Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-506

MITRE ↗

CWE-506

19
CRITICAL
45
HIGH
1
MEDIUM
71 CVEs · Page 1/2
10.0
CVE-2026-46412

@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support

9.8
CVE-2026-31976

xygeni-action is the GitHub Action for Xygeni Scanner. On March 3, 2026, an attacker with access to compromised credenti

9.8
CVE-2026-34841

Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack

9.8
CVE-2026-34424

Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected throu

9.8
CVE-2026-6443

All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to

9.8
CVE-2026-44484

PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introdu

9.8
CVE-2026-8398 KEV

A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421

9.8
CVE-2026-48027 KEV

Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was publish

9.8
CVE-2026-18072

The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to

9.8
CVE-2026-66747

Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across

9.8
CVE-2026-73532

Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served t

9.8
CVE-2026-73533

Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served

9.8
CVE-2026-77649

The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate

9.8
CVE-2026-77650

The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the

9.8
CVE-2026-77651

The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate,

9.8
CVE-2026-74232

Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink

9.6
CVE-2026-45321 KEV

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were publ

9.6
CVE-2026-45758

Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific,

8.8
CVE-2026-33634 KEV

Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy

8.1
CVE-2026-67595

VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template re

6.5
CVE-2024-10938

The OVRI Payment plugin for WordPress contains malicious .htaccess files in version 1.7.0. The files contain directives

CVE-2026-28353

Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. In Trivy VSCode Extension version 1.

CVE-2026-46421

The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-d

CVE-2026-48158

use-context-selector is a React useContextSelector hook in userland Between 2026-05-18 15:57:18 and 2026-05-19 15:24:34,

CVE-2026-48159

use-reducer-async is a React useReducer with async actions. Between 2026-05-18 16:29:52 and 2026-05-19 15:26:07, the def

CVE-2026-48160

react-tracked provides state usage tracking with Proxies. Between 2026-05-18 19:26:36 and 2026-05-19 15:22:45, the defau

CVE-2026-48161

react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contain

9.8
CVE-2017-16128

The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registr

7.5
CVE-2017-16047

mysqljs was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm

7.5
CVE-2017-16061

tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm

7.5
CVE-2017-16062

node-tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished b

7.5
CVE-2017-16044

`d3.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm

7.5
CVE-2017-16045

`jquery.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by

7.5
CVE-2017-16046

`mariadb` was a malicious module published with the intent to hijack environment variables. It has been unpublished by n

7.5
CVE-2017-16048

`node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished

7.5
CVE-2017-16049

`nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished b

7.5
CVE-2017-16050

`sqlite.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by

7.5
CVE-2017-16051

`sqliter` was a malicious module published with the intent to hijack environment variables. It has been unpublished by n

7.5
CVE-2017-16052

`node-fabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished

7.5
CVE-2017-16053

`fabric-js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by

7.5
CVE-2017-16054

`nodefabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished b

7.5
CVE-2017-16055

`sqlserver` was a malicious module published with the intent to hijack environment variables. It has been unpublished by

7.5
CVE-2017-16056

mssql.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by np

7.5
CVE-2017-16057

nodemssql was a malicious module published with the intent to hijack environment variables. It has been unpublished by n

7.5
CVE-2017-16058

gruntcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by np

7.5
CVE-2017-16059

mssql-node was a malicious module published with the intent to hijack environment variables. It has been unpublished by

7.5
CVE-2017-16060

babelcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by np

7.5
CVE-2017-16063

node-opensl was a malicious module published with the intent to hijack environment variables. It has been unpublished by

7.5
CVE-2017-16064

node-openssl was a malicious module published with the intent to hijack environment variables. It has been unpublished b

7.5
CVE-2017-16065

openssl.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by

Frequently Asked Questions

What is CWE-506?

CWE-506 (CWE-506) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-506?

There are 71 CVE records associated with CWE-506 in our database. Of these, 19 are critical severity, 45 are high severity, and 1 are medium severity.

How can I protect against CWE-506 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-506 using AI-powered security agents.

Detect CWE-506 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-506 vulnerabilities across your infrastructure.

Get Started