CWE-506— Embedded Malicious Code
The product contains code that appears to be malicious in nature.— MITRE CWE catalog
105 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-506page 3 of 3
- CVE-2017-16207HIGHCVSS 7.3EG 7.32018-06-07
discordi.js is a malicious module based on the discord.js library that exfiltrates login tokens to pastebin.
- CVE-2024-10938MEDIUMCVSS 6.5EG 6.52026-02-27
The OVRI Payment plugin for WordPress contains malicious .htaccess files in version 1.7.0. The files contain directives to prevent the execution of certain scripts while allowing execution of known malicious PHP files. If moved outside of …
- CVE-2025-55556MEDIUMCVSS 6.5EG 6.52025-09-25
TensorFlow v2.18.0 was discovered to output random results when compiling Embedding, leading to unexpected behavior in the application.
- CVE-2025-8217MEDIUMCVSS 4.0EG 4.02025-07-30
The Amazon Q Developer Visual Studio Code (VS Code) extension v1.84.0 contains inert, injected code designed to call the Q Developer CLI. The code executes when the extension is launched within the VS Code environment; however the injected…
- CVE-2021-22887LOWCVSS 2.3EG 2.32021-03-16
A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. Before an attacker can c…
Map vulnerabilities like CWE-506 to your infrastructure
EchelonGraph correlates every CVE — across CWE-506 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →