← Back
CWE-506

86 CVEs • Abstraction: Class

Embedded Malicious Code

The product contains code that appears to be malicious in nature.

JSON object

Loading...

CVEs (86)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Pulsesecure
Supermicro
11Psa 5000 Firmware
Psa 7000 FirmwareX10sl7 F Firmware+8 more
Jun 17, 2026
Mar 16, 2021
N/A· v4
2.3 LOW· v3
2.1 LOW· v2
A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. Befor...Show more
A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. Before an attacker can compromise the BIOS, they must exploit the device.Show less
1Chameleon Mini Live Debugger Project
1Chameleon Mini Live Debugger
Jun 17, 2026
Aug 28, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Version 1.1.6-free of Chameleon Mini Live Debugger on Google Play Store may have had it's sources or permissions tampered by a malicious actor. The official maintainer of the package is recommending all users upgrade to...Show more
Version 1.1.6-free of Chameleon Mini Live Debugger on Google Play Store may have had it's sources or permissions tampered by a malicious actor. The official maintainer of the package is recommending all users upgrade to v1.1.8 as soon as possible. For more information, review the referenced GitHub Security Advisory.Show less
1Discordi.js Project
1Discordi.js
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.3 HIGH· v3
5.0 MEDIUM· v2
discordi.js is a malicious module based on the discord.js library that exfiltrates login tokens to pastebin.
1Coffescript Project
1Coffescript
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
1Jquey Project
1Jquey
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
1Coffescript Project
1Coffescript
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The coffe-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
1Cofeescript Project
1Cofeescript
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
1Npm Script Demo Project
1Npm Script Demo
Nov 21, 2024
Jun 7, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registry.
1Cross Env.js Project
1Cross Env.js
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Nodesass Project
1Nodesass
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Smb Project
1Smb
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
smb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Shadowsock Project
1Shadowsock
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Mongose Project
1Mongose
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
mongose was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Proxy.js Project
1Proxy.js
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Http Proxy.js Project
1Http Proxy.js
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Crossenv Project
1Crossenv
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Noderequest Project
1Noderequest
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Nodemailer.js Project
1Nodemailer.js
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Nodemailer Js Project
1Nodemailer Js
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Nodecaffe Project
1Nodecaffe
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.