CWE-506
86 CVEs • Abstraction: Class
Embedded Malicious Code
The product contains code that appears to be malicious in nature.
CVEs (86)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Pulsesecure Supermicro11Psa 5000 Firmware Psa 7000 FirmwareX10sl7 F Firmware+8 moreJun 17, 2026 Mar 16, 2021 N/A· v4 2.3 LOW· v3 2.1 LOW· v2 A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. Befor...Show more |
1Chameleon Mini Live Debugger Project 1Chameleon Mini Live Debugger Jun 17, 2026 Aug 28, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Version 1.1.6-free of Chameleon Mini Live Debugger on Google Play Store may have had it's sources or permissions tampered by a malicious actor. The official maintainer of the package is recommending all users upgrade to...Show more |
1Discordi.js Project 1Discordi.js Nov 21, 2024 Jun 7, 2018 N/A· v4 7.3 HIGH· v3 5.0 MEDIUM· v2 discordi.js is a malicious module based on the discord.js library that exfiltrates login tokens to pastebin. |
1Coffescript Project 1Coffescript Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation. |
The jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation. |
1Coffescript Project 1Coffescript Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The coffe-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation. |
1Cofeescript Project 1Cofeescript Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation. |
1Npm Script Demo Project 1Npm Script Demo Nov 21, 2024 Jun 7, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registry. |
1Cross Env.js Project 1Cross Env.js Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
smb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Shadowsock Project 1Shadowsock Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
mongose was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Http Proxy.js Project 1Http Proxy.js Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Noderequest Project 1Noderequest Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Nodemailer.js Project 1Nodemailer.js Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Nodemailer Js Project 1Nodemailer Js Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |