VulnSea

CWE-95

CVEs classified under CWE-95, newest first.

55 CVEsRSS

CVE-2026-73601High· 8.8
1mo ago

Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands by manipulating environment variables…

Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands by manipulating environment variables…

▾ Twilightflowiseai · flowiseEPSS 1.1%via NVD
CVE-2026-73248None
1mo ago

calibre is an e-book manager

calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a malicious EPUB, OPF, PDF, or similar file through program: and a nested template() call whose formatter does not inhe…

▾ SunlitEPSS 0.20%via NVD
CVE-2025-31114None
1mo ago

Fooocus is an image generating software

Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code execution due to the unsafe use of eval when processing metadata JSON. An attacker with access to the Fooocus web UI ma…

▾ SunlitEPSS 0.67%via NVD
CVE-2026-73231High· 7.8
1mo ago

Faker generates massive amounts of fake data in the browser and Node.js

Faker generates massive amounts of fake data in the browser and Node.js. Prior to 10.5.0, the faker.helpers.fake method in src/modules/helpers/eval.ts allows attacker-controlled fake templates to access the Function constructor through f…

▾ Twilightfaker-js · @faker-js/fakerEPSS 0.21%via NVD
CVE-2026-72904None
1mo ago

Firecrawl turns entire websites into LLM-ready markdown or structured data

Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file read vulnerability exists in Firecrawl's extraction functionality due to unsafe schema dereferencing of user-supplied…

▾ SunlitEPSS 0.46%via NVD
CVE-2026-67195High· 8.8
1mo ago

Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands by submitting crafted expression strings to the PolarsVirtualServer backend, which pass…

Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands by submitting crafted expression strings to the PolarsVirtualServer backend, which pass…

▾ TwilightEPSS 1.2%via NVD
CVE-2026-69264Critical· 9.8
1mo ago

Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Pyodide

Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Pyodide. Because Pyodide is loaded with the default js bridge to gl…

▾ Midnightflowiseai · flowiseEPSS 1.1%via NVD
CVE-2026-69253High· 8.8
1mo ago

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1.3, several custom-tool components — AgentAsTool, ChatflowTool, and ExecuteFlow — ran code in the in-process  vm2  sa…

▾ Twilightflowiseai · flowiseEPSS 0.66%via NVD
CVE-2026-55415High· 7.5
2mo ago

datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements

datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.49%via OSV
CVE-2026-45293High· 8.6
2mo ago

WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions

WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.14.1 until 3.4.1, the WordPress.WP.EnqueuedResourceParameters sniff (active in the WordPress and WordPress-Extra rule…

▾ Twilightwp-coding-standards · wp-coding-standards/wpcsEPSS 0.25%via NVD
CVE-2026-46562Critical· 9.8
2mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorithmExecutorFactory.java was constructed…

▾ Midnightspaceapplications · yamcsEPSS 0.98%via NVD
GHSA-r3hx-x5rh-p9vvHigh
2mo ago

django-haystack: Remote Code Execution via `eval()` in Elasticsearch Result Deserialization

django-haystack: Remote Code Execution via `eval()` in Elasticsearch Result Deserialization

▾ Twilightdjango-haystack · django-haystackvia GHSA
CVE-2026-49273High
2mo ago

MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php

MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php

▾ Twilightmantisbt · mantisbt/mantisbtvia GHSA
CVE-2026-14380High· 8.8
2mo ago

DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the packa…

DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the packa…

▾ Twilightperl · dbiEPSS 0.50%via NVD
CVE-2026-40187High
2mo ago

EGroupware has Authenticated RCE via Malicious eTemplate Upload

EGroupware has Authenticated RCE via Malicious eTemplate Upload

▾ Twilightegroupware · egroupware/egroupwareEPSS 0.86%via GHSA
CVE-2026-44939Critical· 9.6
2mo ago

Rancher vulnerable to command injection through unsanitized YAML parameter

Rancher vulnerable to command injection through unsanitized YAML parameter

▾ Midnightrancher · github.com/rancher/rancherEPSS 1.3%via GHSA
CVE-2026-44179Critical· 9.9
3mo ago

xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro

xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro

▾ Midnightxwiki · com.xwiki.pro:xwiki-pro-macrosvia GHSA
GHSA-2c85-rfcc-g74jHigh
3mo ago

Karate Mock Server RCE via embedded expression evaluation of request-derived data

Karate Mock Server RCE via embedded expression evaluation of request-derived data

▾ Twilightkaratelabs · io.karatelabs:karate-corevia GHSA
CVE-2026-47103Critical· 9.8PoC
3mo ago

python-statemachine SCXML <data expr> Eval Injection

python-statemachine SCXML <data expr> Eval Injection

▾ Abyssalpython-statemachine · python-statemachineEPSS 1.4%via GHSA
GHSA-cc5p-54x3-hcf8High
3mo ago

Duplicate Advisory: Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER

Duplicate Advisory: Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER

▾ Twilightpicklescan · picklescanvia GHSA
CVE-2026-48962High· 7.3PoC
4mo ago

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the par…

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the par…

▾ MidnightEPSS 0.50%via NVD
CVE-2025-65530High· 8.8
9mo ago

An eval injection in the malware de-obfuscation routines of CloudLinux ai-bolit before v32.7.4 allows attackers to overwrite arbitrary files as root via scanning a crafted file.

An eval injection in the malware de-obfuscation routines of CloudLinux ai-bolit before v32.7.4 allows attackers to overwrite arbitrary files as root via scanning a crafted file.

▾ Twilightcloudlinux · ai-bolitEPSS 0.30%via NVD
CVE-2025-66474High· 8.8
9mo ago

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc)

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Versions 16.10.9 and below, 17.0.0-rc-1 through 17.4.2 and 17.5.0-rc-1 through 17.5.0 …

▾ Twilightxwiki · xwiki-renderingEPSS 1.0%via NVD
CVE-2025-48868High· 7.2PoC
1y ago

Horilla is a free and open source Human Resource Management System (HRMS)

Horilla is a free and open source Human Resource Management System (HRMS). An authenticated Remote Code Execution (RCE) vulnerability exists in Horilla 1.3.0 due to the unsafe use of Python’s eval() function on a user-controlled query pa…

▾ Midnighthorilla · horillaEPSS 2.5%via NVD
CVE-2025-4318None
1y ago

The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation

The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation. This could potentially allow an authenticated user who has access to create or modify components to run arbitra…

▾ SunlitEPSS 0.94%via NVD
CWE-95 vulnerabilities (CVEs) — page 2 · VulnSea