Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,963 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
17,157 results · page 306 of 344
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-1302 | Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with certain crafted fields in a SELECTION record, which triggers memory corruption, aka "Malformed SELECTION record… | HIGH 9.3EPSS 13.6% | 13 July 2006 |
| CVE-2006-3581 | Multiple stack-based buffer overflows in Audacious AdPlug 2.0 and earlier allow remote user-assisted attackers to execute arbitrary code via large (1) DTM and (2) S3M files. | EXPLOIT ✓MEDIUM 5.1EPSS 13.0% | 13 July 2006 |
| CVE-2006-3545 | Microsoft Internet Explorer 7.0 Beta allows remote attackers to cause a denial of service (application crash) via a web page with multiple empty APPLET start tags. | MEDIUM 5.0EPSS 14.2% | 13 July 2006 |
| CVE-2006-3524 | Buffer overflow in SIPfoundry sipXtapi released before 20060324 allows remote attackers to execute arbitrary code via a long CSeq field value in an INVITE message. | EXPLOIT ×4 ✓HIGH 7.5EPSS 67.5% | 12 July 2006 |
| CVE-2006-3513 | danim.dll in Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (application crash) by accessing the Data property of a DirectAnimation DAUserData object before it is initialized, which triggers a NULL pointer dereference. | EXPLOIT ✓MEDIUM 5.0EPSS 22.7% | 11 July 2006 |
| CVE-2006-3512 | Internet Explorer 6 on Windows XP allows remote attackers to cause a denial of service (crash) by setting the Enabled property of a DXTFilter ActiveX object to true, which triggers a null dereference. | EXPLOIT ✓MEDIUM 5.0EPSS 24.3% | 11 July 2006 |
| CVE-2006-3511 | Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by setting the fonts property of the HtmlDlgSafeHelper object, which triggers a null dereference. | EXPLOIT ✓MEDIUM 5.0EPSS 21.6% | 11 July 2006 |
| CVE-2006-3510 | The Remote Data Service Object (RDS.DataControl) in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (crash) via a series of operations that result in an invalid length calculation when using… | EXPLOIT ✓LOW 2.6EPSS 14.8% | 11 July 2006 |
| CVE-2006-0026 | Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP). | EXPLOIT ✓MEDIUM 6.5EPSS 89.3% | 11 July 2006 |
| CVE-2006-2389 | Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with a malformed property that triggers memory corruption… | EXPLOIT ✓HIGH 9.3EPSS 38.7% | 11 July 2006 |
| CVE-2006-2372 | Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a crafted DHCP response. | EXPLOIT ✓HIGH 10.0EPSS 90.2% | 11 July 2006 |
| CVE-2006-1316 | Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with malformed string that triggers memory corruption related… | HIGH 9.3EPSS 15.2% | 11 July 2006 |
| CVE-2006-1315 | The Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to obtain sensitive information via crafted requests that leak information in SMB buffers, which are… | EXPLOIT ✓MEDIUM 5.0EPSS 48.8% | 11 July 2006 |
| CVE-2006-1314 | Heap-based buffer overflow in the Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to execute arbitrary code via crafted first-class Mailslot messages that… | EXPLOIT ✓HIGH 7.5EPSS 61.2% | 11 July 2006 |
| CVE-2006-1300 | Microsoft .NET framework 2.0 (ASP.NET) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to bypass access restrictions via unspecified "URL paths" that can access Application Folder objects "explicitly by… | MEDIUM 5.0EPSS 36.9% | 11 July 2006 |
| CVE-2006-0033 | Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted PNG image that triggers memory corruption when it is parsed. | HIGH 9.3EPSS 15.2% | 11 July 2006 |
| CVE-2006-0007 | Buffer overflow in GIFIMP32.FLT, as used in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted GIF image that triggers memory corruption when it… | HIGH 9.3EPSS 19.4% | 11 July 2006 |
| CVE-2006-3493 | Buffer overflow in LsCreateLine function (mso_203) in mso.dll and mso9.dll, as used by Microsoft Word and possibly other products in Microsoft Office 2003, 2002, and 2000, allows remote user-assisted attackers to cause a denial of service (crash) via a… | EXPLOIT ✓MEDIUM 5.1EPSS 40.4% | 10 July 2006 |
| CVE-2006-3472 | Microsoft Internet Explorer 6.0 and 6.0 SP1 allows remote attackers to cause a denial of service via an HTML page with an A tag containing a long title attribute. | EXPLOIT ✓MEDIUM 5.0EPSS 10.6% | 10 July 2006 |
| CVE-2006-3471 | Microsoft Internet Explorer 6 on Windows XP allows remote attackers to cause a denial of service (crash) via a table with a frameset as a child, which triggers a null dereference, as demonstrated using the appendChild method. | EXPLOIT ✓MEDIUM 5.0EPSS 20.8% | 10 July 2006 |
| CVE-2006-3431 | Buffer overflow in certain Asian language versions of Microsoft Excel might allow user-assisted attackers to execute arbitrary code via a crafted STYLE record in a spreadsheet that triggers the overflow when the user attempts to repair the document or… | EXPLOIT ✓HIGH 7.5EPSS 28.3% | 7 July 2006 |
| CVE-2006-3427 | Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by declaring the sourceURL attribute on an uninitialized DirectAnimation.StructuredGraphicsControl ActiveX Object, which triggers a null dereference. | EXPLOIT ✓MEDIUM 5.0EPSS 24.3% | 7 July 2006 |
| CVE-2006-3392 | Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes… | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 78.3% | 6 July 2006 |
| CVE-2006-3357 | Heap-based buffer overflow in HTML Help ActiveX control (hhctrl.ocx) in Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code by repeatedly setting the Image field of… | HIGH 7.5EPSS 35.3% | 6 July 2006 |
| CVE-2006-3354 | Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Filter property of an ADODB.Recordset ActiveX object to certain values multiple times, which triggers a null dereference. | EXPLOIT ✓MEDIUM 5.0EPSS 17.1% | 6 July 2006 |
| CVE-2006-3340 | Multiple PHP remote file inclusion vulnerabilities in Pearl For Mambo module 1.6 for Mambo, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via the (1) phpbb_root_path parameter in (a) includes/functions_cms.php… | EXPLOIT ✓MEDIUM 5.1EPSS 15.6% | 3 July 2006 |
| CVE-2006-3317 | PHP remote file inclusion vulnerability in phpRaid 3.0.6 allows remote attackers to execute arbitrary code via a URL in the phpraid_dir parameter to (1) announcements.php and (2) rss.php, a different set of vectors and affected versions than… | EXPLOIT ✓MEDIUM 5.1EPSS 17.1% | 29 June 2006 |
| CVE-2006-3281 | Microsoft Internet Explorer 6.0 does not properly handle Drag and Drop events, which allows remote user-assisted attackers to execute arbitrary code via a link to an SMB file share with a filename that contains encoded ..\ (%2e%2e%5c) sequences and… | EXPLOIT ✓MEDIUM 5.1EPSS 48.2% | 28 June 2006 |
| CVE-2006-3280 | Cross-domain vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a… | EXPLOIT ✓HIGH 7.5EPSS 55.9% | 28 June 2006 |
| CVE-2006-3276 | Heap-based buffer overflow in RealNetworks Helix DNA Server 10.0 and 11.0 allows remote attackers to execute arbitrary code via (1) a long User-Agent HTTP header in the RTSP service and (2) unspecified vectors involving the "parsing of HTTP URL schemes". | HIGH 7.5EPSS 13.9% | 28 June 2006 |
| CVE-2006-3266 | Multiple PHP remote file inclusion vulnerabilities in Bee-hive Lite 1.2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) header parameter to (a) conad/include/rootGui.inc.php and… | EXPLOIT ✓MEDIUM 5.1EPSS 18.0% | 27 June 2006 |
| CVE-2006-3252 | Buffer overflow in the Online Registration Facility for Algorithmic Research PrivateWire VPN software up to 3.7 allows remote attackers to execute arbitrary code via a long GET request. | EXPLOIT ×2 ✓HIGH 7.5EPSS 62.2% | 27 June 2006 |
| CVE-2006-3134 | Buffer overflow in GraceNote CDDBControl ActiveX Control, as used by multiple products that use Gracenote CDDB, allows remote attackers to execute arbitrary code via a long option string. | HIGH 9.3EPSS 11.2% | 27 June 2006 |
| CVE-2006-3228 | Buffer overflow in in_midi.dll for WinAmp 2.90 up to 5.23, including 5.21, allows remote attackers to execute arbitrary code via a crafted .mid (MIDI) file. | EXPLOIT ✓HIGH 9.3EPSS 11.7% | 26 June 2006 |
| CVE-2006-3227 | Interpretation conflict between Internet Explorer and other web browsers such as Mozilla, Opera, and Firefox might allow remote attackers to modify the visual presentation of web pages and possibly bypass protection mechanisms such as content filters… | LOW 2.6EPSS 13.5% | 26 June 2006 |
| CVE-2006-3210 | Ralf Image Gallery (RIG) 0.7.4 and other versions before 1.0, when register_globals is enabled, allows remote attackers to conduct PHP remote file inclusion and directory traversal attacks via URLs or ".." sequences in the (1) dir_abs_src parameter in… | EXPLOIT ✓MEDIUM 5.1EPSS 13.5% | 24 June 2006 |
| CVE-2006-3200 | Unspecified versions of Internet Explorer allow remote attackers to cause a denial of service (crash) via an IFRAME with a src tag containing a "File://" URI followed by an 8-bit character. | MEDIUM 5.0EPSS 15.7% | 23 June 2006 |
| CVE-2006-3199 | Opera 9 allows remote attackers to cause a denial of service (crash) via an A tag with an href attribute with a URL containing a long hostname, which triggers an out-of-bounds operation. | EXPLOIT ✓MEDIUM 5.0EPSS 14.6% | 23 June 2006 |
| CVE-2006-2914 | PHP remote file inclusion vulnerability in DeluxeBB 1.06 allows remote attackers to execute arbitrary code via a URL in the templatefolder parameter to (1) postreply.php, (2) posting.php, (3) and pm/newpm.php in the deluxe/ directory, and (4)… | EXPLOIT ✓MEDIUM 5.1EPSS 20.7% | 23 June 2006 |
| CVE-2006-3193 | Multiple PHP remote file inclusion vulnerabilities in Grayscale BandSite CMS 1.1.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) includes/content/contact_content.php;… | EXPLOIT ✓MEDIUM 5.1EPSS 14.8% | 23 June 2006 |
| CVE-2006-3172 | Multiple PHP remote file inclusion vulnerabilities in Content*Builder 0.7.5 allow remote attackers to execute arbitrary PHP code via a URL with a trailing slash (/) character in the (1) lang_path parameter to (a) cms/plugins/col_man/column.inc.php, (b)… | EXPLOIT ✓HIGH 7.5EPSS 15.6% | 23 June 2006 |
| CVE-2006-3014 | Microsoft Excel allows user-assisted attackers to execute arbitrary javascript and redirect users to arbitrary sites via an Excel spreadsheet with an embedded Shockwave Flash Player ActiveX Object, which is automatically executed when the user opens the… | EXPLOIT ✓MEDIUM 5.1EPSS 30.1% | 22 June 2006 |
| CVE-2006-3109 | Cross-site scripting (XSS) vulnerability in Cisco CallManager 3.3 before 3.3(5)SR3, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3), and 4.3 before 4.3(1), allows remote attackers to inject arbitrary web script or HTML via the (1) pattern parameter in… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 13.7% | 21 June 2006 |
| CVE-2006-3101 | Cross-site scripting (XSS) vulnerability in LogonProxy.cgi in Cisco Secure ACS for UNIX 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) error, (2) SSL, and (3) Ok parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 24.0% | 21 June 2006 |
| CVE-2006-3086 | Stack-based buffer overflow in the HrShellOpenWithMonikerDisplayName function in Microsoft Hyperlink Object Library (hlink.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long hyperlink, as… | EXPLOIT ✓HIGH 9.3EPSS 56.5% | 19 June 2006 |
| CVE-2006-3081 | mysqld in MySQL 4.1.x before 4.1.18, 5.0.x before 5.0.19, and 5.1.x before 5.1.6 allows remote authorized users to cause a denial of service (crash) via a NULL second argument to the str_to_date function. | EXPLOIT ✓MEDIUM 4.0EPSS 25.8% | 19 June 2006 |
| CVE-2006-3059 | Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors. | EXPLOIT ✓HIGH 9.3EPSS 41.1% | 17 June 2006 |
| CVE-2006-2385 | Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted web page that triggers memory corruption when it is saved as a multipart HTML (.mht)… | HIGH 7.6EPSS 20.1% | 13 June 2006 |
| CVE-2006-2384 | Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to conduct spoofing and phishing attacks by using a modal browser window in a way that preserves the original address bar and trusted UI of a trusted site, even after the… | MEDIUM 4.3EPSS 19.2% | 13 June 2006 |
| CVE-2006-2383 | Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via "unexpected data" related to "parameter validation" in the DXImageTransform.Microsoft.Light ActiveX control,… | EXPLOIT ✓HIGH 9.3EPSS 40.3% | 13 June 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.