CWE-95
CVEs classified under CWE-95, newest first.
55 CVEsRSS
CVE-2026-73601High· 8.8Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands by manipulating environment variables…
Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands by manipulating environment variables…
CVE-2026-73248Nonecalibre is an e-book manager
calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a malicious EPUB, OPF, PDF, or similar file through program: and a nested template() call whose formatter does not inhe…
CVE-2025-31114NoneFooocus is an image generating software
Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code execution due to the unsafe use of eval when processing metadata JSON. An attacker with access to the Fooocus web UI ma…
CVE-2026-73231High· 7.8Faker generates massive amounts of fake data in the browser and Node.js
Faker generates massive amounts of fake data in the browser and Node.js. Prior to 10.5.0, the faker.helpers.fake method in src/modules/helpers/eval.ts allows attacker-controlled fake templates to access the Function constructor through f…
CVE-2026-72904NoneFirecrawl turns entire websites into LLM-ready markdown or structured data
Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file read vulnerability exists in Firecrawl's extraction functionality due to unsafe schema dereferencing of user-supplied…
CVE-2026-67195High· 8.8Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands by submitting crafted expression strings to the PolarsVirtualServer backend, which pass…
Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands by submitting crafted expression strings to the PolarsVirtualServer backend, which pass…
CVE-2026-69264Critical· 9.8Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Pyodide
Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Pyodide. Because Pyodide is loaded with the default js bridge to gl…
CVE-2026-69253High· 8.8Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows
Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1.3, several custom-tool components — AgentAsTool, ChatflowTool, and ExecuteFlow — ran code in the in-process vm2 sa…
CVE-2026-55415High· 7.5datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
CVE-2026-45293High· 8.6WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions
WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.14.1 until 3.4.1, the WordPress.WP.EnqueuedResourceParameters sniff (active in the WordPress and WordPress-Extra rule…
CVE-2026-46562Critical· 9.8Yamcs is a mission control framework
Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorithmExecutorFactory.java was constructed…
GHSA-r3hx-x5rh-p9vvHighdjango-haystack: Remote Code Execution via `eval()` in Elasticsearch Result Deserialization
django-haystack: Remote Code Execution via `eval()` in Elasticsearch Result Deserialization
CVE-2026-49273HighMantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php
MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php
CVE-2026-14380High· 8.8DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the packa…
DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the packa…
CVE-2026-40187HighEGroupware has Authenticated RCE via Malicious eTemplate Upload
EGroupware has Authenticated RCE via Malicious eTemplate Upload
CVE-2026-44939Critical· 9.6Rancher vulnerable to command injection through unsanitized YAML parameter
Rancher vulnerable to command injection through unsanitized YAML parameter
CVE-2026-44179Critical· 9.9xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro
xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro
GHSA-2c85-rfcc-g74jHighKarate Mock Server RCE via embedded expression evaluation of request-derived data
Karate Mock Server RCE via embedded expression evaluation of request-derived data
CVE-2026-47103Critical· 9.8PoCpython-statemachine SCXML <data expr> Eval Injection
python-statemachine SCXML <data expr> Eval Injection
GHSA-cc5p-54x3-hcf8HighDuplicate Advisory: Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER
Duplicate Advisory: Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER
CVE-2026-48962High· 7.3PoCIO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the par…
IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the par…
CVE-2025-65530High· 8.8An eval injection in the malware de-obfuscation routines of CloudLinux ai-bolit before v32.7.4 allows attackers to overwrite arbitrary files as root via scanning a crafted file.
An eval injection in the malware de-obfuscation routines of CloudLinux ai-bolit before v32.7.4 allows attackers to overwrite arbitrary files as root via scanning a crafted file.
CVE-2025-66474High· 8.8XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc)
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Versions 16.10.9 and below, 17.0.0-rc-1 through 17.4.2 and 17.5.0-rc-1 through 17.5.0 …
CVE-2025-48868High· 7.2PoCHorilla is a free and open source Human Resource Management System (HRMS)
Horilla is a free and open source Human Resource Management System (HRMS). An authenticated Remote Code Execution (RCE) vulnerability exists in Horilla 1.3.0 due to the unsafe use of Python’s eval() function on a user-controlled query pa…
CVE-2025-4318NoneThe AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation
The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation. This could potentially allow an authenticated user who has access to create or modify components to run arbitra…