2006 CVE Vulnerabilities
7,145 CVEs published in 2006.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2006-2726 | — | — | 19.2% | Jun 1, 2006 | PHP remote file inclusion vulnerability in Fastpublish CMS 1.6.9.d allows remote attackers to include arbitrary files vi... |
| CVE-2006-2725 | — | — | 1.7% | Jun 1, 2006 | SQL injection vulnerability in rss/posts.php in Eggblog before 3.07 allows remote attackers to execute arbitrary SQL com... |
| CVE-2006-2721 | — | — | 1.1% | Jun 1, 2006 | Cross-site scripting (XSS) vulnerability in news.php in VARIOMAT allows remote attackers to inject arbitrary HTML or web... |
| CVE-2006-2720 | — | — | 1.2% | Jun 1, 2006 | SQL injection vulnerability in news.php in VARIOMAT allows remote attackers to execute arbitrary SQL commands via the su... |
| CVE-2006-2723 | — | — | 2.9% | Jun 1, 2006 | Unspecified versions of Mozilla Firefox allow remote attackers to cause a denial of service (crash) via a web page that ... |
| CVE-2006-2724 | — | — | 1.3% | Jun 1, 2006 | Cross-site scripting (XSS) vulnerability in PunBB 1.2.11 allows remote authenticated administrators to inject arbitrary ... |
| CVE-2006-2718 | — | — | 1.5% | Jun 1, 2006 | JIWA Financials 6.4.14 passes a Microsoft SQL Server account's username and password, and the name of a data source, to ... |
| CVE-2006-2722 | — | — | 1.1% | Jun 1, 2006 | SQL injection vulnerability in view_album.php in SelectaPix 1.4 allows remote attackers to execute arbitrary SQL command... |
| CVE-2006-2719 | — | — | 0.5% | Jun 1, 2006 | JIWA Financials 6.4.14 stores usernames and passwords for all accounts in cleartext in the HR_Staff table in Microsoft S... |
| CVE-2006-2711 | — | — | 1.9% | May 31, 2006 | Secure Elements Class 5 AVR (aka C5 EVM) 2.8.1 and earlier, and possibly later 2.8.x releases, uses the same initializat... |
| CVE-2006-2709 | — | — | 3.6% | May 31, 2006 | Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 do not validate the source address of a message, which allows remo... |
| CVE-2006-2708 | — | — | 2.3% | May 31, 2006 | Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 allows remote attackers to read portions of process memory ... |
| CVE-2006-2707 | — | — | 1.1% | May 31, 2006 | Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 does not validate the peer certificate when obtaining an up... |
| CVE-2006-2706 | — | — | 2.1% | May 31, 2006 | Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 allows remote attackers to cause a denial of service via fo... |
| CVE-2006-2705 | — | — | 2.1% | May 31, 2006 | Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 allows remote attackers to cause an unspecified denial of s... |
| CVE-2006-2704 | — | — | 2.1% | May 31, 2006 | Secure Elements Class 5 AVR server and client (aka C5 EVM) before 2.8.1 send messages in cleartext, which allows remote ... |
| CVE-2006-2717 | — | — | 1.8% | May 31, 2006 | Unspecified vulnerability in Secure Elements Class 5 AVR client and server (aka C5 EVM) before 2.8.1 allows authenticate... |
| CVE-2006-2716 | — | — | 2.1% | May 31, 2006 | Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 uses a hard-coded user ID and password, which allows remote... |
| CVE-2006-2715 | — | — | 2.1% | May 31, 2006 | The Administration Console in Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 does not enforce access control, whi... |
| CVE-2006-2714 | — | — | 1.8% | May 31, 2006 | Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 does not validate the CEID of an incoming message, which al... |
| CVE-2006-2713 | — | — | 1.9% | May 31, 2006 | Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 generates predictable CEIDs, which allows remote attackers ... |
| CVE-2006-2712 | — | — | 2.6% | May 31, 2006 | Secure Elements Class 5 AVR (aka C5 EVM) client and server before 2.8.1 do not verify the integrity of a message digest,... |
| CVE-2006-2710 | — | — | 1.9% | May 31, 2006 | Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 uses the same invariant RSA key for all installations, which allow... |
| CVE-2006-1515 | — | — | 3.6% | May 31, 2006 | Buffer overflow in the addnewword function in typespeed 0.4.4 and earlier might allow remote attackers to execute arbitr... |
| CVE-2006-2687 | — | — | 1.1% | May 31, 2006 | Cross-site scripting (XSS) vulnerability in adduser.php in PHP-AGTC Membership System 1.1a and earlier allows remote att... |
Check if your code is affected by 2006 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now