VulnSea

CWE-506

CVEs classified under CWE-506, newest first.

14 CVEsRSS

GHSA-93qj-5q5v-3c2hCritical
3w ago

Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)

Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)

Midnightpantheon-agents · pantheon-agentsvia GHSA
CVE-2026-77651Critical· 9.8
1mo ago

The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.

The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.

MidnightEPSS 0.45%via NVD
CVE-2026-77650Critical· 9.8
1mo ago

The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code exe…

The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code exe…

MidnightEPSS 0.43%via NVD
CVE-2026-77649Critical· 9.8
1mo ago

The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.

The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.

MidnightEPSS 0.43%via NVD
CVE-2026-73533Critical· 9.8
1mo ago

Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server

Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTabl…

MidnightWPManageNinja · Ninja Tables ProEPSS 0.45%via NVD
CVE-2026-73532Critical· 9.8
1mo ago

Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server

Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), …

MidnightWPManageNinja · Fluent Forms ProEPSS 0.46%via NVD
CVE-2026-48161None
1mo ago

react18-use is a React 19 use hook shim

react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contained malicious commits 7b79148d1495a2505f9277da295a98cf176f4496 through 7b79148d1495a2505f9277da295a98cf176f4496 that e…

SunlitEPSS 0.42%via NVD
CVE-2026-48158Critical· 9.3
1mo ago

use-context-selector is a React useContextSelector hook in userland Between 2026-05-18 15:57:18 and 2026-05-19 15:24:34, the default branch contained malicious commits 9d8481a513b7b0d1c0941b220c69b25de748641b through 6f2dae054ca014068bdb…

use-context-selector is a React useContextSelector hook in userland Between 2026-05-18 15:57:18 and 2026-05-19 15:24:34, the default branch contained malicious commits 9d8481a513b7b0d1c0941b220c69b25de748641b through 6f2dae054ca014068bdb…

Midnightdai-shi · use-context-selectorEPSS 0.40%via NVD
CVE-2026-48160None
1mo ago

react-tracked provides state usage tracking with Proxies

react-tracked provides state usage tracking with Proxies. Between 2026-05-18 19:26:36 and 2026-05-19 15:22:45, the default branch contained malicious commits 6978272a7d6ca02225cb747ea69f427512e33699 through 949f1a3d6bb1ff7d1a0dec892afd77…

SunlitEPSS 0.40%via NVD
CVE-2026-48159None
1mo ago

use-reducer-async is a React useReducer with async actions

use-reducer-async is a React useReducer with async actions. Between 2026-05-18 16:29:52 and 2026-05-19 15:26:07, the default branch contained malicious commits da72edbde5705efcec6c62e0a3dcb73687b78dc8 through df07d5711458d8b46e11dd7afaaa…

SunlitEPSS 0.49%via NVD
CVE-2026-66747Critical· 9.8PoC
1mo ago

Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line

Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at b…

AbyssalZbtlink · CPE2801 FirmwareEPSS 0.66%via NVD
GHSA-99j7-fhr2-xfj4Critical
2mo ago

`exploration` was removed from crates.io for malicious code

`exploration` was removed from crates.io for malicious code

Midnightexploration · explorationvia GHSA
GHSA-98x5-vq43-vc5pCritical
2mo ago

semantic-router exposed to compromised litellm wheel (CVE-2026-42208) via unbounded transitive pin

semantic-router exposed to compromised litellm wheel (CVE-2026-42208) via unbounded transitive pin

Midnightsemantic-router · semantic-routervia GHSA
CVE-2024-3094Critical· 10.0PoC

Malicious backdoor in xz/liblzma (supply-chain compromise)

A backdoor was intentionally introduced into the xz-utils upstream release tarballs (5.6.0 / 5.6.1). When linked into sshd via liblzma, it allows a remote attacker holding a specific key to bypass authentication and execute commands.

Abyssalliblzma · liblzmaLinuxEPSS 86%via GHSA
CWE-506 vulnerabilities (CVEs) · VulnSea