Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-506
Weakness type CWE-506 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 29 | 22 | 9 |
Monthly trend
▂▁▂▁▁▁▁▁▁▁▁▁▂▁▁▁▂▁▂▁▁▂▁▁▂▁▃▂▄█▂▁
2025-11 0 · 2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 3 · 2026-06 1 · 2026-07 4 · 2026-08 11 · 2026-09 2 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-30066 | 8.6 | 99.4 | KEV | tj-actions changed-files GitHub Action |
| CVE-2024-4978 | 8.7 | 98.0 | KEV | Malicious Code in Justice AV Solutions (JAVS) Viewer |
| CVE-2025-54313 | 7.5 | 91.2 | KEV | Prettier eslint-config-prettier |
| CVE-2025-30154 | 8.6 | 83.7 | KEV | Multiple Reviewdog actions were compromised during a specific time period |
| CVE-2026-33634 | 9.4 | 76.2 | KEV | Trivy ecosystem supply chain briefly compromised |
| CVE-2026-48027 | 9.3 | 70.2 | KEV | Compromised Nx Console version 18.95.0 |
| CVE-2025-59374 | 9.3 | 67.1 | KEV | ASUS Live Update |
| CVE-2026-45321 | 9.6 | 63.2 | KEV | Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SS… |
| CVE-2026-8398 | 9.3 | 60.3 | KEV | Daemon Daemon Tools Lite |
| CVE-2024-3094 | 10.0 | 99.7 | — | Xz: malicious code in distributed source |
| CVE-2026-18072 | 9.8 | 86.8 | — | Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 - … |
| CVE-2026-74232 | 9.3 | 55.6 | — | Zbtlink MQWrt yunmgrd Cloud C2 Implant |
| CVE-2026-77649 | 9.8 | 55.1 | — | — |
| CVE-2026-77650 | 9.8 | 55.1 | — | — |
| CVE-2026-77651 | 9.8 | 55.1 | — | — |
| CVE-2026-66747 | 9.3 | 54.7 | — | ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant |
| CVE-2026-46412 | 10.0 | 53.9 | — | Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm |
| CVE-2026-67595 | 9.2 | 53.8 | — | VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php |
| CVE-2026-48158 | 9.3 | 50.3 | — | use-context-selector was vulnerable to malicious code execution via compromised commits |
| CVE-2026-48159 | 9.3 | 50.3 | — | use-reducer-async was vulnerable to malicious code execution via compromised commits |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| dai-shi | 4 |
| droundy | 3 |
| wpmanageninja | 2 |
| zbtlink | 2 |
| @cap-js/db-service | 1 |
| @tanstack | 1 |
| aquasecurity | 1 |
| asus | 1 |
| avb disc soft | 1 |
| beproduct | 1 |
| berriai | 1 |
| cap-js | 1 |
| debug-js | 1 |
| guardrails-ai | 1 |
| justice av solutions | 1 |