Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,963 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
17,157 results · page 310 of 344
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-0705 | Format string vulnerability in a logging function as used by various SFTP servers, including (1) AttachmateWRQ Reflection for Secure IT UNIX Server before 6.0.0.9, (2) Reflection for Secure IT Windows Server before 6.0 build 38, (3) F-Secure SSH Server… | MEDIUM 6.5EPSS 10.2% | 15 February 2006 |
| CVE-2006-0006 | Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code… | EXPLOIT ×2 ✓HIGH 9.3EPSS 49.6% | 14 February 2006 |
| CVE-2006-0004 | Microsoft PowerPoint 2000 in Office 2000 SP3 has an interaction with Internet Explorer that allows remote attackers to obtain sensitive information via a PowerPoint presentation that attempts to access objects in the Temporary Internet Files Folder… | MEDIUM 5.0EPSS 31.5% | 14 February 2006 |
| CVE-2006-0021 | Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via an IGMP packet with an invalid IP option, aka the "IGMP v3 DoS Vulnerability." | EXPLOIT ×2 ✓HIGH 7.8EPSS 62.9% | 14 February 2006 |
| CVE-2006-0013 | Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than… | MEDIUM 6.5EPSS 34.9% | 14 February 2006 |
| CVE-2006-0005 | Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML… | EXPLOIT ×3 ✓HIGH 9.3EPSS 38.7% | 14 February 2006 |
| CVE-2006-0585 | jscript.dll in Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (application crash) via a Shockwave Flash object that contains ActionScript code that calls VBScript, which in turn calls the Javascript… | MEDIUM 5.0EPSS 15.2% | 8 February 2006 |
| CVE-2006-0564 | Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included in the Microsoft HTML Help 1.4 SDK, allows context-dependent attackers to execute arbitrary code via a .hhp file with a long Contents… | EXPLOIT ×8 ✓HIGH 7.5EPSS 71.7% | 6 February 2006 |
| CVE-2006-0544 | urlmon.dll in Microsoft Internet Explorer 7.0 beta 2 (aka 7.0.5296.0) allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a BGSOUND element with its SRC attribute set to "file://" followed by… | EXPLOIT ✓HIGH 7.5EPSS 21.7% | 4 February 2006 |
| CVE-2006-0537 | Buffer overflow in the POP3 server in Kinesphere Corporation eXchange before 5.0.060125 allows remote attackers to execute arbitrary code via a long RCPT TO argument. | EXPLOIT ✓HIGH 7.5EPSS 41.5% | 4 February 2006 |
| CVE-2006-0295 | Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory… | EXPLOIT ×3 ✓MEDIUM 5.1EPSS 71.3% | 2 February 2006 |
| CVE-2006-0528 | The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attached text file that contains "Content-Disposition: inline" in the header, and… | EXPLOIT ✓MEDIUM 5.0EPSS 11.0% | 2 February 2006 |
| CVE-2006-0476 | Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with a long file name (File1 field). | EXPLOIT ×4 ✓HIGH 7.6EPSS 75.0% | 31 January 2006 |
| CVE-2006-0468 | CommuniGate Pro Core Server before 5.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via LDAP messages with negative BER lengths, and possibly other vectors, as demonstrated by the ProtoVer LDAP test… | EXPLOIT ✓HIGH 7.5EPSS 10.5% | 30 January 2006 |
| CVE-2006-0057 | Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to bypass the Kill bit settings for dangerous ActiveX controls via unknown vectors involving crafted HTML, which can expose the browser to attacks that would otherwise be prevented by… | HIGH 7.5EPSS 19.6% | 27 January 2006 |
| CVE-2006-0441 | Stack-based buffer overflow in Sami FTP Server 2.0.1 allows remote attackers to execute arbitrary code via a long USER command, which triggers the overflow when the log is viewed. | EXPLOIT ×7 ✓HIGH 7.5EPSS 71.5% | 26 January 2006 |
| CVE-2006-0376 | The 802.11 wireless client in certain operating systems including Windows 2000, Windows XP, and Windows Server 2003 does not warn the user when (1) it establishes an association with a station in ad hoc (aka peer-to-peer) mode or (2) a station in ad hoc… | HIGH 7.5EPSS 18.2% | 22 January 2006 |
| CVE-2006-0354 | Cisco IOS before 12.3-7-JA2 on Aironet Wireless Access Points (WAP) allows remote authenticated users to cause a denial of service (termination of packet passing or termination of client connections) by sending the management interface a large number of… | EXPLOIT ✓MEDIUM 5.5EPSS 10.5% | 22 January 2006 |
| CVE-2006-0316 | Buffer overflow in YGPPicFinder.DLL in AOL You've Got Pictures (YGP) Picture Finder Tool ActiveX Control, as used in AOL 8.0, 8.0 Plus, and 9.0 Classic, allows remote attackers to execute arbitrary code via unspecified vectors. | HIGH 10.0EPSS 10.5% | 19 January 2006 |
| CVE-2006-0306 | The DM Primer (dmprimer.exe) in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Backup for Laptops & Desktops r11.0, r11.1, r11.1 SP1, Unicenter Remote Control 6.0, 6.0 SP1, CA Desktop… | EXPLOIT ✓MEDIUM 5.0EPSS 12.5% | 19 January 2006 |
| CVE-2006-0289 | Multiple unspecified vulnerabilities in Oracle Application Server 6.0.8.26(PS17) and E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) REP05 and (2) REP06 in the Oracle Reports… | HIGH 10.0EPSS 13.0% | 18 January 2006 |
| CVE-2006-0287 | Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 10.1.0.5 and Application Server 10.1.2.0.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# OHS02. | EXPLOIT ✓HIGH 10.0EPSS 29.0% | 18 January 2006 |
| CVE-2006-0254 | Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) time parameter to cal2.jsp and (2) any invalid parameter, which causes an XSS when the log file is… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 32.2% | 18 January 2006 |
| CVE-2006-0200 | Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute arbitrary code via format string specifiers in MySQL error messages. | HIGH 9.3EPSS 20.0% | 13 January 2006 |
| CVE-2006-0189 | Buffer overflow in eStara Softphone 3.0.1.14 through 3.0.1.46 allows remote attackers to execute arbitrary code via a long attribute (aka "a") field in the SDP data of a SIP packet on UDP port 5060. | EXPLOIT ×2 ✓HIGH 7.5EPSS 15.9% | 13 January 2006 |
| CVE-2006-0187 | By design, Microsoft Visual Studio 2005 automatically executes code in the Load event of a user-defined control (UserControl1_Load function), which allows user-assisted attackers to execute arbitrary code by tricking the user into opening a malicious… | EXPLOIT ×2 ✓MEDIUM 5.1EPSS 19.1% | 12 January 2006 |
| CVE-2006-0179 | The Cisco IP Phone 7940 allows remote attackers to cause a denial of service (reboot) via a large amount of TCP SYN packets (syn flood) to arbitrary ports, as demonstrated to port 80. | EXPLOIT ✓MEDIUM 5.0EPSS 13.6% | 11 January 2006 |
| CVE-2006-0010 | Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded… | HIGH 9.3EPSS 33.1% | 10 January 2006 |
| CVE-2006-0002 | Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation… | HIGH 7.5EPSS 45.6% | 10 January 2006 |
| CVE-2006-0020 | An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code… | HIGH 9.3EPSS 19.1% | 10 January 2006 |
| CVE-2006-0162 | Heap-based buffer overflow in libclamav/upx.c in Clam Antivirus (ClamAV) before 0.88 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted UPX files. | HIGH 7.5EPSS 10.1% | 10 January 2006 |
| CVE-2006-0147 | Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PhpOpenChat, possibly (7) MAXdev MD-Pro, and (8)… | EXPLOIT ✓HIGH 7.5EPSS 13.1% | 9 January 2006 |
| CVE-2006-0146 | The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty,… | EXPLOIT ✓HIGH 7.5EPSS 13.2% | 9 January 2006 |
| CVE-2006-0143 | Microsoft Windows Graphics Rendering Engine (GRE) allows remote attackers to corrupt memory and cause a denial of service (crash) via a WMF file containing (1) ExtCreateRegion or (2) ExtEscape function calls with arguments with inconsistent lengths. | EXPLOIT ✓HIGH 7.5EPSS 31.3% | 9 January 2006 |
| CVE-2006-0097 | Stack-based buffer overflow in the create_named_pipe function in libmysql.c in PHP 4.3.10 and 4.4.x before 4.4.3 for Windows allows attackers to execute arbitrary code via a long (1) arg_host or (2) arg_unix_socket argument, as demonstrated by a long… | EXPLOIT ✓HIGH 7.5EPSS 12.2% | 6 January 2006 |
| CVE-2005-4844 | The CLSID_ApprenticeICW control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer. | HIGH 7.1EPSS 12.4% | 31 December 2005 |
| CVE-2005-4843 | The SmartConnect Class control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer. | HIGH 7.8EPSS 11.2% | 31 December 2005 |
| CVE-2005-4840 | The Outlook Express Address Book control, when using Internet Explorer 6, allows remote attackers to cause a denial of service (NULL dereference and browser crash) by creating the OutlookExpress.AddressBook COM object, which is not intended for use… | MEDIUM 4.3EPSS 11.5% | 31 December 2005 |
| CVE-2005-4832 | SQL injection vulnerability in the Oracle Database Server 10g allows remote authenticated users to execute arbitrary SQL commands with elevated privileges via the SUBSCRIPTION_NAME parameter in the (1) SYS.DBMS_CDC_SUBSCRIBE and (2)… | EXPLOIT ×4 ✓HIGH 7.5EPSS 41.7% | 31 December 2005 |
| CVE-2005-4827 | Internet Explorer 6.0, and possibly other versions, allows remote attackers to bypass the same origin security policy and make requests outside of the intended domain by calling open on an XMLHttpRequest object (Microsoft.XMLHTTP) and using tab,… | HIGH 7.5EPSS 11.2% | 31 December 2005 |
| CVE-2005-4823 | Buffer overflow in the HP HTTP Server 5.0 through 5.95 of the HP Web-enabled Management Software allows remote attackers to execute arbitrary code via unknown vectors. | HIGH 10.0EPSS 12.6% | 31 December 2005 |
| CVE-2005-4816 | Buffer overflow in mod_radius in ProFTPD before 1.3.0rc2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password. | HIGH 7.5EPSS 12.8% | 31 December 2005 |
| CVE-2005-4810 | Microsoft Internet Explorer 7.0 Beta3 and earlier allows remote attackers to cause a denial of service (crash) via a "text/html" HTML Content-type header sent in response to an XMLHttpRequest (AJAX). | MEDIUM 5.0EPSS 14.1% | 31 December 2005 |
| CVE-2005-4807 | Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050721 allows attackers to execute arbitrary code via a .c file with crafted inline assembly code. | EXPLOIT ✓HIGH 7.5EPSS 12.1% | 31 December 2005 |
| CVE-2005-4797 | Directory traversal vulnerability in printd line printer daemon (lpd) in Solaris 7 through 10 allows remote attackers to delete arbitrary files via ".." sequences in an "Unlink data file" command. | MEDIUM 5.0EPSS 29.2% | 31 December 2005 |
| CVE-2005-4734 | Stack-based buffer overflow in IISWebAgentIF.dll in RSA Authentication Agent for Web (aka SecurID Web Agent) 5.2 and 5.3 for IIS allows remote attackers to execute arbitrary code via a long url parameter in the Redirect method. | EXPLOIT ✓MEDIUM 6.4EPSS 55.3% | 31 December 2005 |
| CVE-2005-4718 | Opera 8.02 and earlier allows remote attackers to cause a denial of service (client crash) via (1) a crafted HTML file with a "content: url(0);" style attribute, a "bodyA" tag, a long string, and a "u" tag with a long attribute, as demonstrated by… | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 10.2% | 31 December 2005 |
| CVE-2005-4717 | Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP SP2, and Windows Server 2003 SP1 allows remote attackers to cause a denial of service (client crash) via a certain combination of a malformed HTML file… | EXPLOIT ✓MEDIUM 5.0EPSS 16.3% | 31 December 2005 |
| CVE-2005-4703 | Apache Tomcat 4.0.3, when running on Windows, allows remote attackers to obtain sensitive information via a request for a file that contains an MS-DOS device name such as lpt9, which leaks the pathname in an error message, as demonstrated by lpt9.xtp… | EXPLOIT ✓MEDIUM 5.0EPSS 25.7% | 31 December 2005 |
| CVE-2005-4593 | PHP remote file inclusion vulnerability in phpDocumentor 1.3.0 rc4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary code via a URL in the (1) FORUM[LIB] parameter in Documentation/tests/bug-559668.php and (2)… | EXPLOIT ✓HIGH 7.5EPSS 14.1% | 31 December 2005 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.