CWE-506: CWE-506

8
Total CVEs
2
Critical
4
High
7.8
Avg CVSS
4
In CISA KEV

Yearly Trend

2025
6
2024
1
2023
1

Top Affected Vendors

1 Google 1
2 Asus 1
3 Homarr 1
4 Prettier 1
5 Un Ts 1
6 Alexghr 1
7 Tj Actions 1
8 Reviewdog 1
9 Unitronics 1
10 Javs 1

All CWE-506 CVEs (8)

CVE-2025-59374
KEV EPSS 30.9% 9.8

This CVE describes a supply chain compromise where unauthorized modifications were introduced into certain ASUS Live Update client versions. The modif...

Dec 17, 2025
CVE-2023-2003
9.1

This vulnerability allows remote attackers to inject and execute malicious code on Unitronics Vision1210 PLCs by storing base64-encoded payloads in de...

Jul 13, 2023
CVE-2025-30154
KEV EPSS 15.4% 8.6

CVE-2025-30154 is a supply chain attack where the reviewdog/action-setup GitHub Action was compromised with malicious code that exfiltrates exposed se...

Mar 19, 2025
CVE-2025-30066
KEV EPSS 86.6% 8.6

CVE-2025-30066 is a supply chain attack where malicious commits were injected into the tj-actions/changed-files GitHub Action, allowing attackers to e...

Mar 15, 2025
CVE-2024-4978
8.4

CVE-2024-4978 is a supply chain attack where Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary signed with an unexpected authe...

May 23, 2024
CVE-2025-54313
KEV 7.5

This CVE describes a supply chain compromise where malicious versions of eslint-config-prettier contain embedded malware. Installing affected package ...

Jul 19, 2025
CVE-2025-55556
6.5

TensorFlow v2.18.0 has a bug where Embedding layers produce random outputs during compilation instead of expected results, causing ML models to genera...

Sep 25, 2025
CVE-2025-8217
4.0

The Amazon Q Developer VS Code extension v1.84.0 contains injected code with a syntax error that prevents it from calling the Q Developer CLI. This is...

Jul 30, 2025

About CWE-506 (CWE-506)

Our database tracks 8 CVEs classified as CWE-506, with 2 rated critical and 4 rated high severity. The average CVSS score for CWE-506 vulnerabilities is 7.8.

External reference: View CWE-506 on MITRE CWE →

Monitor CWE-506 Vulnerabilities

Get alerted when new CWE-506 CVEs affect your infrastructure.

Start Monitoring Free