@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support
xygeni-action is the GitHub Action for Xygeni Scanner. On March 3, 2026, an attacker with access to compromised credenti
Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack
Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected throu
All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to
PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introdu
A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421
Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was publish
The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to
Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across
Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served t
Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served
The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate
The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the
The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate,
Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were publ
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific,
Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy
VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template re
The OVRI Payment plugin for WordPress contains malicious .htaccess files in version 1.7.0. The files contain directives
Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. In Trivy VSCode Extension version 1.
The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-d
use-context-selector is a React useContextSelector hook in userland Between 2026-05-18 15:57:18 and 2026-05-19 15:24:34,
use-reducer-async is a React useReducer with async actions. Between 2026-05-18 16:29:52 and 2026-05-19 15:26:07, the def
react-tracked provides state usage tracking with Proxies. Between 2026-05-18 19:26:36 and 2026-05-19 15:22:45, the defau
react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contain
The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registr
mysqljs was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm
tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm
node-tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished b
`d3.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm
`jquery.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by
`mariadb` was a malicious module published with the intent to hijack environment variables. It has been unpublished by n
`node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished
`nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished b
`sqlite.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by
`sqliter` was a malicious module published with the intent to hijack environment variables. It has been unpublished by n
`node-fabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished
`fabric-js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by
`nodefabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished b
`sqlserver` was a malicious module published with the intent to hijack environment variables. It has been unpublished by
mssql.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by np
nodemssql was a malicious module published with the intent to hijack environment variables. It has been unpublished by n
gruntcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by np
mssql-node was a malicious module published with the intent to hijack environment variables. It has been unpublished by
babelcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by np
node-opensl was a malicious module published with the intent to hijack environment variables. It has been unpublished by
node-openssl was a malicious module published with the intent to hijack environment variables. It has been unpublished b
openssl.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by
Frequently Asked Questions
What is CWE-506?
CWE-506 (CWE-506) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-506?
There are 71 CVE records associated with CWE-506 in our database. Of these, 19 are critical severity, 45 are high severity, and 1 are medium severity.
How can I protect against CWE-506 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-506 using AI-powered security agents.
Detect CWE-506 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-506 vulnerabilities across your infrastructure.
Get Started