SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-29 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

399,085 CVEs1,729 in CISA KEV17,272 with EPSS ≥ 10%25,049 with a public exploitUpdated 29 September 2026

25,049 results · page 400 of 501

CVESummaryPriorityPublished
CVE-2006-1922PHP remote file inclusion vulnerability in (1) about.php or (2) auth.php in TotalCalendar allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter.EXPLOIT ✓MEDIUM 6.4EPSS 3.00%20 April 2006
CVE-2006-1921nettools.php in PHP Net Tools 2.7.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the host parameter.EXPLOIT ✓MEDIUM 6.4EPSS 3.97%20 April 2006
CVE-2006-1919PHP remote file inclusion vulnerability in index.php in Internet Photoshow 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.EXPLOIT ✓HIGH 7.5EPSS 3.79%20 April 2006
CVE-2006-1918Multiple cross-site scripting (XSS) vulnerabilities in Papoo 2.1.5 allow remote attackers to inject arbitrary web script or HTML via the menuid parameter to (1) index.php or (2) forum.php, or the (3) reporeid_print parameter to print.php.EXPLOIT ✓LOW 2.6EPSS 1.71%20 April 2006
CVE-2006-1917SQL injection vulnerability in member.php in Blackorpheus ClanMemberSkript 1.0 allows remote attackers to execute arbitrary SQL commands via the userID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.42%20 April 2006
CVE-2006-1916Multiple cross-site scripting (XSS) vulnerabilities in profile.php in DbbS 2.0-alpha and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ulocation or (2) uhobbies parameters.EXPLOIT ✓MEDIUM 6.8EPSS 1.93%20 April 2006
CVE-2006-1913Cross-site scripting (XSS) vulnerability in jax_guestbook.php in Jax Guestbook 3.1, 3.31, and 3.50 allows remote attackers to inject arbitrary web script or HTML via the page parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.78%20 April 2006
CVE-2006-1912MyBB (MyBulletinBoard) 1.1.0 does not set the constant KILL_GLOBAL variable in (1) global.php and (2) inc/init.php, which allows remote attackers to initialize arbitrary variables that are processed by an @extract command, which could then be leveraged…EXPLOIT ✓MEDIUM 5.8EPSS 1.60%20 April 2006
CVE-2006-1909Directory traversal vulnerability in index.php in Coppermine 1.4.4 allows remote attackers to read arbitrary files via a .//./ (modified dot dot slash) in the file parameter, which causes a regular expression to collapse the sequences into standard…EXPLOIT ✓MEDIUM 5.0EPSS 3.62%20 April 2006
CVE-2006-1906Cross-site scripting (XSS) vulnerability in index.php in jjgan852 phpLister 0.4.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter.EXPLOIT ✓LOW 2.6EPSS 1.95%20 April 2006
CVE-2006-1905Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.3 allow remote attackers to execute arbitrary code via format string specifiers in a long filename on an EXTINFO line in a playlist file.EXPLOIT ✓HIGH 7.5EPSS 14.3%20 April 2006
CVE-2006-1900Multiple buffer overflows in World Wide Web Consortium (W3C) Amaya 9.4, and possibly other versions including 8.x before 8.8.5, allow remote attackers to execute arbitrary code via a long value in (1) the COMPACT attribute of the COLGROUP element, (2)…EXPLOIT ×2 ✓HIGH 7.6EPSS 16.5%20 April 2006
CVE-2006-1893Cross-site scripting (XSS) vulnerability in print.php in ar-blog 5.2 allows remote attackers to inject arbitrary web script or HTML via the id parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.95%20 April 2006
CVE-2006-1878Cross-site scripting (XSS) vulnerability in index.php in phpFaber TopSites allows remote attackers to inject arbitrary web script or HTML via the page parameter.EXPLOIT ✓LOW 2.6EPSS 2.17%20 April 2006
CVE-2006-1853Multiple SQL injection vulnerabilities in ModernBill 4.3.2 and earlier allow remote attackers or administrators to execute arbitrary SQL commands via the (1) id parameter in (a) user.php, or (2) where and (3) order parameters to (b) admin.php.EXPLOIT ✓MEDIUM 6.5EPSS 1.00%19 April 2006
CVE-2006-1852SQL injection vulnerability in category.php in Article Publisher Pro 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cname parameter.EXPLOIT ✓HIGH 7.5EPSS 1.11%19 April 2006
CVE-2006-1850Multiple cross-site scripting (XSS) vulnerabilities in xFlow 5.46.11 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) level, (2) position, (3) id, and (4) action parameters to members_only/index.cgi, and the (5) page…EXPLOIT ✓LOW 2.6EPSS 1.77%19 April 2006
CVE-2006-1849Multiple SQL injection vulnerabilities in members_only/index.cgi in xFlow 5.46.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) position and (2) id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.12%19 April 2006
CVE-2006-1839PHP remote file inclusion vulnerability in language.php in PHP Album 0.3.2.3, when register_globals is enabled, allows remote attackers to execute arbitrary code via an FTP URL in the data_dir parameter, which satisfies the file_exists function call.EXPLOIT ✓HIGH 7.5EPSS 5.65%19 April 2006
CVE-2006-1838edit_kategorie.php in Fuju News 1.0 allows remote attackers to bypass authentication by setting the authorized cookie.EXPLOIT ✓HIGH 7.5EPSS 2.80%19 April 2006
CVE-2006-1837SQL injection vulnerability in archiv2.php in Fuju News 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.14%19 April 2006
CVE-2006-1835Cross-site scripting (XSS) vulnerability in yearcal.php in Calendarix allows remote attackers to inject arbitrary web script or HTML via the ycyear parameter.EXPLOIT ✓LOW 2.6EPSS 2.01%19 April 2006
CVE-2006-1834Integer signedness error in Opera before 8.54 allows remote attackers to execute arbitrary code via long values in a stylesheet attribute, which pass a length check.EXPLOIT ✓MEDIUM 5.1EPSS 12.1%19 April 2006
CVE-2006-1832sysinfo.cgi in sysinfo 1.21 allows remote attackers to obtain the installation path via the debugger action.EXPLOIT ✓MEDIUM 5.0EPSS 6.57%19 April 2006
CVE-2006-1831Direct static code injection vulnerability in sysinfo.cgi in sysinfo 1.21 and possibly other versions before 2.25 allows remote attackers to execute arbitrary commands via a leading ; (semicolon) in the name parameter in a systemdoc action, which is…EXPLOIT ✓HIGH 7.5EPSS 8.33%19 April 2006
CVE-2006-1828SQL injection vulnerability in php121language.php in PHP121 1.4 allows remote attackers to execute arbitrary SQL commands and execute arbitrary code via the sess_username variable, as set by the php121un HTTP COOKIE parameter, which is used in multiple…EXPLOIT ✓MEDIUM 5.1EPSS 2.02%19 April 2006
CVE-2006-1825Cross-site scripting (XSS) vulnerability in index.php in phpLinks 2.1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.84%18 April 2006
CVE-2006-1822Cross-site scripting (XSS) vulnerability in search.php in FarsiNews 2.5.3 Pro and earlier allows remote attackers to inject arbitrary web script or HTML via the selected_search_arch parameter.EXPLOIT ✓MEDIUM 5.8EPSS 2.19%18 April 2006
CVE-2006-1821Directory traversal vulnerability in index.php in ModX 0.9.1 allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 6.4EPSS 2.97%18 April 2006
CVE-2006-1820Cross-site scripting (XSS) vulnerability in index.php in ModX 0.9.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.EXPLOIT ✓MEDIUM 5.8EPSS 2.09%18 April 2006
CVE-2006-1808Cross-site scripting (XSS) vulnerability in index.php in Lifetype 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the show parameter in a Template operation.EXPLOIT ✓LOW 2.6EPSS 1.93%18 April 2006
CVE-2006-1805SQL injection vulnerability in member.php in PowerClan 1.14 allows remote attackers to execute arbitrary SQL commands via the memberid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.36%18 April 2006
CVE-2006-1803Cross-site scripting (XSS) vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to inject arbitrary web script or HTML via the sql_query parameter.EXPLOIT ✓MEDIUM 4.3EPSS 2.54%18 April 2006
CVE-2006-1802Cross-site scripting (XSS) vulnerability in index.php in TinyWebGallery 1.3 and 1.4 allows remote attackers to inject arbitrary web script or HTML via the twg_album parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.94%18 April 2006
CVE-2006-1801Cross-site scripting (XSS) vulnerability in planetsearchplus.php in planetSearch+ allows remote attackers to inject arbitrary web script or HTML via the search_exp parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.88%18 April 2006
CVE-2006-1800Directory traversal vulnerability in posts.php in SimpleBBS 1.0.6 through 1.1 allows remote attackers to include and execute arbitrary files via ".." sequences in the language cookie, as demonstrated by by injecting the code into the gl_session cookie…EXPLOIT ✓HIGH 7.5EPSS 2.62%18 April 2006
CVE-2006-1799censtore.cgi in Censtore 7.3.002 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter.EXPLOIT ✓HIGH 7.5EPSS 3.49%18 April 2006
CVE-2006-1794SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via (1) the $username variable in the mosGetParam function and (2) the $task parameter in the mosMenuCheck…EXPLOITHIGH 7.6EPSS 5.53%17 April 2006
CVE-2006-1793Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPath[path] parameter to (1) class.forumposts.php and (2) forumpollrenderer.php.EXPLOIT ✓HIGH 7.6EPSS 3.56%17 April 2006
CVE-2006-0992Stack-based buffer overflow in Novell GroupWise Messenger before 2.0 Public Beta 2 allows remote attackers to execute arbitrary code via a long Accept-Language value without a comma or semicolon.EXPLOIT ✓HIGH 10.0EPSS 72.8%14 April 2006
CVE-2006-1786Cross-site scripting (XSS) vulnerability in Adobe Document Server for Reader Extensions 6.0 allows remote attackers to inject arbitrary web script or HTML via (1) the actionID parameter in ads-readerext and (2) the op parameter in AlterCast.EXPLOIT ×2 ✓LOW 2.6EPSS 11.9%13 April 2006
CVE-2006-1784PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and earlier, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the settings_dir parameter.EXPLOIT ✓MEDIUM 5.1EPSS 7.81%13 April 2006
CVE-2006-1551Eval injection vulnerability in pajax_call_dispatcher.php in PAJAX 0.5.1 and earlier allows remote attackers to execute arbitrary code via the (1) $method and (2) $args parameters.EXPLOIT ✓HIGH 7.5EPSS 50.6%13 April 2006
CVE-2006-1783Cross-site scripting (XSS) vulnerability in PatroNet CMS allows remote attackers to inject arbitrary web script or HTML via the URI.EXPLOIT ✓LOW 2.6EPSS 1.35%13 April 2006
CVE-2006-1781PHP remote file inclusion vulnerability in functions.php in Circle R Monster Top List (MTL) 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 9.59%13 April 2006
CVE-2006-1779Cross-site scripting (XSS) vulnerability in login.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the btag parameter.EXPLOIT ✓MEDIUM 6.8EPSS 5.77%13 April 2006
CVE-2006-1778Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) blogid parameter in (a) index.php and (b) archive.php, the (2) m and (3) y parameters in…EXPLOIT ✓HIGH 7.5EPSS 4.29%13 April 2006
CVE-2006-1777Directory traversal vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the s parameter, as demonstrated by injecting PHP…EXPLOIT ✓HIGH 7.5EPSS 9.77%13 April 2006
CVE-2006-1776PHP remote file inclusion vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the s parameter.EXPLOIT ✓HIGH 7.5EPSS 12.7%13 April 2006
CVE-2006-1773SQL injection vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to execute arbitrary SQL commands via the contentid parameter, possibly involving content/news.php.EXPLOIT ✓MEDIUM 6.4EPSS 1.11%13 April 2006

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.