CWE-95 · 159 records
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
CVEs in this class
159 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2025-24893Weaponized | Remote code execution as guest via SolrSearchMacros request in xwikixwiki · xwiki · CWE-95 | Critical9.8 | KEV | 99.9% | Feb 20, 2025 |
99Now | CVE-2024-36401Weaponized | Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoservergeoserver · geoserver · CWE-95 | Critical9.8 | KEV | 99.8% | Jul 1, 2024 |
67This week | CVE-2024-21650Proof of concept | XWiki Remote Code Execution vulnerability via user registrationxwiki · xwiki · CWE-95 | Critical9.8 | — | 93.5% | Jan 8, 2024 |
67This week | CVE-2023-7101Weaponized | Arbitrary Code Execution (ACE) Vulnerabilityjmcnamara · spreadsheet\ · CWE-95 | High7.8 | KEV | 19.1% | Dec 24, 2023 |
66This week | CVE-2024-7954Weaponized | SPIP porte_plume Plugin Arbitrary PHP Executionspip · spip · CWE-95 | Critical9.8 | — | 90.1% | Aug 23, 2024 |
62This week | CVE-2024-36404Proof of concept | GeoTools Remote Code Execution (RCE) vulnerability in evaluating XPath expressionsgeotools · geotools · CWE-95 | Critical9.8 | — | 76.1% | Jul 2, 2024 |
61This week | CVE-2023-26477No exploit | org.xwiki.platform:xwiki-platform-flamingo-theme-ui Eval Injection vulnerabilityxwiki · xwiki · CWE-95 | Critical9.8 | — | 74.8% | Mar 2, 2023 |
60This week | CVE-2024-31984No exploit | XWiki Platform: Remote code execution through space title and Solr space facetxwiki · xwiki · CWE-95 | High8.8 | — | 83.0% | Apr 10, 2024 |
58Plan | CVE-2023-29509No exploit | org.xwiki.platform:xwiki-platform-flamingo-theme-ui Eval Injection vulnerabilityxwiki · xwiki · CWE-95 | High8.8 | — | 75.7% | Apr 16, 2023 |
58Plan | CVE-2024-31465No exploit | XWiki Platform: Remote code execution from account via SearchSuggestSourceSheetxwiki · xwiki · CWE-95 | High8.8 | — | 75.6% | Apr 10, 2024 |
55Plan | CVE-2023-35150No exploit | XWiki Platform vulnerable to privilege escalation (PR) from view right via Invitation applicationxwiki · xwiki · CWE-95 | High8.0 | — | 77.7% | Jun 23, 2023 |
49Plan | CVE-2024-31982Proof of concept | XWiki Platform: Remote code execution as guest via DatabaseSearchxwiki · xwiki · CWE-95 | Critical9.8 | — | 34.5% | Apr 10, 2024 |
49Plan | CVE-2026-0769Proof of concept | Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerabilitylangflow · langflow · CWE-95 | Critical9.8 | — | 32.3% | Jan 23, 2026 |
45Plan | CVE-2026-1470No exploit | Authenticated users can bypass the Expression sandbox mechanism to achieve full remote code execution on n8n’s main node.n8n · n8n · CWE-95 | Critical9.9 | — | 20.7% | Jan 27, 2026 |
44Plan | CVE-2025-54322Proof of concept | Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py.xspeeder · sxzos · CWE-95 | Critical9.8 | — | 15.1% | Dec 27, 2025 |
42Plan | CVE-2025-0868Proof of concept | Remote Code Execution in DocsGPTarc53 · docsgpt · CWE-95 | Critical9.3 | — | 17.1% | Feb 20, 2025 |
42Plan | CVE-2026-0863No exploit | Sandbox escape in n8n Python task runner allows for arbitrary code execution on the underlying host.n8n · n8n · CWE-95 | Critical9.9 | — | 9.4% | Jan 18, 2026 |
41Plan | CVE-2013-10070Weaponized | PHP-Charts v1.0 PHP Code Executionphp-charts · php-charts · CWE-95 | Critical10.0 | — | 2.1% | Aug 5, 2025 |
40Plan | CVE-2026-19295Weaponized | Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcementlangflow · langflow · CWE-95 | Critical9.9 | — | 3.3% | Aug 28, 2026 |
40Plan | CVE-2024-31996No exploit | XWiki Commons missing escaping of `{` in Velocity escapetool allows remote code executionxwiki · xwiki · CWE-95 | Critical9.8 | — | 2.1% | Apr 10, 2024 |
40Plan | CVE-2026-100741No exploit | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in hMailServerprogressive robot ltd · hmailserver · CWE-95 | Critical9.8 | — | 1.7% | 3 days ago |
40Plan | CVE-2026-61539No exploit | Xinference: Remote code execution via unsafe `eval()` in Llama3 tool-call parsingxorbitsai · inference · CWE-95 | Critical10.0 | — | 1.2% | Aug 21, 2026 |
40Plan | CVE-2021-23277No exploit | Improper Neutralization of Directives in Dynamically Evaluated Codeeaton · intelligent power manager · CWE-95 | Critical10.0 | — | 1.0% | Apr 13, 2021 |
40Plan | CVE-2025-68271No exploit | Unauthenticated Remote Code Execution in openc3-apiopenc3 · cosmos · CWE-95 | Critical10.0 | — | 0.6% | Jan 13, 2026 |
39Monitor | CVE-2026-22666Proof of concept | Dolibarr ERP/CRM < 23.0.2 Authenticated RCE via dol_eval_standard()dolibarr · dolibarr erp\/crm · CWE-95 | High8.6 | — | 15.5% | Apr 7, 2026 |
- CVE-2025-2489399Now
Remote code execution as guest via SolrSearchMacros request in xwiki
CriticalCVSS 9.8KEVWeaponizedEPSS 100%xwiki · xwikiFeb 20, 2025
- CVE-2024-3640199Now
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
CriticalCVSS 9.8KEVWeaponizedEPSS 100%geoserver · geoserverJul 1, 2024
- CVE-2024-2165067This week
XWiki Remote Code Execution vulnerability via user registration
CriticalCVSS 9.8Proof of conceptEPSS 93%xwiki · xwikiJan 8, 2024
- CVE-2023-710167This week
Arbitrary Code Execution (ACE) Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 19%jmcnamara · spreadsheet\Dec 24, 2023
- CVE-2024-795466This week
SPIP porte_plume Plugin Arbitrary PHP Execution
CriticalCVSS 9.8WeaponizedEPSS 90%spip · spipAug 23, 2024
- CVE-2024-3640462This week
GeoTools Remote Code Execution (RCE) vulnerability in evaluating XPath expressions
CriticalCVSS 9.8Proof of conceptEPSS 76%geotools · geotoolsJul 2, 2024
- CVE-2023-2647761This week
org.xwiki.platform:xwiki-platform-flamingo-theme-ui Eval Injection vulnerability
CriticalCVSS 9.8No exploitEPSS 75%xwiki · xwikiMar 2, 2023
- CVE-2024-3198460This week
XWiki Platform: Remote code execution through space title and Solr space facet
HighCVSS 8.8No exploitEPSS 83%xwiki · xwikiApr 10, 2024
- CVE-2023-2950958Plan
org.xwiki.platform:xwiki-platform-flamingo-theme-ui Eval Injection vulnerability
HighCVSS 8.8No exploitEPSS 76%xwiki · xwikiApr 16, 2023
- CVE-2024-3146558Plan
XWiki Platform: Remote code execution from account via SearchSuggestSourceSheet
HighCVSS 8.8No exploitEPSS 76%xwiki · xwikiApr 10, 2024
- CVE-2023-3515055Plan
XWiki Platform vulnerable to privilege escalation (PR) from view right via Invitation application
HighCVSS 8.0No exploitEPSS 78%xwiki · xwikiJun 23, 2023
- CVE-2024-3198249Plan
XWiki Platform: Remote code execution as guest via DatabaseSearch
CriticalCVSS 9.8Proof of conceptEPSS 35%xwiki · xwikiApr 10, 2024
- CVE-2026-076949Plan
Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 32%langflow · langflowJan 23, 2026
- CVE-2026-147045Plan
Authenticated users can bypass the Expression sandbox mechanism to achieve full remote code execution on n8n’s main node.
CriticalCVSS 9.9No exploitEPSS 21%n8n · n8nJan 27, 2026
- CVE-2025-5432244Plan
Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py.
CriticalCVSS 9.8Proof of conceptEPSS 15%xspeeder · sxzosDec 27, 2025
- CVE-2025-086842Plan
Remote Code Execution in DocsGPT
CriticalCVSS 9.3Proof of conceptEPSS 17%arc53 · docsgptFeb 20, 2025
- CVE-2026-086342Plan
Sandbox escape in n8n Python task runner allows for arbitrary code execution on the underlying host.
CriticalCVSS 9.9No exploitEPSS 9%n8n · n8nJan 18, 2026
- CVE-2013-1007041Plan
PHP-Charts v1.0 PHP Code Execution
CriticalCVSS 10.0WeaponizedEPSS 2%php-charts · php-chartsAug 5, 2025
- CVE-2026-1929540Plan
Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement
CriticalCVSS 9.9WeaponizedEPSS 3%langflow · langflowAug 28, 2026
- CVE-2024-3199640Plan
XWiki Commons missing escaping of `{` in Velocity escapetool allows remote code execution
CriticalCVSS 9.8No exploitEPSS 2%xwiki · xwikiApr 10, 2024
- CVE-2026-10074140Plan
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in hMailServer
CriticalCVSS 9.8No exploitEPSS 2%progressive robot ltd · hmailserver3 days ago
- CVE-2026-6153940Plan
Xinference: Remote code execution via unsafe `eval()` in Llama3 tool-call parsing
CriticalCVSS 10.0No exploitEPSS 1%xorbitsai · inferenceAug 21, 2026
- CVE-2021-2327740Plan
Improper Neutralization of Directives in Dynamically Evaluated Code
CriticalCVSS 10.0No exploitEPSS 1%eaton · intelligent power managerApr 13, 2021
- CVE-2025-6827140Plan
Unauthenticated Remote Code Execution in openc3-api
CriticalCVSS 10.0No exploitEPSS 1%openc3 · cosmosJan 13, 2026
- CVE-2026-2266639Monitor
Dolibarr ERP/CRM < 23.0.2 Authenticated RCE via dol_eval_standard()
HighCVSS 8.6Proof of conceptEPSS 16%dolibarr · dolibarr erp\/crmApr 7, 2026