Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
399,085 CVEs1,729 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026
25,049 results · page 399 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-2040 | Multiple SQL injection vulnerabilities in photokorn 1.53 and 1.542 allow remote attackers to execute arbitrary SQL commands via the (1) cat, (2) pic and (3) page parameter in index.php; (4) id parameter in postcard.php; and (5) cat parameter in print.php. | EXPLOIT ×3 ✓MEDIUM 6.4EPSS 3.90% | 26 April 2006 |
| CVE-2006-2037 | Cross-site scripting (XSS) vulnerability in index.php in Thwboard 3.0 Beta 2.84 allows remote attackers to inject arbitrary web script or HTML via the navpath parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.69% | 26 April 2006 |
| CVE-2006-1864 | Directory traversal vulnerability in smbfs in Linux 2.6.16 and earlier allows local users to escape chroot restrictions for an SMB-mounted filesystem via "..\\" sequences, a similar vulnerability to CVE-2006-1863. | EXPLOIT ✓MEDIUM 4.6EPSS 1.16% | 26 April 2006 |
| CVE-2006-2034 | SQL injection vulnerability in function/showprofile.php in FlexBB 0.5.5 allows remote attackers to execute arbitrary SQL commands, and view all usernames and passwords, via the id parameter to the showprofile page in index.php. | EXPLOIT ✓HIGH 7.5EPSS 2.31% | 26 April 2006 |
| CVE-2006-2032 | Multiple SQL injection vulnerabilities in Core CoreNews 2.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) icon_id and (2) userid parameters in preview.php. | EXPLOIT ✓MEDIUM 6.4EPSS 1.22% | 26 April 2006 |
| CVE-2006-2029 | Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) tid parameter in (a) preview.php; the (2) cid, (3) pid, and (4) eid parameters in (b) archive.php;… | EXPLOIT ×2 ✓MEDIUM 6.4EPSS 2.30% | 26 April 2006 |
| CVE-2006-2028 | Cross-site scripting (XSS) vulnerability in imagelist.php in Jeremy Ashcraft Simplog 0.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the imagedir parameter. | EXPLOIT ✓MEDIUM 5.8EPSS 2.67% | 26 April 2006 |
| CVE-2006-2027 | Buffer overflow in Unicode processing in the logging functionality in Pablo Software Solutions Quick 'n Easy FTP Server Professional and Lite, probably 3.0, allows remote authenticated users to execute arbitrary code by sending a command with a long… | EXPLOIT ✓MEDIUM 6.5EPSS 3.89% | 26 April 2006 |
| CVE-2006-2026 | Double free vulnerability in tif_jpeg.c in libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image that triggers errors related to "setfield/getfield… | EXPLOIT ✓MEDIUM 6.5EPSS 9.74% | 25 April 2006 |
| CVE-2006-2025 | Integer overflow in the TIFFFetchData function in tif_dirread.c for libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via a crafted TIFF image. | EXPLOIT ✓MEDIUM 6.5EPSS 10.5% | 25 April 2006 |
| CVE-2006-2024 | Multiple vulnerabilities in libtiff before 3.8.1 allow context-dependent attackers to cause a denial of service via a TIFF image that triggers errors in (1) the TIFFFetchAnyArray function in (a) tif_dirread.c; (2) certain "codec cleanup methods" in (b)… | EXPLOIT ✓MEDIUM 4.0EPSS 8.65% | 25 April 2006 |
| CVE-2006-1863 | Directory traversal vulnerability in CIFS in Linux 2.6.16 and earlier allows local users to escape chroot restrictions for an SMB-mounted filesystem via "..\\" sequences, a similar vulnerability to CVE-2006-1864. | EXPLOIT ✓LOW 2.1EPSS 1.02% | 25 April 2006 |
| CVE-2006-2022 | Buffer overflow in the parse_url function in the RTSP module (rtsp/parse_url.c) in Fenice 1.10 and earlier allows remote attackers to execute arbitrary code via a long URL. | EXPLOIT ×2 ✓HIGH 7.5EPSS 14.7% | 25 April 2006 |
| CVE-2006-2020 | Asterisk Recording Interface (ARI) in Asterisk@Home before 2.8 stores recordings/includes/main.conf under the web document root with insufficient access control, which allows remote attackers to obtain password information. | EXPLOIT ✓HIGH 7.8EPSS 8.01% | 25 April 2006 |
| CVE-2006-2019 | Apple Mac OS X Safari 2.0.3, 1.3.1, and possibly other versions allows remote attackers to cause a denial of service (CPU consumption and crash) via a TD element with a large number in the rowspan attribute. | EXPLOIT ✓MEDIUM 5.0EPSS 4.07% | 25 April 2006 |
| CVE-2006-2016 | Multiple cross-site scripting (XSS) vulnerabilities in phpLDAPadmin 0.9.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dn parameter in (a) compare_form.php, (b) copy_form.php, (c) rename_form.php, (d)… | EXPLOIT ×5 ✓LOW 2.6EPSS 8.22% | 25 April 2006 |
| CVE-2006-2012 | Format string vulnerability in Skulltag 0.96f and earlier allows remote attackers to cause a denial of service via the version string. | EXPLOIT ✓MEDIUM 5.0EPSS 3.53% | 25 April 2006 |
| CVE-2006-2008 | PHP remote file inclusion vulnerability in movie_cls.php in Built2Go PHP Movie Review 2B and earlier allows remote attackers to execute arbitrary PHP code via a URL in the full_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.45% | 25 April 2006 |
| CVE-2006-2005 | Eval injection vulnerability in index.php in ClanSys 1.1 allows remote attackers to execute arbitrary PHP code via PHP code in the page parameter, as demonstrated by using an "include" statement that is injected into the eval statement. | EXPLOIT ✓HIGH 7.5EPSS 3.26% | 25 April 2006 |
| CVE-2006-2002 | PHP remote file inclusion vulnerability in stats.php in MyGamingLadder 7.0 allows remote attackers to execute arbitrary PHP code via a URL in the dir[base] parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 2.88% | 25 April 2006 |
| CVE-2006-2001 | Cross-site scripting (XSS) vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the p parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 2.30% | 25 April 2006 |
| CVE-2006-1999 | The multiplayer menu in OpenTTD 0.4.7 allows remote attackers to cause a denial of service via a UDP packet with an incorrect size, which causes the client to return to the main menu. | EXPLOIT ✓MEDIUM 5.0EPSS 9.15% | 25 April 2006 |
| CVE-2006-1998 | OpenTTD 0.4.7 and earlier allows local users to cause a denial of service (application exit) via a large invalid error number, which triggers an error. | EXPLOIT ✓LOW 2.1EPSS 0.90% | 25 April 2006 |
| CVE-2006-1995 | Directory traversal vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to read arbitrary files via ".." sequences in the p parameter, which is not properly sanitized due to an rtrim function call with the arguments in the wrong order. | EXPLOIT ✓MEDIUM 5.0EPSS 4.38% | 25 April 2006 |
| CVE-2006-1994 | PHP remote file inclusion vulnerability in dForum 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DFORUM_PATH parameter to (1) about.php, (2) admin.php, (3) anmelden.php, (4) losethread.php, (5) config.php, (6)… | EXPLOIT ✓HIGH 7.5EPSS 3.44% | 25 April 2006 |
| CVE-2006-1993 | Mozilla Firefox 1.5.0.2, when designMode is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain Javascript that is not properly handled by the contentWindow.focus method in an iframe, which… | EXPLOIT ✓MEDIUM 5.1EPSS 54.0% | 25 April 2006 |
| CVE-2006-1992 | mshtml.dll 6.00.2900.2873, as used in Microsoft Internet Explorer, allows remote attackers to cause a denial of service (crash) via nested OBJECT tags, which trigger invalid pointer dereferences including NULL dereferences. | EXPLOIT ✓LOW 2.6EPSS 40.4% | 25 April 2006 |
| CVE-2006-0230 | Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses a client-side check to verify a password, which allows remote attackers to gain administrator privileges via a modified client that sends certain XML requests. | EXPLOIT ✓HIGH 10.0EPSS 16.1% | 25 April 2006 |
| CVE-2006-1985 | Heap-based buffer overflow in BOM BOMArchiveHelper 10.4 (6.3) Build 312, as used in Mac OS X 10.4.6 and earlier, allows user-assisted attackers to execute arbitrary code via a crafted archive (such as ZIP) that contains long path names, which triggers… | EXPLOIT ✓MEDIUM 5.1EPSS 13.9% | 21 April 2006 |
| CVE-2006-1982 | Heap-based buffer overflow in the LZWDecodeVector function in Mac OS X before 10.4.6, as used in applications that use ImageIO or AppKit, allows remote attackers to execute arbitrary code via crafted TIFF images. | EXPLOIT ✓HIGH 7.5EPSS 19.9% | 21 April 2006 |
| CVE-2006-1980 | Cross-site scripting (XSS) vulnerability in W2B Online Banking allows remote attackers to inject arbitrary web script or HTML via the (1) query string, (2) SID parameter, or (3) ilang parameter. | EXPLOIT ✓LOW 2.6EPSS 1.95% | 21 April 2006 |
| CVE-2006-1979 | Cross-site scripting (XSS) vulnerability in mwguest.php in Manic Web MWGuest 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the homepage parameter. | EXPLOIT ✓MEDIUM 5.8EPSS 1.78% | 21 April 2006 |
| CVE-2006-1978 | SQL injection vulnerability in inc/start.php in FlexBB 0.5.5 and earlier allows remote attackers to execute arbitrary SQL commands via the flexbb_username COOKIE parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.26% | 21 April 2006 |
| CVE-2006-1974 | SQL injection vulnerability in index.php in MyBB (MyBulletinBoard) before 1.04 allows remote attackers to execute arbitrary SQL commands via the referrer parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.03% | 21 April 2006 |
| CVE-2006-1971 | Cross-site scripting (XSS) vulnerability in login.php in KRANKIKOM ContentBoxX allows remote attackers to inject arbitrary web script or HTML via the action parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 2.09% | 21 April 2006 |
| CVE-2006-1965 | Multiple cross-site scripting (XSS) vulnerabilities in aasi media Net Clubs Pro 4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) onuser, (2) pass, (3) chatsys, (4) room, (5) username, and (6) to parameters in (a)… | EXPLOIT ×3 ✓MEDIUM 5.8EPSS 2.47% | 21 April 2006 |
| CVE-2006-1960 | Cross-site scripting (XSS) vulnerability in the appliance web user interface in Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13 allows remote attackers to inject arbitrary web script or HTML, possibly via the displayMsg… | EXPLOIT ✓MEDIUM 5.8EPSS 5.35% | 21 April 2006 |
| CVE-2006-1959 | PHP remote file inclusion vulnerability in direct.php in ActualScripts ActualAnalyzer Lite 2.72 and earlier, Gold 7.63 and earlier, and Server 8.23 and earlier allows remote attackers to execute arbitrary code via a URL in the rf parameter. | EXPLOIT ✓HIGH 7.5EPSS 13.1% | 21 April 2006 |
| CVE-2006-1954 | SQL injection vulnerability in authent.php4 in Nicolas Fischer (aka NFec) RechnungsZentrale V2 1.1.3, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the User field. | EXPLOIT ✓MEDIUM 5.0EPSS 1.71% | 21 April 2006 |
| CVE-2006-1950 | Multiple cross-site scripting (XSS) vulnerabilities in banners.cgi in PerlCoders BannerFarm 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) aff and (2) cat parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 1.88% | 20 April 2006 |
| CVE-2006-1947 | Multiple SQL injection vulnerabilities in plexum.php in NicPlex Plexum X5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) pagesize, (2) maxrec, and (3) startpos parameters. | EXPLOIT ✓HIGH 7.5EPSS 1.14% | 20 April 2006 |
| CVE-2006-1946 | Multiple cross-site scripting (XSS) vulnerabilities in Visale 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the keyval parameter in pbpgst.cgi, (2) the catsubno parameter in pblscg.cgi, and (3) the listno… | EXPLOIT ×3 ✓LOW 2.6EPSS 2.24% | 20 April 2006 |
| CVE-2006-1945 | Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the config parameter. | EXPLOIT ✓LOW 2.6EPSS 4.83% | 20 April 2006 |
| CVE-2006-1944 | Multiple cross-site scripting (XSS) vulnerabilities in SibSoft CommuniMail 1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the list_id parameter in mailadmin.cgi and (2) the form_id parameter in templates.cgi. | EXPLOIT ×2 ✓LOW 2.6EPSS 2.10% | 20 April 2006 |
| CVE-2006-1943 | Multiple cross-site scripting (XSS) vulnerabilities in Smarter Scripts IntelliLink Pro 5.06 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter in addlink_lwp.cgi and the (2) id, (3) forgotid, and (4)… | EXPLOIT ×2 ✓LOW 2.6EPSS 2.10% | 20 April 2006 |
| CVE-2006-1941 | Neon Responder 5.4 for LANsurveyor allows remote attackers to cause a denial of service (application outage) via a crafted Clock Synchronisation packet that triggers an access violation. | EXPLOIT ✓MEDIUM 5.0EPSS 3.72% | 20 April 2006 |
| CVE-2006-1931 | The HTTP/XMLRPC server in Ruby before 1.8.2 uses blocking sockets, which allows attackers to cause a denial of service (blocked connections) via a large amount of data. | EXPLOIT ✓MEDIUM 5.0EPSS 10.2% | 20 April 2006 |
| CVE-2006-1929 | PHP remote file inclusion vulnerability in include/common.php in I-Rater Platinum allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 6.96% | 20 April 2006 |
| CVE-2006-1926 | SQL injection vulnerability in showtopic.php in ThWboard 2.84 beta 3 and earlier allows remote attackers to execute arbitrary SQL commands via the pagenum parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 1.10% | 20 April 2006 |
| CVE-2006-1925 | Directory traversal vulnerability in the editnews module (inc/editnews.mdu) in index.php in CuteNews 1.4.1 allows remote attackers to read or modify files via the source parameter in the (1) editnews or (2) doeditnews action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.80% | 20 April 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.