Total
75 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-28353 | 2026-03-05 | N/A | N/A | ||
|
Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. In Trivy VSCode Extension version 1.8.12, which was distributed via OpenVSX marketplace was compromised and contained malicious code designed to leverage local AI coding agent to collect and exfiltrate sensitive information. Users using the affected artifact are advised to immediately remove it and rotate environment secrets. The malicious artifact has been removed from the marketplace. No other affected artifact ...
Show More |
|||||
| CVE-2024-10938 | 2026-02-27 | N/A | 6.5 MEDIUM | ||
|
The OVRI Payment plugin for WordPress contains malicious .htaccess files in version 1.7.0. The files contain directives to prevent the execution of certain scripts while allowing execution of known malicious PHP files. If moved outside of the plugin's directory, they may interfere with the proper function of a site.
|
|||||
| CVE-2025-54313 | 5 Alexghr, Homarr, Microsoft and 2 more | 8 Got-fetch, Homarr, Windows and 5 more | 2026-01-23 | N/A | 7.5 HIGH |
|
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.
|
|||||
| CVE-2023-2003 | 1 Unitronics | 2 Vision1210, Vision1210 Firmware | 2026-01-08 | N/A | 9.1 CRITICAL |
|
Embedded malicious code vulnerability in Vision1210, in the build 5 of operating system version 4.3, which could allow a remote attacker to store base64-encoded malicious code in the device's data tables via the PCOM protocol, which can then be retrieved by a client and executed on the device.
|
|||||
| CVE-2025-59374 | 1 Asus | 1 Live Update | 2025-12-18 | N/A | 9.8 CRITICAL |
|
"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions and installed the compromised versions were affected. The Live Update client has already reached End-of-Support (EOS) in October 2021, and no currently supported devices or products ...
Show More |
|||||
| CVE-2025-30066 | 1 Tj-actions | 1 Changed-files | 2025-11-05 | N/A | 8.6 HIGH |
|
tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)
|
|||||
| CVE-2025-30154 | 1 Reviewdog | 6 Action-ast-grep, Action-composite-template, Action-setup and 3 more | 2025-10-24 | N/A | 8.6 HIGH |
|
reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs. Other reviewdog actions that use `reviewdog/action-setup@v1` that would also be compromised, regardless of version or pinning method, are reviewdog/action-shellcheck, reviewdog/action-composite-template, reviewdog/action-staticcheck, reviewdog/action-ast-grep, ...
Show More |
|||||
| CVE-2024-4978 | 1 Javs | 1 Javs Viewer | 2025-10-24 | N/A | 8.4 HIGH |
|
Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor may exploit this vulnerability to execute of unauthorized PowerShell commands.
|
|||||
| CVE-2018-25117 | 2025-10-16 | N/A | N/A | ||
|
VestaCP commit a3f0fa1 (2018-05-31) up to commit ee03eff (2018-06-13) contain embedded malicious code that resulted in a supply-chain compromise. New installations created from the compromised installer since at least May 2018 were subject to installation of Linux/ChachaDDoS, a multi-stage DDoS bot that uses Lua for second- and third-stage components. The compromise leaked administrative credentials (base64-encoded admin password and server domain) to an external URL during installation and/or r ...
Show More |
|||||
| CVE-2017-20203 | 2025-10-14 | N/A | N/A | ||
|
NetSarang Xmanager Enterprise 5.0 Build 1232, Xmanager 5.0 Build 1045, Xshell 5.0 Build 1322, Xftp 5.0 Build 1218, and Xlpd 5.0 Build 1220 contain a malicious nssock2.dll that implements a multi-stage, DNS-based backdoor. The dormant library contacts a C2 DNS server via a specially crafted TXT record for a month‑generated domain. After receiving a decryption key, it then downloads and executes arbitrary code, creates an encrypted virtual file system (VFS) in the registry, and grants the attacker ...
Show More |
|||||
| CVE-2025-8217 | 2025-10-14 | N/A | 4.0 MEDIUM | ||
|
The Amazon Q Developer Visual Studio Code (VS Code) extension v1.84.0 contains inert, injected code designed to call the Q Developer CLI. The code executes when the extension is launched within the VS Code environment; however the injected code contains a syntax error which prevents it from making a successful API call to the Q Developer CLI.
To mitigate this issue, users should upgrade to version v1.85.0. All installations of v1.84.0 should be removed from use.
|
|||||
| CVE-2017-20202 | 2025-10-14 | N/A | N/A | ||
|
Web Developer for Chrome v0.4.9 contained malicious code that generated a domain via a DGA and fetched a remote script. The fetched script conditionally loaded follow-on modules that performed extensive ad substitution and malvertising, displayed fake “repair” alerts that redirected users to affiliate programs, and attempted to harvest credentials when users logged in. Injected components enumerate common banner sizes for substitution, replace third-party ad calls, and redirect victim traffic to ...
Show More |
|||||
| CVE-2017-20201 | 2025-10-14 | N/A | N/A | ||
|
CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 (32-bit builds) contained a malicious pre-entry-point loader that diverts execution from __scrt_common_main_seh into a custom loader. That loader decodes an embedded blob into shellcode, allocates executable heap memory, resolves Windows API functions at runtime, and transfers execution to an in-memory payload. The payload performs anti-analysis checks, gathers host telemetry, encodes the data with a two-stage obfuscation, and attempts HTTPS exfi ...
Show More |
|||||
| CVE-2025-55556 | 1 Google | 1 Tensorflow | 2025-10-03 | N/A | 6.5 MEDIUM |
|
TensorFlow v2.18.0 was discovered to output random results when compiling Embedding, leading to unexpected behavior in the application.
|
|||||
| CVE-2025-10894 | 2025-09-26 | N/A | 9.6 CRITICAL | ||
|
Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's accounts.
|
|||||
| CVE-2025-59330 | 2025-09-16 | N/A | N/A | ||
|
error-ex allows error subclassing and stack customization. On 8 September 2025, an npm publishing account for error-ex was taken over after a phishing attack. Version 1.3.3 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the attacker's own addresses from within browser environments. Local environments, server environments, command line applications, etc. are not affected. If the package wa ...
Show More |
|||||
| CVE-2025-59144 | 2025-09-16 | N/A | N/A | ||
|
debug is a JavaScript debugging utility. On 8 September 2025, the npm publishing account for debug was taken over after a phishing attack. Version 4.4.2 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the attacker's own addresses from within browser environments. Local environments, server environments, command line applications, etc. are not affected. If the package was used in a browser ...
Show More |
|||||
| CVE-2025-59141 | 2025-09-16 | N/A | N/A | ||
|
simple-swizzle swizzles function arguments. On 8 September 2025, the npm publishing account for simple-swizzle was taken over after a phishing attack. Version 0.2.3 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the attacker's own addresses from within browser environments. Local environments, server environments, command line applications, etc. are not affected. If the package was used i ...
Show More |
|||||
| CVE-2025-59142 | 2025-09-16 | N/A | N/A | ||
|
color-string is a parser and generator for CSS color strings. On 8 September 2025, the npm publishing account for color-string was taken over after a phishing attack. Version 2.1.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the attacker's own addresses from within browser environments. Local environments, server environments, command line applications, etc. are not affected. If the pa ...
Show More |
|||||
| CVE-2025-59145 | 2025-09-16 | N/A | N/A | ||
|
color-name is a JSON with CSS color names. On 8 September 2025, an npm publishing account for color-name was taken over after a phishing attack. Version 2.0.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the attacker's own addresses from within browser environments. Local environments, server environments, command line applications, etc. are not affected. If the package was used in a br ...
Show More |
|||||
| CVE-2025-59331 | 2025-09-16 | N/A | N/A | ||
|
is-arrayish checks if an object can be used like an Array. On 8 September 2025, an npm publishing account for is-arrayish was taken over after a phishing attack. Version 0.3.3 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the attacker's own addresses from within browser environments. Local environments, server environments, command line applications, etc. are not affected. If the package ...
Show More |
|||||
| CVE-2025-59162 | 2025-09-16 | N/A | N/A | ||
|
color-convert provides plain color conversion functions in JavaScript. On 8 September 2025, the npm publishing account for color-convert was taken over after a phishing attack. Version 3.1.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the attacker's own addresses from within browser environments. Local environments, server environments, command line applications, etc. are not affected. ...
Show More |
|||||
| CVE-2025-59140 | 2025-09-16 | N/A | N/A | ||
|
backlash parses collected strings with escapes. On 8 September 2025, the npm publishing account for backslash was taken over after a phishing attack. Version 0.2.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the attacker's own addresses from within browser environments. Local environments, server environments, command line applications, etc. are not affected. If the package was used in ...
Show More |
|||||
| CVE-2025-59143 | 2025-09-16 | N/A | N/A | ||
|
color is a Javascript color conversion and manipulation library. On 8 September 2025, the npm publishing account for color was taken over after a phishing attack. Version 5.0.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the attacker's own addresses from within browser environments. Local environments, server environments, command line applications, etc. are not affected. If the packag ...
Show More |
|||||
| CVE-2025-59037 | 2025-09-11 | N/A | N/A | ||
|
DuckDB is an analytical in-process SQL database management system. On 08 September 2025, the DuckDB distribution for Node.js on npm was compromised with malware (along with several other packages). An attacker published new versions of four of DuckDB's packages that included malicious code to interfere with cryptocoin transactions* According to the npm statistics, nobody has downloaded these packages before they were deprecated. The packages and versions `@duckdb/[email protected]`, `@duckdb/node-b ...
Show More |
|||||
| CVE-2025-59038 | 2025-09-11 | N/A | N/A | ||
|
Prebid.js is a free and open source library for publishers to quickly implement header bidding. NPM users of prebid 10.9.2 may have been briefly compromised by a malware campaign. The malicious code attempts to redirect crypto transactions on the site to the attackers' wallet. Version 10.10.0 fixes the issue. As a workaround, it is also possible to downgrade to 10.9.1.
|
|||||
| CVE-2025-59039 | 2025-09-11 | N/A | N/A | ||
|
Prebid Universal Creative (PUC) is a JavaScript API to render multiple formats. Npm users of PUC 1.17.3 or PUC latest were briefly affected by crypto-related malware. This includes the extremely popular jsdelivr hosting of this file. The maintainers of PUC unpublished version 1.17.3. Users should see Prebid.js 9 release notes for suggestions on moving off the deprecated workflow of using the PUC or pointing to a dynamic version of it. PUC users pointing to latest should transition to 1.17.2 as s ...
Show More |
|||||
| CVE-2024-3094 | 1 Tukaani | 1 Xz | 2025-08-19 | N/A | 10.0 CRITICAL |
|
Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0.
Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.
|
|||||
| CVE-2025-32965 | 2025-04-23 | N/A | N/A | ||
|
xrpl.js is a JavaScript/TypeScript API for interacting with the XRP Ledger in Node.js and the browser. Versions 4.2.1, 4.2.2, 4.2.3, and 4.2.4 of xrpl.js were compromised and contained malicious code designed to exfiltrate private keys. Version 2.14.2 is also malicious, though it is less likely to lead to exploitation as it is not compatible with other 2.x versions. Anyone who used one of these versions should stop immediately and rotate any private keys or secrets used with affected systems. Us ...
Show More |
|||||
| CVE-2021-22887 | 2 Pulsesecure, Supermicro | 24 Psa-5000, Psa-5000 Firmware, Psa-7000 and 21 more | 2024-11-21 | 2.1 LOW | 2.3 LOW |
|
A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. Before an attacker can compromise the BIOS, they must exploit the device.
|
|||||
| CVE-2020-15165 | 1 Chameleon Mini Live Debugger Project | 1 Chameleon Mini Live Debugger | 2024-11-21 | 6.4 MEDIUM | 9.3 CRITICAL |
|
Version 1.1.6-free of Chameleon Mini Live Debugger on Google Play Store may have had it's sources or permissions tampered by a malicious actor. The official maintainer of the package is recommending all users upgrade to v1.1.8 as soon as possible. For more information, review the referenced GitHub Security Advisory.
|
|||||
| CVE-2017-16207 | 1 Discordi.js Project | 1 Discordi.js | 2024-11-21 | 5.0 MEDIUM | 7.3 HIGH |
|
discordi.js is a malicious module based on the discord.js library that exfiltrates login tokens to pastebin.
|
|||||
| CVE-2017-16205 | 1 Coffescript Project | 1 Coffescript | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
The coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
|
|||||
| CVE-2017-16204 | 1 Jquey Project | 1 Jquey | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
The jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
|
|||||
| CVE-2017-16203 | 1 Coffescript Project | 1 Coffescript | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
The coffe-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
|
|||||
| CVE-2017-16202 | 1 Cofeescript Project | 1 Cofeescript | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
The cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
|
|||||
| CVE-2017-16128 | 1 Npm-script-demo Project | 1 Npm-script-demo | 2024-11-21 | 10.0 HIGH | 9.8 CRITICAL |
|
The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registry.
|
|||||
| CVE-2017-16081 | 1 Cross-env.js Project | 1 Cross-env.js | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
|
|||||
| CVE-2017-16080 | 1 Nodesass Project | 1 Nodesass | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
|
|||||
| CVE-2017-16079 | 1 Smb Project | 1 Smb | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
smb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
|
|||||