CWE-506 · 455 kayıt
Embedded Malicious Code
Bu sınıftaki CVE’ler
455 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
86Hemen | CVE-2025-30066Silahlaştırılmış | tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs.tj-actions · changed-files · CWE-506 | Yüksek8,6 | KEV | %72,1 | 15 Mar 2025 |
72Bu hafta | CVE-2024-4978Silahlaştırılmış | Malicious Code in Justice AV Solutions (JAVS) Viewerjavs · javs viewer · CWE-506 | Yüksek8,7 | KEV | %26,9 | 22 May 2024 |
68Bu hafta | CVE-2026-33634Silahlaştırılmış | Trivy ecosystem supply chain briefly compromisedaquasec · setup-trivy · CWE-506 | Kritik9,4 | KEV | %1,7 | 23 Mar 2026 |
68Bu hafta | CVE-2026-45321Silahlaştırılmış | Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keystanstack · tanstack\/arktype-adapter · CWE-506 | Kritik9,6 | KEV | %1,1 | 11 May 2026 |
67Bu hafta | CVE-2026-48027Silahlaştırılmış | Compromised Nx Console version 18.95.0nx · nx console · CWE-506 | Kritik9,3 | KEV | %1,3 | 27 May 2026 |
67Bu hafta | CVE-2025-59374Silahlaştırılmış | "UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced throasus · live update · CWE-506 | Kritik9,3 | KEV | %1,2 | 17 Ara 2025 |
67Bu hafta | CVE-2026-8398Silahlaştırılmış | A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434)disc-soft · daemon tools · CWE-506 | Kritik9,3 | KEV | %1,0 | 15 May 2026 |
66Bu hafta | CVE-2024-3094Kavram kanıtı | Xz: malicious code in distributed sourcetukaani · xz · CWE-506 | Kritik10,0 | — | %86,0 | 29 Mar 2024 |
65Bu hafta | CVE-2025-30154Silahlaştırılmış | Multiple Reviewdog actions were compromised during a specific time periodreviewdog · action-ast-grep · CWE-506 | Yüksek8,6 | KEV | %2,4 | 19 Mar 2025 |
61Bu hafta | CVE-2025-54313Silahlaştırılmış | eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise.prettier · eslint-config-prettier · CWE-506 | Yüksek7,5 | KEV | %4,5 | 19 Tem 2025 |
40Planlayın | CVE-2026-18072Kavram kanıtı | Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 - Unauthenticated Authentication Bypass via Hardcoded Backdoor in '_wploginnico23 · advanced responsive video embedder for rumble, odysee, youtube, vimeo, kick … · CWE-506 | Kritik9,8 | — | %3,0 | 29 Tem 2026 |
40Planlayın | CVE-2024-6297Kavram kanıtı | Several WordPress.org Plugins <= Various Versions - Injected Backdoorwarfareplugins · social sharing plugin – social warfare · CWE-506 | Kritik10,0 | — | %1,0 | 25 Haz 2024 |
40Planlayın | CVE-2026-46412İstismar yok | Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud wormbeproduct · beproduct-org-nestjs-auth · CWE-506 | Kritik10,0 | — | %0,8 | 20 Tem 2026 |
40Planlayın | CVE-2026-28353İstismar yok | Trivy Vulnerability Scanner: Unauthorized AI Agent Execution Code Included in OpenVSX Extension Releaseaquasecurity · trivy-vscode-extension · CWE-506 | Kritik10,0 | — | %0,4 | 5 Mar 2026 |
39İzleyin | CVE-2017-16128İstismar yok | The module npm-script-demo opened a connection to a command and control server.npm-script-demo project · npm-script-demo · CWE-506 | Kritik9,8 | — | %1,5 | 6 Haz 2018 |
39İzleyin | CVE-2023-2003İstismar yok | Embedded malicious code vulnerability in Unitronics Vision1210unitronics · vision1210 firmware · CWE-506 | Kritik9,8 | — | %0,9 | 13 Tem 2023 |
39İzleyin | CVE-2026-77650İstismar yok | The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it hadroundy · append-only-vec · CWE-506 | Kritik9,8 | — | %0,8 | 20 Ağu 2026 |
39İzleyin | CVE-2026-77651İstismar yok | The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rodroundy · arrayref · CWE-506 | Kritik9,8 | — | %0,8 | 20 Ağu 2026 |
39İzleyin | CVE-2026-77649İstismar yok | The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rdroundy · internment · CWE-506 | Kritik9,8 | — | %0,8 | 20 Ağu 2026 |
39İzleyin | CVE-2026-6443İstismar yok | Essentialplugin Plugins (Various Versions) - Injected Backdooressentialplugin · accordion and accordion slider · CWE-506 | Kritik9,8 | — | %0,6 | 17 Nis 2026 |
39İzleyin | CVE-2026-97230İstismar yok | IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URLCWE-506 | Kritik9,8 | — | %0,2 | 6 gün önce |
39İzleyin | GHSA-563h-49v8-g7x4İstismar yok | Malicious Package in ks-sha3npm · ks-sha3 · CWE-506 | Kritik9,8 | — | — | 3 Eyl 2020 |
39İzleyin | GHSA-vxfp-qmpq-6826İstismar yok | Malicious Package in hpmmnpm · hpmm · CWE-506 | Kritik9,8 | — | — | 3 Eyl 2020 |
39İzleyin | GHSA-x6ch-c6rv-f7whİstismar yok | Malicious Package in asymcnpm · asymc · CWE-506 | Kritik9,8 | — | — | 2 Eyl 2020 |
39İzleyin | GHSA-226w-6hhj-69hpİstismar yok | Malicious Package in cal_rdnpm · cal_rd · CWE-506 | Kritik9,8 | — | — | 3 Eyl 2020 |
- CVE-2025-3006686Hemen
tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs.
YüksekCVSS 8,6KEVSilahlaştırılmışEPSS %72tj-actions · changed-files15 Mar 2025
- CVE-2024-497872Bu hafta
Malicious Code in Justice AV Solutions (JAVS) Viewer
YüksekCVSS 8,7KEVSilahlaştırılmışEPSS %27javs · javs viewer22 May 2024
- CVE-2026-3363468Bu hafta
Trivy ecosystem supply chain briefly compromised
KritikCVSS 9,4KEVSilahlaştırılmışEPSS %2aquasec · setup-trivy23 Mar 2026
- CVE-2026-4532168Bu hafta
Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
KritikCVSS 9,6KEVSilahlaştırılmışEPSS %1tanstack · tanstack\/arktype-adapter11 May 2026
- CVE-2026-4802767Bu hafta
Compromised Nx Console version 18.95.0
KritikCVSS 9,3KEVSilahlaştırılmışEPSS %1nx · nx console27 May 2026
- CVE-2025-5937467Bu hafta
"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced thro
KritikCVSS 9,3KEVSilahlaştırılmışEPSS %1asus · live update17 Ara 2025
- CVE-2026-839867Bu hafta
A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434)
KritikCVSS 9,3KEVSilahlaştırılmışEPSS %1disc-soft · daemon tools15 May 2026
- CVE-2024-309466Bu hafta
Xz: malicious code in distributed source
KritikCVSS 10,0Kavram kanıtıEPSS %86tukaani · xz29 Mar 2024
- CVE-2025-3015465Bu hafta
Multiple Reviewdog actions were compromised during a specific time period
YüksekCVSS 8,6KEVSilahlaştırılmışEPSS %2reviewdog · action-ast-grep19 Mar 2025
- CVE-2025-5431361Bu hafta
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise.
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %5prettier · eslint-config-prettier19 Tem 2025
- CVE-2026-1807240Planlayın
Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 - Unauthenticated Authentication Bypass via Hardcoded Backdoor in '_wplogin
KritikCVSS 9,8Kavram kanıtıEPSS %3nico23 · advanced responsive video embedder for rumble, odysee, youtube, vimeo, kick …29 Tem 2026
- CVE-2024-629740Planlayın
Several WordPress.org Plugins <= Various Versions - Injected Backdoor
KritikCVSS 10,0Kavram kanıtıEPSS %1warfareplugins · social sharing plugin – social warfare25 Haz 2024
- CVE-2026-4641240Planlayın
Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm
KritikCVSS 10,0İstismar yokEPSS %1beproduct · beproduct-org-nestjs-auth20 Tem 2026
- CVE-2026-2835340Planlayın
Trivy Vulnerability Scanner: Unauthorized AI Agent Execution Code Included in OpenVSX Extension Release
KritikCVSS 10,0İstismar yokEPSS %0aquasecurity · trivy-vscode-extension5 Mar 2026
- CVE-2017-1612839İzleyin
The module npm-script-demo opened a connection to a command and control server.
KritikCVSS 9,8İstismar yokEPSS %1npm-script-demo project · npm-script-demo6 Haz 2018
- CVE-2023-200339İzleyin
Embedded malicious code vulnerability in Unitronics Vision1210
KritikCVSS 9,8İstismar yokEPSS %1unitronics · vision1210 firmware13 Tem 2023
- CVE-2026-7765039İzleyin
The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it ha
KritikCVSS 9,8İstismar yokEPSS %1droundy · append-only-vec20 Ağu 2026
- CVE-2026-7765139İzleyin
The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a ro
KritikCVSS 9,8İstismar yokEPSS %1droundy · arrayref20 Ağu 2026
- CVE-2026-7764939İzleyin
The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a r
KritikCVSS 9,8İstismar yokEPSS %1droundy · internment20 Ağu 2026
- CVE-2026-644339İzleyin
Essentialplugin Plugins (Various Versions) - Injected Backdoor
KritikCVSS 9,8İstismar yokEPSS %1essentialplugin · accordion and accordion slider17 Nis 2026
- CVE-2026-9723039İzleyin
IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL
KritikCVSS 9,8İstismar yokEPSS %06 gün önce
- GHSA-563h-49v8-g7x439İzleyin
Malicious Package in ks-sha3
KritikCVSS 9,8İstismar yoknpm · ks-sha33 Eyl 2020
- GHSA-vxfp-qmpq-682639İzleyin
Malicious Package in hpmm
KritikCVSS 9,8İstismar yoknpm · hpmm3 Eyl 2020
- GHSA-x6ch-c6rv-f7wh39İzleyin
Malicious Package in asymc
KritikCVSS 9,8İstismar yoknpm · asymc2 Eyl 2020
- GHSA-226w-6hhj-69hp39İzleyin
Malicious Package in cal_rd
KritikCVSS 9,8İstismar yoknpm · cal_rd3 Eyl 2020