VulnSea

CWE-95

CVEs classified under CWE-95, newest first.

47 CVEsRSS

CVE-2025-53837Critical· 9.9
3d ago

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc)

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior to versions 14.10.2 and 15.0 RC1, any user who can edit their own user profile o…

Midnightxwiki · xwiki-renderingEPSS 0.64%via NVD
CVE-2026-63325High· 7.8
5d ago

Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier

Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to version 2.33.0 of @redocly/respect-core and @redocly/cli, the respect command dynamically evaluates $faker runtime expressions in Arazzo descript…

TwilightRedocly · redocly-cliEPSS 0.21%via NVD
CVE-2026-19780High· 8.80day
6d ago

Koha Eval Code Injection Remote Code Execution Vulnerability

Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Koha. Authentication is required to exploit this vulnerability. The specific…

AbyssalKoha · KohaEPSS 0.96%via NVD
CVE-2026-61667Critical· 9.9
6d ago

DIRAC is an interware, meaning a software framework for distributed computing

DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, DataManagementSystem/Service/FileCatalogHandler.py checkDataset forwards an authenticated caller-controlled data…

MidnightDIRACGrid · DIRACEPSS 0.65%via NVD
CVE-2026-45579Critical· 9.9
6d ago

DIRAC is an interware, meaning a software framework for distributed computing

DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, the RequestManagementSystem/Service/ReqManagerHandler.py export_getRequestCountersWeb function passes an authent…

MidnightDIRACGrid · DIRACEPSS 0.44%via NVD
CVE-2026-82789High· 8.8
1w ago

An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI System(CHS)

An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI System(CHS). If exploited, arbitrary code may be executed by an attacker who can log in to the product.

TwilightContec · CONPROSYS HMI System(CHS)EPSS 0.30%via NVD
CVE-2026-80351Critical· 9.8
1w ago

Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. An improper neutralization of directives in dynamically evaluated Maven configuration allows tenant-controlled rep…

Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. An improper neutralization of directives in dynamically evaluated Maven configuration allows tenant-controlled rep…

Midnightapache · camelEPSS 0.54%via NVD
CVE-2026-78550Medium· 6.6
1w ago

The Okta Access Gateway management console passes user-supplied input to eval() without sanitization during an authenticated administrator SSH session

The Okta Access Gateway management console passes user-supplied input to eval() without sanitization during an authenticated administrator SSH session. As a result, the unsanitized input is executed directly, leading to code execution wi…

SunlitOkta · Okta Access GatewayEPSS 0.36%via NVD
CVE-2026-76190High· 8.6
1w ago

ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user

ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit…

Twilightadobe · coldfusionEPSS 0.92%via NVD
CVE-2026-48273Critical· 9.9
1w ago

ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user

ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker…

Midnightadobe · coldfusionEPSS 1.9%via NVD
CVE-2026-79678High· 8.1
2w ago

A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced

A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated…

TwilightRed Hat · ipaEPSS 0.47%via NVD
CVE-2026-85165Critical· 9.9
2w ago

n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals

n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals. Authenticated users with workflow-ed…

Midnightn8n · n8nEPSS 0.32%via NVD
CVE-2026-65643High· 8.8PoC
2w ago

Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.

Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.

Midnightcpanel · cpanelEPSS 0.90%via NVD
CVE-2026-54569Critical· 9.8
3w ago

senaite.core Vulnerable to Eval Injection and Missing Authorization

senaite.core Vulnerable to Eval Injection and Missing Authorization

Midnightsenaite-core · senaite-coreEPSS 0.78%via OSV
CVE-2026-78136High· 7.8
4w ago

chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data

chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/kenwood_itm.py.

TwilightEPSS 0.19%via NVD
CVE-2026-61539Critical· 10.0
1mo ago

Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing

Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing

Midnightxinference · xinferenceEPSS 0.66%via OSV
CVE-2026-71864Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a double quote in a header parameter name is emitted into the generated request-validation zod.object({...}) schem…

Midnightorval · orvalEPSS 0.61%via NVD
CVE-2026-71865Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a double quote in a query parameter name is emitted into the generated request-validation zod.object({...}) schema…

Midnightorval · orvalEPSS 0.48%via NVD
CVE-2026-71867Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a single quote in a schema property name is emitted into single-quoted object keys in generated MSW mock factories…

Midnightorval · orvalEPSS 0.61%via NVD
CVE-2026-71866Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. From version 8.19.0 until 8.21.0, a double quote in a schema property name is emitted into the generated zod.object({...}) schema w…

Midnightorval · orvalEPSS 0.48%via NVD
CVE-2026-34399High· 7.8
1mo ago

FreeCAD is a free and open-source multiplatform 3D parametric modeler

FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, FreeCAD's BIM Workbench contains an eval() call on untrusted data from SVG template files. When a user creates a TechDraw page from a malicious…

TwilightFreeCAD · FreeCADEPSS 0.13%via NVD
CVE-2026-34398High· 7.8
1mo ago

FreeCAD is a free and open-source multiplatform 3D parametric modeler

FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, src/Mod/BIM/bimcommands/BimProjectManager.py in the BIM Project Manager Load Template flow passes attacker-controlled FCStd Meta property value…

TwilightEPSS 0.22%via NVD
CVE-2026-74234High· 7.7
1mo ago

Legora before 2026-08-14 contains a cross-site scripting vulnerability that allows attackers to achieve arbitrary JavaScript execution in a victim's browser by embedding a Mermaid block prefixed with a gray-matter JavaScript front-matter…

Legora before 2026-08-14 contains a cross-site scripting vulnerability that allows attackers to achieve arbitrary JavaScript execution in a victim's browser by embedding a Mermaid block prefixed with a gray-matter JavaScript front-matter…

TwilightEPSS 0.28%via NVD
CVE-2026-73602Critical· 9.9
1mo ago

Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass

Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass. Attackers can craft a fake String object …

Midnightflowiseai · flowiseEPSS 0.84%via NVD
CVE-2026-73601High· 8.8
1mo ago

Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands by manipulating environment variables…

Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands by manipulating environment variables…

Twilightflowiseai · flowiseEPSS 0.88%via NVD
CVE-2026-73248None
1mo ago

calibre is an e-book manager

calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a malicious EPUB, OPF, PDF, or similar file through program: and a nested template() call whose formatter does not inhe…

SunlitEPSS 0.21%via NVD
CVE-2025-31114None
1mo ago

Fooocus is an image generating software

Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code execution due to the unsafe use of eval when processing metadata JSON. An attacker with access to the Fooocus web UI ma…

SunlitEPSS 0.67%via NVD
CVE-2026-73231High· 7.8
1mo ago

Faker generates massive amounts of fake data in the browser and Node.js

Faker generates massive amounts of fake data in the browser and Node.js. Prior to 10.5.0, the faker.helpers.fake method in src/modules/helpers/eval.ts allows attacker-controlled fake templates to access the Function constructor through f…

Twilightfaker-js · @faker-js/fakerEPSS 0.22%via NVD
CVE-2026-72904None
1mo ago

Firecrawl turns entire websites into LLM-ready markdown or structured data

Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file read vulnerability exists in Firecrawl's extraction functionality due to unsafe schema dereferencing of user-supplied…

SunlitEPSS 0.29%via NVD
CVE-2026-67195High· 8.8
1mo ago

Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands by submitting crafted expression strings to the PolarsVirtualServer backend, which pass…

Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands by submitting crafted expression strings to the PolarsVirtualServer backend, which pass…

TwilightEPSS 1.2%via NVD
CWE-95 vulnerabilities (CVEs) · VulnSea