CWE-506
Embedded Malicious Code
Description
The product contains code that appears to be malicious in nature.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-442 · CAPEC-448 · CAPEC-636
CVEs mapped to this weakness (103)
page 5 of 6| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-16056 | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2018 | mssql.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2017-16055 | Hig | 0.49 | 7.5 | 0.01 | Jun 4, 2018 | `sqlserver` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2017-16054 | Hig | 0.49 | 7.5 | 0.01 | Jun 4, 2018 | `nodefabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2017-16053 | Hig | 0.49 | 7.5 | 0.01 | Jun 4, 2018 | `fabric-js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2017-16052 | Hig | 0.49 | 7.5 | 0.01 | Jun 4, 2018 | `node-fabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2017-16051 | Hig | 0.49 | 7.5 | 0.01 | Jun 4, 2018 | `sqliter` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2017-16050 | Hig | 0.49 | 7.5 | 0.01 | Jun 4, 2018 | `sqlite.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2017-16049 | Hig | 0.49 | 7.5 | 0.01 | Jun 4, 2018 | `nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2017-16048 | Hig | 0.49 | 7.5 | 0.01 | Jun 4, 2018 | `node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2017-16046 | Hig | 0.49 | 7.5 | 0.01 | Jun 4, 2018 | `mariadb` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2017-16045 | Hig | 0.49 | 7.5 | 0.01 | Jun 4, 2018 | `jquery.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2017-16044 | Hig | 0.49 | 7.5 | 0.01 | Jun 4, 2018 | `d3.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2017-16062 | Hig | 0.49 | 7.5 | 0.01 | May 29, 2018 | node-tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2017-16061 | Hig | 0.49 | 7.5 | 0.01 | May 29, 2018 | tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2017-16047 | Hig | 0.49 | 7.5 | 0.01 | May 29, 2018 | mysqljs was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2017-16207 | Hig | 0.48 | 7.3 | 0.01 | Jun 7, 2018 | discordi.js is a malicious module based on the discord.js library that exfiltrates login tokens to pastebin. | ||
| CVE-2024-10938 | Med | 0.42 | 6.5 | 0.00 | Feb 27, 2026 | The OVRI Payment plugin for WordPress contains malicious .htaccess files in version 1.7.0. The files contain directives to prevent the execution of certain scripts while allowing execution of known malicious PHP files. If moved outside of the plugin's directory, they may… | ||
| CVE-2025-55556 | Med | 0.42 | 6.5 | 0.00 | Sep 25, 2025 | TensorFlow v2.18.0 was discovered to output random results when compiling Embedding, leading to unexpected behavior in the application. | ||
| CVE-2021-4229 | Med | 0.33 | 5.0 | 0.01 | May 24, 2022 | A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated as critical. This issue affects the crypto mining component which introduces a backdoor. Upgrading to version 0.7.30, 0.8.1 and 1.0.1 is able to address this issue. It is recommended to upgrade the… | ||
| CVE-2025-8217 | Med | 0.26 | 4.0 | 0.00 | Jul 30, 2025 | The Amazon Q Developer Visual Studio Code (VS Code) extension v1.84.0 contains inert, injected code designed to call the Q Developer CLI. The code executes when the extension is launched within the VS Code environment; however the injected code contains a syntax error which… |
- risk 0.49cvss 7.5epss 0.01
mssql.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
`sqlserver` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
`nodefabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
`fabric-js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
`node-fabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
`sqliter` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
`sqlite.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
`nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
`node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
`mariadb` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
`jquery.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
`d3.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
node-tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
mysqljs was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.48cvss 7.3epss 0.01
discordi.js is a malicious module based on the discord.js library that exfiltrates login tokens to pastebin.
- risk 0.42cvss 6.5epss 0.00
The OVRI Payment plugin for WordPress contains malicious .htaccess files in version 1.7.0. The files contain directives to prevent the execution of certain scripts while allowing execution of known malicious PHP files. If moved outside of the plugin's directory, they may…
- risk 0.42cvss 6.5epss 0.00
TensorFlow v2.18.0 was discovered to output random results when compiling Embedding, leading to unexpected behavior in the application.
- risk 0.33cvss 5.0epss 0.01
A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated as critical. This issue affects the crypto mining component which introduces a backdoor. Upgrading to version 0.7.30, 0.8.1 and 1.0.1 is able to address this issue. It is recommended to upgrade the…
- risk 0.26cvss 4.0epss 0.00
The Amazon Q Developer Visual Studio Code (VS Code) extension v1.84.0 contains inert, injected code designed to call the Q Developer CLI. The code executes when the extension is launched within the VS Code environment; however the injected code contains a syntax error which…