (2) keywords parameters in (a) Results.cfm, and the (3) ProdID… | EXPLOIT ×2 ✓MEDIUM 6.4EPSS 4.05% | 26 April 2006 |
| CVE-2006-2043 | na-img-4.0.34.bin for the IP3 Networks NetAccess NA75 allows local users to gain Unix shell access via "`" (backtick) characters in the appliance's command line interface (CLI). | EXPLOIT ✓MEDIUM 4.6EPSS 0.65% | 26 April 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.