Skip to main content

CWE archive

CWE-506 CVEs

Programmatic archive

87 CVEs tagged with CWE-50625 Critical, 58 High, 3 Medium, 1 Low, 0 Unrated.

CVE-2026-46412

Published Jul 20, 2026

@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker u…

CVSS 10.0 · Critical
evidence mentions
3
Buzz score
23.9

CVE-2026-46421

Published Jul 15, 2026

The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that tool.…

CVSS 9.3 · Critical
evidence mentions
4
Buzz score
32.6

CVE-2026-45758

Published Jun 5, 2026

Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of `guardrails-ai…

CVSS 9.6 · Critical
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-48027

Published May 27, 2026

Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC,…

CVSS 9.3 · Critical
evidence mentions
7
Buzz score
65.8
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2026-8398

Published May 15, 2026

A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate websi…

CVSS 9.3 · Critical
evidence mentions
4
Buzz score
61.1
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2026-44484

Published May 14, 2026

PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent with a credential harvesting m…

CVSS 9.3 · Critical
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-6443

Published Apr 17, 2026

All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to the plugin being sold to a malicious threat actor that embe…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-34424

Published Apr 9, 2026

Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated…

CVSS 9.3 · Critical
evidence mentions
5
Buzz score
29.4

CVE-2026-34841

Published Apr 6, 2026

Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack involving compromised versions of the axios npm package, wh…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-31976

Published Mar 11, 2026

xygeni-action is the GitHub Action for Xygeni Scanner. On March 3, 2026, an attacker with access to compromised credentials created a series of pull requests (#46, #47, #48) injec…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-28353

Published Mar 5, 2026

Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. In Trivy VSCode Extension version 1.8.12, which was distributed via OpenVSX marketplace was com…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2024-10938

Published Feb 27, 2026

The OVRI Payment plugin for WordPress contains malicious .htaccess files in version 1.7.0. The files contain directives to prevent the execution of certain scripts while allowing…

CVSS 6.5 · Medium

CVE-2025-59374

Published Dec 17, 2025

"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modi…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
46.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2018-25117

Published Oct 15, 2025

VestaCP commit a3f0fa1 (2018-05-31) up to commit ee03eff (2018-06-13) contain embedded malicious code that resulted in a supply-chain compromise. New installations created from th…

CVSS 9.3 · Critical

CVE-2017-20203

Published Oct 9, 2025

NetSarang Xmanager Enterprise 5.0 Build 1232, Xmanager 5.0 Build 1045, Xshell 5.0 Build 1322, Xftp 5.0 Build 1218, and Xlpd 5.0 Build 1220 contain a malicious nssock2.dll that imp…

CVSS 9.3 · Critical

CVE-2017-20202

Published Oct 8, 2025

Web Developer for Chrome v0.4.9 contained malicious code that generated a domain via a DGA and fetched a remote script. The fetched script conditionally loaded follow-on modules t…

CVSS 9.3 · Critical

CVE-2017-20201

Published Oct 8, 2025

CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 (32-bit builds) contained a malicious pre-entry-point loader that diverts execution from __scrt_common_main_seh into a custom loa…

CVSS 9.3 · Critical

CVE-2025-55556

Published Sep 25, 2025

TensorFlow v2.18.0 was discovered to output random results when compiling Embedding, leading to unexpected behavior in the application.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-10894

Published Sep 24, 2025

Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain att…

CVSS 9.6 · Critical
evidence mentions
6
Buzz score
37.5

CVE-2025-59145

Published Sep 15, 2025

color-name is a JSON with CSS color names. On 8 September 2025, an npm publishing account for color-name was taken over after a phishing attack. Version 2.0.1 was published, funct…

CVSS 8.8 · High

CVE-2025-59331

Published Sep 15, 2025

is-arrayish checks if an object can be used like an Array. On 8 September 2025, an npm publishing account for is-arrayish was taken over after a phishing attack. Version 0.3.3 was…

CVSS 8.8 · High

CVE-2025-59330

Published Sep 15, 2025

error-ex allows error subclassing and stack customization. On 8 September 2025, an npm publishing account for error-ex was taken over after a phishing attack. Version 1.3.3 was pu…

CVSS 8.8 · High

CVE-2025-59162

Published Sep 15, 2025

color-convert provides plain color conversion functions in JavaScript. On 8 September 2025, the npm publishing account for color-convert was taken over after a phishing attack. Ve…

CVSS 8.8 · High
Showing 1-25 of 87 CVEsPage 1 of 4