CWE-95 · 160 записей
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
CVE этого класса
160 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2025-24893Готовый эксплойт | Remote code execution as guest via SolrSearchMacros request in xwikixwiki · xwiki · CWE-95 | Критическая9,8 | KEV | 99,9 % | 20 февр. 2025 г. |
99Срочно | CVE-2024-36401Готовый эксплойт | Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoservergeoserver · geoserver · CWE-95 | Критическая9,8 | KEV | 99,8 % | 1 июл. 2024 г. |
67На этой неделе | CVE-2024-21650Proof of concept | XWiki Remote Code Execution vulnerability via user registrationxwiki · xwiki · CWE-95 | Критическая9,8 | — | 93,5 % | 8 янв. 2024 г. |
67На этой неделе | CVE-2023-7101Готовый эксплойт | Arbitrary Code Execution (ACE) Vulnerabilityjmcnamara · spreadsheet\ · CWE-95 | Высокая7,8 | KEV | 19,1 % | 24 дек. 2023 г. |
66На этой неделе | CVE-2024-7954Готовый эксплойт | SPIP porte_plume Plugin Arbitrary PHP Executionspip · spip · CWE-95 | Критическая9,8 | — | 90,1 % | 23 авг. 2024 г. |
62На этой неделе | CVE-2024-36404Proof of concept | GeoTools Remote Code Execution (RCE) vulnerability in evaluating XPath expressionsgeotools · geotools · CWE-95 | Критическая9,8 | — | 76,1 % | 2 июл. 2024 г. |
61На этой неделе | CVE-2023-26477Эксплойта нет | org.xwiki.platform:xwiki-platform-flamingo-theme-ui Eval Injection vulnerabilityxwiki · xwiki · CWE-95 | Критическая9,8 | — | 74,8 % | 2 мар. 2023 г. |
60На этой неделе | CVE-2024-31984Эксплойта нет | XWiki Platform: Remote code execution through space title and Solr space facetxwiki · xwiki · CWE-95 | Высокая8,8 | — | 83,0 % | 10 апр. 2024 г. |
58В плане | CVE-2023-29509Эксплойта нет | org.xwiki.platform:xwiki-platform-flamingo-theme-ui Eval Injection vulnerabilityxwiki · xwiki · CWE-95 | Высокая8,8 | — | 75,7 % | 16 апр. 2023 г. |
58В плане | CVE-2024-31465Эксплойта нет | XWiki Platform: Remote code execution from account via SearchSuggestSourceSheetxwiki · xwiki · CWE-95 | Высокая8,8 | — | 75,6 % | 10 апр. 2024 г. |
55В плане | CVE-2023-35150Эксплойта нет | XWiki Platform vulnerable to privilege escalation (PR) from view right via Invitation applicationxwiki · xwiki · CWE-95 | Высокая8,0 | — | 77,7 % | 23 июн. 2023 г. |
49В плане | CVE-2024-31982Proof of concept | XWiki Platform: Remote code execution as guest via DatabaseSearchxwiki · xwiki · CWE-95 | Критическая9,8 | — | 34,5 % | 10 апр. 2024 г. |
49В плане | CVE-2026-0769Готовый эксплойт | Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerabilitylangflow · langflow · CWE-95 | Критическая9,8 | — | 32,3 % | 23 янв. 2026 г. |
45В плане | CVE-2026-1470Эксплойта нет | Authenticated users can bypass the Expression sandbox mechanism to achieve full remote code execution on n8n’s main node.n8n · n8n · CWE-95 | Критическая9,9 | — | 20,7 % | 27 янв. 2026 г. |
44В плане | CVE-2025-54322Proof of concept | Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py.xspeeder · sxzos · CWE-95 | Критическая9,8 | — | 15,1 % | 27 дек. 2025 г. |
42В плане | CVE-2025-0868Proof of concept | Remote Code Execution in DocsGPTarc53 · docsgpt · CWE-95 | Критическая9,3 | — | 17,1 % | 20 февр. 2025 г. |
42В плане | CVE-2026-0863Эксплойта нет | Sandbox escape in n8n Python task runner allows for arbitrary code execution on the underlying host.n8n · n8n · CWE-95 | Критическая9,9 | — | 9,4 % | 18 янв. 2026 г. |
41В плане | CVE-2013-10070Готовый эксплойт | PHP-Charts v1.0 PHP Code Executionphp-charts · php-charts · CWE-95 | Критическая10,0 | — | 2,1 % | 5 авг. 2025 г. |
40В плане | CVE-2026-19295Готовый эксплойт | Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcementlangflow · langflow · CWE-95 | Критическая9,9 | — | 3,0 % | 28 авг. 2026 г. |
40В плане | CVE-2024-31996Эксплойта нет | XWiki Commons missing escaping of `{` in Velocity escapetool allows remote code executionxwiki · xwiki · CWE-95 | Критическая9,8 | — | 2,1 % | 10 апр. 2024 г. |
40В плане | CVE-2026-100741Эксплойта нет | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in hMailServerprogressive robot ltd · hmailserver · CWE-95 | Критическая9,8 | — | 1,7 % | 27 сент. 2026 г. |
40В плане | CVE-2026-61539Эксплойта нет | Xinference: Remote code execution via unsafe `eval()` in Llama3 tool-call parsingxorbitsai · inference · CWE-95 | Критическая10,0 | — | 1,2 % | 21 авг. 2026 г. |
40В плане | CVE-2021-23277Эксплойта нет | Improper Neutralization of Directives in Dynamically Evaluated Codeeaton · intelligent power manager · CWE-95 | Критическая10,0 | — | 1,0 % | 13 апр. 2021 г. |
40В плане | CVE-2025-68271Эксплойта нет | Unauthenticated Remote Code Execution in openc3-apiopenc3 · cosmos · CWE-95 | Критическая10,0 | — | 0,6 % | 13 янв. 2026 г. |
39Наблюдать | CVE-2026-22666Proof of concept | Dolibarr ERP/CRM < 23.0.2 Authenticated RCE via dol_eval_standard()dolibarr · dolibarr erp\/crm · CWE-95 | Высокая8,6 | — | 15,5 % | 7 апр. 2026 г. |
- CVE-2025-2489399Срочно
Remote code execution as guest via SolrSearchMacros request in xwiki
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %xwiki · xwiki20 февр. 2025 г.
- CVE-2024-3640199Срочно
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %geoserver · geoserver1 июл. 2024 г.
- CVE-2024-2165067На этой неделе
XWiki Remote Code Execution vulnerability via user registration
КритическаяCVSS 9,8Proof of conceptEPSS 93 %xwiki · xwiki8 янв. 2024 г.
- CVE-2023-710167На этой неделе
Arbitrary Code Execution (ACE) Vulnerability
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 19 %jmcnamara · spreadsheet\24 дек. 2023 г.
- CVE-2024-795466На этой неделе
SPIP porte_plume Plugin Arbitrary PHP Execution
КритическаяCVSS 9,8Готовый эксплойтEPSS 90 %spip · spip23 авг. 2024 г.
- CVE-2024-3640462На этой неделе
GeoTools Remote Code Execution (RCE) vulnerability in evaluating XPath expressions
КритическаяCVSS 9,8Proof of conceptEPSS 76 %geotools · geotools2 июл. 2024 г.
- CVE-2023-2647761На этой неделе
org.xwiki.platform:xwiki-platform-flamingo-theme-ui Eval Injection vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 75 %xwiki · xwiki2 мар. 2023 г.
- CVE-2024-3198460На этой неделе
XWiki Platform: Remote code execution through space title and Solr space facet
ВысокаяCVSS 8,8Эксплойта нетEPSS 83 %xwiki · xwiki10 апр. 2024 г.
- CVE-2023-2950958В плане
org.xwiki.platform:xwiki-platform-flamingo-theme-ui Eval Injection vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 76 %xwiki · xwiki16 апр. 2023 г.
- CVE-2024-3146558В плане
XWiki Platform: Remote code execution from account via SearchSuggestSourceSheet
ВысокаяCVSS 8,8Эксплойта нетEPSS 76 %xwiki · xwiki10 апр. 2024 г.
- CVE-2023-3515055В плане
XWiki Platform vulnerable to privilege escalation (PR) from view right via Invitation application
ВысокаяCVSS 8,0Эксплойта нетEPSS 78 %xwiki · xwiki23 июн. 2023 г.
- CVE-2024-3198249В плане
XWiki Platform: Remote code execution as guest via DatabaseSearch
КритическаяCVSS 9,8Proof of conceptEPSS 35 %xwiki · xwiki10 апр. 2024 г.
- CVE-2026-076949В плане
Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability
КритическаяCVSS 9,8Готовый эксплойтEPSS 32 %langflow · langflow23 янв. 2026 г.
- CVE-2026-147045В плане
Authenticated users can bypass the Expression sandbox mechanism to achieve full remote code execution on n8n’s main node.
КритическаяCVSS 9,9Эксплойта нетEPSS 21 %n8n · n8n27 янв. 2026 г.
- CVE-2025-5432244В плане
Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py.
КритическаяCVSS 9,8Proof of conceptEPSS 15 %xspeeder · sxzos27 дек. 2025 г.
- CVE-2025-086842В плане
Remote Code Execution in DocsGPT
КритическаяCVSS 9,3Proof of conceptEPSS 17 %arc53 · docsgpt20 февр. 2025 г.
- CVE-2026-086342В плане
Sandbox escape in n8n Python task runner allows for arbitrary code execution on the underlying host.
КритическаяCVSS 9,9Эксплойта нетEPSS 9 %n8n · n8n18 янв. 2026 г.
- CVE-2013-1007041В плане
PHP-Charts v1.0 PHP Code Execution
КритическаяCVSS 10,0Готовый эксплойтEPSS 2 %php-charts · php-charts5 авг. 2025 г.
- CVE-2026-1929540В плане
Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement
КритическаяCVSS 9,9Готовый эксплойтEPSS 3 %langflow · langflow28 авг. 2026 г.
- CVE-2024-3199640В плане
XWiki Commons missing escaping of `{` in Velocity escapetool allows remote code execution
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %xwiki · xwiki10 апр. 2024 г.
- CVE-2026-10074140В плане
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in hMailServer
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %progressive robot ltd · hmailserver27 сент. 2026 г.
- CVE-2026-6153940В плане
Xinference: Remote code execution via unsafe `eval()` in Llama3 tool-call parsing
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %xorbitsai · inference21 авг. 2026 г.
- CVE-2021-2327740В плане
Improper Neutralization of Directives in Dynamically Evaluated Code
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %eaton · intelligent power manager13 апр. 2021 г.
- CVE-2025-6827140В плане
Unauthenticated Remote Code Execution in openc3-api
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %openc3 · cosmos13 янв. 2026 г.
- CVE-2026-2266639Наблюдать
Dolibarr ERP/CRM < 23.0.2 Authenticated RCE via dol_eval_standard()
ВысокаяCVSS 8,6Proof of conceptEPSS 16 %dolibarr · dolibarr erp\/crm7 апр. 2026 г.