İçeriğe atla
Noroxi

CWE-506 · 455 kayıt

Embedded Malicious Code

Bu sınıftaki CVE’ler

455 kayıt

  • tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs.

    YüksekCVSS 8,6KEVSilahlaştırılmışEPSS %72

    tj-actions · changed-files15 Mar 2025

  • CVE-2024-4978
    72Bu hafta

    Malicious Code in Justice AV Solutions (JAVS) Viewer

    YüksekCVSS 8,7KEVSilahlaştırılmışEPSS %27

    javs · javs viewer22 May 2024

  • CVE-2026-33634
    68Bu hafta

    Trivy ecosystem supply chain briefly compromised

    KritikCVSS 9,4KEVSilahlaştırılmışEPSS %2

    aquasec · setup-trivy23 Mar 2026

  • CVE-2026-45321
    68Bu hafta

    Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys

    KritikCVSS 9,6KEVSilahlaştırılmışEPSS %1

    tanstack · tanstack\/arktype-adapter11 May 2026

  • CVE-2026-48027
    67Bu hafta

    Compromised Nx Console version 18.95.0

    KritikCVSS 9,3KEVSilahlaştırılmışEPSS %1

    nx · nx console27 May 2026

  • CVE-2025-59374
    67Bu hafta

    "UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced thro

    KritikCVSS 9,3KEVSilahlaştırılmışEPSS %1

    asus · live update17 Ara 2025

  • CVE-2026-8398
    67Bu hafta

    A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434)

    KritikCVSS 9,3KEVSilahlaştırılmışEPSS %1

    disc-soft · daemon tools15 May 2026

  • CVE-2024-3094
    66Bu hafta

    Xz: malicious code in distributed source

    KritikCVSS 10,0Kavram kanıtıEPSS %86

    tukaani · xz29 Mar 2024

  • CVE-2025-30154
    65Bu hafta

    Multiple Reviewdog actions were compromised during a specific time period

    YüksekCVSS 8,6KEVSilahlaştırılmışEPSS %2

    reviewdog · action-ast-grep19 Mar 2025

  • CVE-2025-54313
    61Bu hafta

    eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise.

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %5

    prettier · eslint-config-prettier19 Tem 2025

  • CVE-2026-18072
    40Planlayın

    Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 - Unauthenticated Authentication Bypass via Hardcoded Backdoor in '_wplogin

    KritikCVSS 9,8Kavram kanıtıEPSS %3

    nico23 · advanced responsive video embedder for rumble, odysee, youtube, vimeo, kick …29 Tem 2026

  • CVE-2024-6297
    40Planlayın

    Several WordPress.org Plugins <= Various Versions - Injected Backdoor

    KritikCVSS 10,0Kavram kanıtıEPSS %1

    warfareplugins · social sharing plugin – social warfare25 Haz 2024

  • CVE-2026-46412
    40Planlayın

    Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm

    KritikCVSS 10,0İstismar yokEPSS %1

    beproduct · beproduct-org-nestjs-auth20 Tem 2026

  • CVE-2026-28353
    40Planlayın

    Trivy Vulnerability Scanner: Unauthorized AI Agent Execution Code Included in OpenVSX Extension Release

    KritikCVSS 10,0İstismar yokEPSS %0

    aquasecurity · trivy-vscode-extension5 Mar 2026

  • CVE-2017-16128
    39İzleyin

    The module npm-script-demo opened a connection to a command and control server.

    KritikCVSS 9,8İstismar yokEPSS %1

    npm-script-demo project · npm-script-demo6 Haz 2018

  • CVE-2023-2003
    39İzleyin

    Embedded malicious code vulnerability in Unitronics Vision1210

    KritikCVSS 9,8İstismar yokEPSS %1

    unitronics · vision1210 firmware13 Tem 2023

  • CVE-2026-77650
    39İzleyin

    The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it ha

    KritikCVSS 9,8İstismar yokEPSS %1

    droundy · append-only-vec20 Ağu 2026

  • CVE-2026-77651
    39İzleyin

    The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a ro

    KritikCVSS 9,8İstismar yokEPSS %1

    droundy · arrayref20 Ağu 2026

  • CVE-2026-77649
    39İzleyin

    The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a r

    KritikCVSS 9,8İstismar yokEPSS %1

    droundy · internment20 Ağu 2026

  • CVE-2026-6443
    39İzleyin

    Essentialplugin Plugins (Various Versions) - Injected Backdoor

    KritikCVSS 9,8İstismar yokEPSS %1

    essentialplugin · accordion and accordion slider17 Nis 2026

  • CVE-2026-97230
    39İzleyin

    IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL

    KritikCVSS 9,8İstismar yokEPSS %0

    6 gün önce

  • Malicious Package in ks-sha3

    KritikCVSS 9,8İstismar yok

    npm · ks-sha33 Eyl 2020

  • Malicious Package in hpmm

    KritikCVSS 9,8İstismar yok

    npm · hpmm3 Eyl 2020

  • Malicious Package in asymc

    KritikCVSS 9,8İstismar yok

    npm · asymc2 Eyl 2020

  • Malicious Package in cal_rd

    KritikCVSS 9,8İstismar yok

    npm · cal_rd3 Eyl 2020

Tüm zafiyet sınıfları