CWE-506— Embedded Malicious Code
The product contains code that appears to be malicious in nature.— MITRE CWE catalog
102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-506page 2 of 3
- CVE-2021-22884HIGHCVSS 7.5EG 7.62021-03-03
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via…
- CVE-2021-22887LOWCVSS 2.3EG 2.32021-03-16
A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. Before an attacker can c…
- CVE-2021-26857CRITICALCVSS 7.8EG 9.0⚠ KEV2021-03-03
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2023-2003CRITICALCVSS 9.1EG 9.12023-07-13
Embedded malicious code vulnerability in Vision1210, in the build 5 of operating system version 4.3, which could allow a remote attacker to store base64-encoded malicious code in the device's data tables via the PCOM protocol, which can th…
- CVE-2024-10938MEDIUMCVSS 6.5EG 6.52026-02-27
The OVRI Payment plugin for WordPress contains malicious .htaccess files in version 1.7.0. The files contain directives to prevent the execution of certain scripts while allowing execution of known malicious PHP files. If moved outside of …
- CVE-2024-3094CRITICALCVSS 10.0EG 10.02024-03-29
Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the sou…
- CVE-2024-4978CRITICALCVSS 8.4EG 9.0⚠ KEV2024-05-23
Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor may exploit this vulnerability to execute of unauthorized Po…
- CVE-2025-10894CRITICALCVSS 9.6EG 9.62025-09-24
Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file syst…
- CVE-2025-30066CRITICALCVSS 8.6EG 9.0⚠ KEV2025-03-15
tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit…
- CVE-2025-30154CRITICALCVSS 8.6EG 9.0⚠ KEV2025-03-19
reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs.…
- CVE-2025-32965CRITICALCVSS 9.3EG 9.32025-04-22
xrpl.js is a JavaScript/TypeScript API for interacting with the XRP Ledger in Node.js and the browser. Versions 4.2.1, 4.2.2, 4.2.3, and 4.2.4 of xrpl.js were compromised and contained malicious code designed to exfiltrate private keys. Ve…
- CVE-2025-54313CRITICALCVSS 7.5EG 9.0⚠ KEV2025-07-19
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.
- CVE-2025-55556MEDIUMCVSS 6.5EG 6.52025-09-25
TensorFlow v2.18.0 was discovered to output random results when compiling Embedding, leading to unexpected behavior in the application.
- CVE-2025-59037HIGHCVSS 8.6EG 8.62025-09-09
DuckDB is an analytical in-process SQL database management system. On 08 September 2025, the DuckDB distribution for Node.js on npm was compromised with malware (along with several other packages). An attacker published new versions of fou…
- CVE-2025-59038HIGHCVSS 8.6EG 8.62025-09-09
Prebid.js is a free and open source library for publishers to quickly implement header bidding. NPM users of prebid 10.9.2 may have been briefly compromised by a malware campaign. The malicious code attempts to redirect crypto transactions…
- CVE-2025-59039CRITICALCVSS 9.3EG 9.32025-09-09
Prebid Universal Creative (PUC) is a JavaScript API to render multiple formats. Npm users of PUC 1.17.3 or PUC latest were briefly affected by crypto-related malware. This includes the extremely popular jsdelivr hosting of this file. The m…
- CVE-2025-59140HIGHCVSS 8.8EG 8.82025-09-15
backlash parses collected strings with escapes. On 8 September 2025, the npm publishing account for backslash was taken over after a phishing attack. Version 0.2.1 was published, functionally identical to the previous patch version, but wi…
- CVE-2025-59141HIGHCVSS 8.8EG 8.82025-09-15
simple-swizzle swizzles function arguments. On 8 September 2025, the npm publishing account for simple-swizzle was taken over after a phishing attack. Version 0.2.3 was published, functionally identical to the previous patch version, but w…
- CVE-2025-59142HIGHCVSS 8.8EG 8.82025-09-15
color-string is a parser and generator for CSS color strings. On 8 September 2025, the npm publishing account for color-string was taken over after a phishing attack. Version 2.1.1 was published, functionally identical to the previous patc…
- CVE-2025-59143HIGHCVSS 8.8EG 8.82025-09-15
color is a Javascript color conversion and manipulation library. On 8 September 2025, the npm publishing account for color was taken over after a phishing attack. Version 5.0.1 was published, functionally identical to the previous patch ve…
- CVE-2025-59144HIGHCVSS 8.8EG 8.82025-09-15
debug is a JavaScript debugging utility. On 8 September 2025, the npm publishing account for debug was taken over after a phishing attack. Version 4.4.2 was published, functionally identical to the previous patch version, but with a malwar…
- CVE-2025-59145HIGHCVSS 8.8EG 8.82025-09-15
color-name is a JSON with CSS color names. On 8 September 2025, an npm publishing account for color-name was taken over after a phishing attack. Version 2.0.1 was published, functionally identical to the previous patch version, but with a …
- CVE-2025-59162HIGHCVSS 8.8EG 8.82025-09-15
color-convert provides plain color conversion functions in JavaScript. On 8 September 2025, the npm publishing account for color-convert was taken over after a phishing attack. Version 3.1.1 was published, functionally identical to the pre…
- CVE-2025-59330HIGHCVSS 8.8EG 8.82025-09-15
error-ex allows error subclassing and stack customization. On 8 September 2025, an npm publishing account for error-ex was taken over after a phishing attack. Version 1.3.3 was published, functionally identical to the previous patch versio…
- CVE-2025-59331HIGHCVSS 8.8EG 8.82025-09-15
is-arrayish checks if an object can be used like an Array. On 8 September 2025, an npm publishing account for is-arrayish was taken over after a phishing attack. Version 0.3.3 was published, functionally identical to the previous patch ver…
- CVE-2025-59374CRITICALCVSS 9.8EG 9.8⚠ KEV2025-12-17
"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting…
- CVE-2025-8217MEDIUMCVSS 4.0EG 4.02025-07-30
The Amazon Q Developer Visual Studio Code (VS Code) extension v1.84.0 contains inert, injected code designed to call the Q Developer CLI. The code executes when the extension is launched within the VS Code environment; however the injected…
- CVE-2026-18072CRITICALCVSS 9.8EG 9.82026-07-29
The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init…
- CVE-2026-28353CRITICALCVSS 10.0EG 10.02026-03-05
Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. In Trivy VSCode Extension version 1.8.12, which was distributed via OpenVSX marketplace was compromised and contained malicious code designed to leverage l…
- CVE-2026-31976CRITICALCVSS 9.8EG 9.82026-03-11
xygeni-action is the GitHub Action for Xygeni Scanner. On March 3, 2026, an attacker with access to compromised credentials created a series of pull requests (#46, #47, #48) injecting obfuscated shell code into action.yml. The PRs were blo…
- CVE-2026-33634CRITICALCVSS 8.8EG 9.0⚠ KEV2026-03-23
Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and r…
- CVE-2026-34424CRITICALCVSS 9.8EG 9.82026-04-09
Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers to execute arbitrary code and commands. Attackers …
- CVE-2026-34841CRITICALCVSS 9.8EG 9.82026-04-06
Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack involving compromised versions of the axios npm package, which introduced a hidden dependency deploying a cross-platfor…
- CVE-2026-44484CRITICALCVSS 9.8EG 9.82026-05-14
PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent with a credential harvesting mechanism.
- CVE-2026-45321CRITICALCVSS 9.6EG 9.6⚠ KEV2026-05-12
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher bi…
- CVE-2026-45758CRITICALCVSS 9.6EG 9.62026-05-19
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of `guardrails-ai` (0.10.1) to PyPI. Aany user who installed `guardrails-ai==…
- CVE-2026-46412CRITICALCVSS 10.0EG 10.02026-05-19
@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compromised npm publish token to publish 18 malicious …
- CVE-2026-46421CRITICALCVSS 9.3EG 9.32026-05-20
The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that tool. On April 29, 2026, compromised versions of `@cap-js/sqlite@…
- CVE-2026-48027CRITICALCVSS 9.3EG 9.3⚠ KEV2026-05-27
Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Market…
- CVE-2026-48158CRITICALCVSS 9.3EG 9.32026-08-10
use-context-selector is a React useContextSelector hook in userland Between 2026-05-18 15:57:18 and 2026-05-19 15:24:34, the default branch contained malicious commits 9d8481a513b7b0d1c0941b220c69b25de748641b through 6f2dae054ca014068bdbbb…
- CVE-2026-48159CRITICALCVSS 9.3EG 9.32026-08-10
use-reducer-async is a React useReducer with async actions. Between 2026-05-18 16:29:52 and 2026-05-19 15:26:07, the default branch contained malicious commits da72edbde5705efcec6c62e0a3dcb73687b78dc8 through df07d5711458d8b46e11dd7afaaa21…
- CVE-2026-48160CRITICALCVSS 9.3EG 9.32026-08-10
react-tracked provides state usage tracking with Proxies. Between 2026-05-18 19:26:36 and 2026-05-19 15:22:45, the default branch contained malicious commits 6978272a7d6ca02225cb747ea69f427512e33699 through 949f1a3d6bb1ff7d1a0dec892afd773e…
- CVE-2026-48161CRITICALCVSS 9.3EG 9.32026-08-10
react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contained malicious commits 7b79148d1495a2505f9277da295a98cf176f4496 through 7b79148d1495a2505f9277da295a98cf176f4496 that exe…
- CVE-2026-6443CRITICALCVSS 9.8EG 9.82026-04-17
All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to the plugin being sold to a malicious threat actor that embedded a backdoor in all of the plugin's they acquired. This m…
- CVE-2026-66747CRITICALCVSS 9.8EG 9.82026-08-05
Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boo…
- CVE-2026-67595HIGHCVSS 8.1EG 8.12026-07-29
VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that…
- CVE-2026-73532CRITICALCVSS 9.8EG 9.82026-08-13
Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), lo…
- CVE-2026-73533CRITICALCVSS 9.8EG 9.82026-08-13
Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableD…
- CVE-2026-77649CRITICALCVSS 9.8EG 9.82026-08-21
The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.
- CVE-2026-77650CRITICALCVSS 9.8EG 9.82026-08-21
The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execu…
Map vulnerabilities like CWE-506 to your infrastructure
EchelonGraph correlates every CVE — across CWE-506 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →