boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-506

Weakness type CWE-506 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
15142

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▂▅█

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 1 · 2026-07 4 · 2026-08 7

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-453219.682.3KEVMalware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SS…
CVE-2026-480279.377.4KEVCompromised Nx Console version 18.95.0
CVE-2024-309410.099.7Xz: malicious code in distributed source
CVE-2026-180729.845.5Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 - …
CVE-2026-667479.345.1ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant
CVE-2026-481599.340.1use-reducer-async was vulnerable to malicious code execution via compromised commits
CVE-2026-735329.338.4Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build
CVE-2026-735339.337.4Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build
CVE-2026-4641210.035.6Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm
CVE-2026-675959.235.4VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php
CVE-2026-481619.335.1react18-use was vulnerable to malicious code execution via compromised commits
CVE-2026-481589.333.0use-context-selector was vulnerable to malicious code execution via compromised commits
CVE-2026-481609.333.0react-tracked was vulnerable to malicious code execution via compromised commits
CVE-2026-464219.331.7Supply chain compromise via malicious package versions (@cap-js/sqlite, @cap-js/postgre…
CVE-2026-457589.620.1Malicious code in guardrails-ai 0.10.1 (supply chain compromise)

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
dai-shi4
wpmanageninja2
@cap-js/db-service1
@tanstack1
beproduct1
cap-js1
guardrails-ai1
nico231
nrwl1
red hat1
webreinvent1
zbtlink1