CWE-506— Embedded Malicious Code
The product contains code that appears to be malicious in nature.— MITRE CWE catalog
105 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-506page 1 of 3
- CVE-2026-8398CRITICALCVSS 9.8EG 9.8⚠ KEV2026-05-15
A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and …
- CVE-2025-59374CRITICALCVSS 9.8EG 9.8⚠ KEV2025-12-17
"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting…
- CVE-2026-45321CRITICALCVSS 9.6EG 9.6⚠ KEV2026-05-12
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher bi…
- CVE-2026-48027CRITICALCVSS 9.3EG 9.3⚠ KEV2026-05-27
Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Market…
- CVE-2026-33634CRITICALCVSS 8.8EG 9.0⚠ KEV2026-03-23
Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and r…
- CVE-2025-30154CRITICALCVSS 8.6EG 9.0⚠ KEV2025-03-19
reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs.…
- CVE-2025-30066CRITICALCVSS 8.6EG 9.0⚠ KEV2025-03-15
tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit…
- CVE-2024-4978CRITICALCVSS 8.4EG 9.0⚠ KEV2024-05-23
Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor may exploit this vulnerability to execute of unauthorized Po…
- CVE-2021-26857CRITICALCVSS 7.8EG 9.0⚠ KEV2021-03-03
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2025-54313CRITICALCVSS 7.5EG 9.0⚠ KEV2025-07-19
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.
- CVE-2026-46412CRITICALCVSS 10.0EG 10.02026-05-19
@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compromised npm publish token to publish 18 malicious …
- CVE-2026-28353CRITICALCVSS 10.0EG 10.02026-03-05
Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. In Trivy VSCode Extension version 1.8.12, which was distributed via OpenVSX marketplace was compromised and contained malicious code designed to leverage l…
- CVE-2024-3094CRITICALCVSS 10.0EG 10.02024-03-29
Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the sou…
- CVE-2026-97230CRITICALCVSS 9.8EG 9.82026-09-24
IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts to retrieve…
- CVE-2026-74232CRITICALCVSS 9.8EG 9.82026-08-27
Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.…
- CVE-2026-77651CRITICALCVSS 9.8EG 9.82026-08-21
The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.
- CVE-2026-77650CRITICALCVSS 9.8EG 9.82026-08-21
The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execu…
- CVE-2026-77649CRITICALCVSS 9.8EG 9.82026-08-21
The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.
- CVE-2026-73532CRITICALCVSS 9.8EG 9.82026-08-13
Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), lo…
- CVE-2026-73533CRITICALCVSS 9.8EG 9.82026-08-13
Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableD…
- CVE-2026-66747CRITICALCVSS 9.8EG 9.82026-08-05
Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boo…
- CVE-2026-18072CRITICALCVSS 9.8EG 9.82026-07-29
The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init…
- CVE-2026-44484CRITICALCVSS 9.8EG 9.82026-05-14
PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent with a credential harvesting mechanism.
- CVE-2026-6443CRITICALCVSS 9.8EG 9.82026-04-17
All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to the plugin being sold to a malicious threat actor that embedded a backdoor in all of the plugin's they acquired. This m…
- CVE-2026-34424CRITICALCVSS 9.8EG 9.82026-04-09
Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers to execute arbitrary code and commands. Attackers …
- CVE-2026-34841CRITICALCVSS 9.8EG 9.82026-04-06
Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack involving compromised versions of the axios npm package, which introduced a hidden dependency deploying a cross-platfor…
- CVE-2026-31976CRITICALCVSS 9.8EG 9.82026-03-11
xygeni-action is the GitHub Action for Xygeni Scanner. On March 3, 2026, an attacker with access to compromised credentials created a series of pull requests (#46, #47, #48) injecting obfuscated shell code into action.yml. The PRs were blo…
- CVE-2017-16128CRITICALCVSS 9.8EG 9.82018-06-07
The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registry.
- CVE-2026-45758CRITICALCVSS 9.6EG 9.62026-05-19
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of `guardrails-ai` (0.10.1) to PyPI. Aany user who installed `guardrails-ai==…
- CVE-2025-10894CRITICALCVSS 9.6EG 9.62025-09-24
Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file syst…
- CVE-2026-48161CRITICALCVSS 9.3EG 9.32026-08-10
react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contained malicious commits 7b79148d1495a2505f9277da295a98cf176f4496 through 7b79148d1495a2505f9277da295a98cf176f4496 that exe…
- CVE-2026-48160CRITICALCVSS 9.3EG 9.32026-08-10
react-tracked provides state usage tracking with Proxies. Between 2026-05-18 19:26:36 and 2026-05-19 15:22:45, the default branch contained malicious commits 6978272a7d6ca02225cb747ea69f427512e33699 through 949f1a3d6bb1ff7d1a0dec892afd773e…
- CVE-2026-48159CRITICALCVSS 9.3EG 9.32026-08-10
use-reducer-async is a React useReducer with async actions. Between 2026-05-18 16:29:52 and 2026-05-19 15:26:07, the default branch contained malicious commits da72edbde5705efcec6c62e0a3dcb73687b78dc8 through df07d5711458d8b46e11dd7afaaa21…
- CVE-2026-48158CRITICALCVSS 9.3EG 9.32026-08-10
use-context-selector is a React useContextSelector hook in userland Between 2026-05-18 15:57:18 and 2026-05-19 15:24:34, the default branch contained malicious commits 9d8481a513b7b0d1c0941b220c69b25de748641b through 6f2dae054ca014068bdbbb…
- CVE-2026-46421CRITICALCVSS 9.3EG 9.32026-05-20
The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that tool. On April 29, 2026, compromised versions of `@cap-js/sqlite@…
- CVE-2018-25117CRITICALCVSS 9.3EG 9.32025-10-15
VestaCP commit a3f0fa1 (2018-05-31) up to commit ee03eff (2018-06-13) contain embedded malicious code that resulted in a supply-chain compromise. New installations created from the compromised installer since at least May 2018 were subject…
- CVE-2017-20203CRITICALCVSS 9.3EG 9.32025-10-09
NetSarang Xmanager Enterprise 5.0 Build 1232, Xmanager 5.0 Build 1045, Xshell 5.0 Build 1322, Xftp 5.0 Build 1218, and Xlpd 5.0 Build 1220 contain a malicious nssock2.dll that implements a multi-stage, DNS-based backdoor. The dormant li…
- CVE-2017-20202CRITICALCVSS 9.3EG 9.32025-10-08
Web Developer for Chrome v0.4.9 contained malicious code that generated a domain via a DGA and fetched a remote script. The fetched script conditionally loaded follow-on modules that performed extensive ad substitution and malvertising, di…
- CVE-2017-20201CRITICALCVSS 9.3EG 9.32025-10-08
CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 (32-bit builds) contained a malicious pre-entry-point loader that diverts execution from __scrt_common_main_seh into a custom loader. That loader decodes an embedded blob into shellcode, al…
- CVE-2025-59039CRITICALCVSS 9.3EG 9.32025-09-09
Prebid Universal Creative (PUC) is a JavaScript API to render multiple formats. Npm users of PUC 1.17.3 or PUC latest were briefly affected by crypto-related malware. This includes the extremely popular jsdelivr hosting of this file. The m…
- CVE-2025-32965CRITICALCVSS 9.3EG 9.32025-04-22
xrpl.js is a JavaScript/TypeScript API for interacting with the XRP Ledger in Node.js and the browser. Versions 4.2.1, 4.2.2, 4.2.3, and 4.2.4 of xrpl.js were compromised and contained malicious code designed to exfiltrate private keys. Ve…
- CVE-2020-15165CRITICALCVSS 9.3EG 9.32020-08-28
Version 1.1.6-free of Chameleon Mini Live Debugger on Google Play Store may have had it's sources or permissions tampered by a malicious actor. The official maintainer of the package is recommending all users upgrade to v1.1.8 as soon as p…
- CVE-2023-2003CRITICALCVSS 9.1EG 9.12023-07-13
Embedded malicious code vulnerability in Vision1210, in the build 5 of operating system version 4.3, which could allow a remote attacker to store base64-encoded malicious code in the device's data tables via the PCOM protocol, which can th…
- CVE-2025-59145HIGHCVSS 8.8EG 8.82025-09-15
color-name is a JSON with CSS color names. On 8 September 2025, an npm publishing account for color-name was taken over after a phishing attack. Version 2.0.1 was published, functionally identical to the previous patch version, but with a …
- CVE-2025-59331HIGHCVSS 8.8EG 8.82025-09-15
is-arrayish checks if an object can be used like an Array. On 8 September 2025, an npm publishing account for is-arrayish was taken over after a phishing attack. Version 0.3.3 was published, functionally identical to the previous patch ver…
- CVE-2025-59330HIGHCVSS 8.8EG 8.82025-09-15
error-ex allows error subclassing and stack customization. On 8 September 2025, an npm publishing account for error-ex was taken over after a phishing attack. Version 1.3.3 was published, functionally identical to the previous patch versio…
- CVE-2025-59162HIGHCVSS 8.8EG 8.82025-09-15
color-convert provides plain color conversion functions in JavaScript. On 8 September 2025, the npm publishing account for color-convert was taken over after a phishing attack. Version 3.1.1 was published, functionally identical to the pre…
- CVE-2025-59144HIGHCVSS 8.8EG 8.82025-09-15
debug is a JavaScript debugging utility. On 8 September 2025, the npm publishing account for debug was taken over after a phishing attack. Version 4.4.2 was published, functionally identical to the previous patch version, but with a malwar…
- CVE-2025-59143HIGHCVSS 8.8EG 8.82025-09-15
color is a Javascript color conversion and manipulation library. On 8 September 2025, the npm publishing account for color was taken over after a phishing attack. Version 5.0.1 was published, functionally identical to the previous patch ve…
- CVE-2025-59142HIGHCVSS 8.8EG 8.82025-09-15
color-string is a parser and generator for CSS color strings. On 8 September 2025, the npm publishing account for color-string was taken over after a phishing attack. Version 2.1.1 was published, functionally identical to the previous patc…
Map vulnerabilities like CWE-506 to your infrastructure
EchelonGraph correlates every CVE — across CWE-506 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →