Known exploited vulnerabilities classified as CWE-506
Entries8
Ransomware-linked1
Vendors8
By vendor
1
1
1
1
1
1
1
1
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2026-8398 | Daemon Daemon Tools Lite | 2026-05-27 | 0.9% | Unknown |
| CVE-2026-48027 | Nx Nx Console | 2026-05-27 | 1.3% | Known |
| CVE-2026-33634 | Aquasecurity Trivy | 2026-03-26 | 1.6% | Unknown |
| CVE-2025-54313 | Prettier eslint-config-prettier | 2026-01-22 | 4.5% | Unknown |
| CVE-2025-59374 | ASUS Live Update | 2025-12-17 | 1.1% | Unknown |
| CVE-2025-30154 | reviewdog action-setup GitHub Action | 2025-03-24 | 2.4% | Unknown |
| CVE-2025-30066 | tj-actions changed-files GitHub Action | 2025-03-18 | 72.0% | Unknown |
| CVE-2024-4978 | Justice AV Solutions Viewer | 2024-05-29 | 26.9% | Unknown |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
8 KEV entries are classified as CWE-506. CWE definition (MITRE)