Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-506 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 15 | 14 | 2 |
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▂▅█
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 1 · 2026-07 4 · 2026-08 7
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-45321 | 9.6 | 82.3 | KEV | Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SS… |
| CVE-2026-48027 | 9.3 | 77.4 | KEV | Compromised Nx Console version 18.95.0 |
| CVE-2024-3094 | 10.0 | 99.7 | — | Xz: malicious code in distributed source |
| CVE-2026-18072 | 9.8 | 45.5 | — | Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 - … |
| CVE-2026-66747 | 9.3 | 45.1 | — | ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant |
| CVE-2026-48159 | 9.3 | 40.1 | — | use-reducer-async was vulnerable to malicious code execution via compromised commits |
| CVE-2026-73532 | 9.3 | 38.4 | — | Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build |
| CVE-2026-73533 | 9.3 | 37.4 | — | Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build |
| CVE-2026-46412 | 10.0 | 35.6 | — | Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm |
| CVE-2026-67595 | 9.2 | 35.4 | — | VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php |
| CVE-2026-48161 | 9.3 | 35.1 | — | react18-use was vulnerable to malicious code execution via compromised commits |
| CVE-2026-48158 | 9.3 | 33.0 | — | use-context-selector was vulnerable to malicious code execution via compromised commits |
| CVE-2026-48160 | 9.3 | 33.0 | — | react-tracked was vulnerable to malicious code execution via compromised commits |
| CVE-2026-46421 | 9.3 | 31.7 | — | Supply chain compromise via malicious package versions (@cap-js/sqlite, @cap-js/postgre… |
| CVE-2026-45758 | 9.6 | 20.1 | — | Malicious code in guardrails-ai 0.10.1 (supply chain compromise) |
| Vendor | CVEs |
|---|---|
| dai-shi | 4 |
| wpmanageninja | 2 |
| @cap-js/db-service | 1 |
| @tanstack | 1 |
| beproduct | 1 |
| cap-js | 1 |
| guardrails-ai | 1 |
| nico23 | 1 |
| nrwl | 1 |
| red hat | 1 |
| webreinvent | 1 |
| zbtlink | 1 |