CWE-506: Embedded Malicious Code
The product contains code that appears to be malicious in nature.
99 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-30066 — tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 thr
- CVE-2026-33634 — Trivy ecosystem supply chain briefly compromised
- CVE-2025-59374 — "UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modificat
- CVE-2024-4978 — Malicious Code in Justice AV Solutions (JAVS) Viewer
- CVE-2026-45321 — Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
- CVE-2026-48027 — Compromised Nx Console version 18.95.0
- CVE-2026-8398 — A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421
- CVE-2025-54313 — eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Inst
- CVE-2026-28353 — Trivy Vulnerability Scanner: Unauthorized AI Agent Execution Code Included in OpenVSX Extension Release
- CVE-2025-10894 — Nx: nx/devkit: malicious versions of nx and plugins published to npm
- CVE-2026-31976 — xygeni-action v5 tag poisoned with C2 backdoor
- CVE-2025-59039 — Prebid Universal Creative on npm briefly compromised
- CVE-2025-32965 — Compromised xrpl.js versions 4.2.1, 4.2.2, 4.2.3, 4.2.4, and 2.14.2
- CVE-2025-59331 — [email protected] contains malware after npm account takeover
- CVE-2025-59330 — [email protected] contains malware after npm account takeover
- CVE-2025-59162 — [email protected] contains malware after npm account takeover
- CVE-2025-59145 — [email protected] contains malware after npm account takeover
- CVE-2025-59144 — [email protected] contains malware after npm account takeover
- CVE-2025-59143 — [email protected] contains malware after npm account takeover
- CVE-2025-59142 — [email protected] contains malware after npm account takeover
Recently published
- CVE-2026-74232 — Zbtlink MQWrt yunmgrd Cloud C2 Implant
- CVE-2026-77651 — The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate,
- CVE-2026-77650 — The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the
- CVE-2026-77649 — The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate
- CVE-2026-73532 — Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build
- CVE-2026-73533 — Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build
- CVE-2026-48161 — react18-use was vulnerable to malicious code execution via compromised commits
- CVE-2026-48160 — react-tracked was vulnerable to malicious code execution via compromised commits
- CVE-2026-48159 — use-reducer-async was vulnerable to malicious code execution via compromised commits
- CVE-2026-48158 — use-context-selector was vulnerable to malicious code execution via compromised commits
- CVE-2026-66747 — ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant
- CVE-2026-67595 — VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php
- CVE-2026-18072 — Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 - Unauthenticated Authentication Bypass via Hardcoded Backdoor in '_wplogin' Parameter
- CVE-2026-46412 — Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm
- CVE-2026-46421 — Supply chain compromise via malicious package versions (@cap-js/sqlite, @cap-js/postgres, @cap-js/db-service)
- CVE-2026-45758 — Malicious code in guardrails-ai 0.10.1 (supply chain compromise)
- CVE-2026-48027 — Compromised Nx Console version 18.95.0
- CVE-2026-8398 — A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421
- CVE-2026-44484 — Compromise of PyTorch Lightning PyPi Package Versions
- CVE-2026-45321 — Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys