İçeriğe atla
Noroxi

CWE-95 · 159 kayıt

Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')

Bu sınıftaki CVE’ler

159 kayıt

  • Remote code execution as guest via SolrSearchMacros request in xwiki

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    xwiki · xwiki20 Şub 2025

  • Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    geoserver · geoserver1 Tem 2024

  • CVE-2024-21650
    67Bu hafta

    XWiki Remote Code Execution vulnerability via user registration

    KritikCVSS 9,8Kavram kanıtıEPSS %93

    xwiki · xwiki8 Oca 2024

  • CVE-2023-7101
    67Bu hafta

    Arbitrary Code Execution (ACE) Vulnerability

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %19

    jmcnamara · spreadsheet\24 Ara 2023

  • CVE-2024-7954
    66Bu hafta

    SPIP porte_plume Plugin Arbitrary PHP Execution

    KritikCVSS 9,8SilahlaştırılmışEPSS %90

    spip · spip23 Ağu 2024

  • CVE-2024-36404
    62Bu hafta

    GeoTools Remote Code Execution (RCE) vulnerability in evaluating XPath expressions

    KritikCVSS 9,8Kavram kanıtıEPSS %76

    geotools · geotools2 Tem 2024

  • CVE-2023-26477
    61Bu hafta

    org.xwiki.platform:xwiki-platform-flamingo-theme-ui Eval Injection vulnerability

    KritikCVSS 9,8İstismar yokEPSS %75

    xwiki · xwiki2 Mar 2023

  • CVE-2024-31984
    60Bu hafta

    XWiki Platform: Remote code execution through space title and Solr space facet

    YüksekCVSS 8,8İstismar yokEPSS %83

    xwiki · xwiki10 Nis 2024

  • CVE-2023-29509
    58Planlayın

    org.xwiki.platform:xwiki-platform-flamingo-theme-ui Eval Injection vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %76

    xwiki · xwiki16 Nis 2023

  • CVE-2024-31465
    58Planlayın

    XWiki Platform: Remote code execution from account via SearchSuggestSourceSheet

    YüksekCVSS 8,8İstismar yokEPSS %76

    xwiki · xwiki10 Nis 2024

  • CVE-2023-35150
    55Planlayın

    XWiki Platform vulnerable to privilege escalation (PR) from view right via Invitation application

    YüksekCVSS 8,0İstismar yokEPSS %78

    xwiki · xwiki23 Haz 2023

  • CVE-2024-31982
    49Planlayın

    XWiki Platform: Remote code execution as guest via DatabaseSearch

    KritikCVSS 9,8Kavram kanıtıEPSS %35

    xwiki · xwiki10 Nis 2024

  • CVE-2026-0769
    49Planlayın

    Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability

    KritikCVSS 9,8Kavram kanıtıEPSS %32

    langflow · langflow23 Oca 2026

  • CVE-2026-1470
    45Planlayın

    Authenticated users can bypass the Expression sandbox mechanism to achieve full remote code execution on n8n’s main node.

    KritikCVSS 9,9İstismar yokEPSS %21

    n8n · n8n27 Oca 2026

  • CVE-2025-54322
    44Planlayın

    Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py.

    KritikCVSS 9,8Kavram kanıtıEPSS %15

    xspeeder · sxzos27 Ara 2025

  • CVE-2025-0868
    42Planlayın

    Remote Code Execution in DocsGPT

    KritikCVSS 9,3Kavram kanıtıEPSS %17

    arc53 · docsgpt20 Şub 2025

  • CVE-2026-0863
    42Planlayın

    Sandbox escape in n8n Python task runner allows for arbitrary code execution on the underlying host.

    KritikCVSS 9,9İstismar yokEPSS %9

    n8n · n8n18 Oca 2026

  • CVE-2013-10070
    41Planlayın

    PHP-Charts v1.0 PHP Code Execution

    KritikCVSS 10,0SilahlaştırılmışEPSS %2

    php-charts · php-charts5 Ağu 2025

  • CVE-2026-19295
    40Planlayın

    Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement

    KritikCVSS 9,9SilahlaştırılmışEPSS %3

    langflow · langflow28 Ağu 2026

  • CVE-2024-31996
    40Planlayın

    XWiki Commons missing escaping of `{` in Velocity escapetool allows remote code execution

    KritikCVSS 9,8İstismar yokEPSS %2

    xwiki · xwiki10 Nis 2024

  • CVE-2026-100741
    40Planlayın

    Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in hMailServer

    KritikCVSS 9,8İstismar yokEPSS %2

    progressive robot ltd · hmailserver3 gün önce

  • CVE-2026-61539
    40Planlayın

    Xinference: Remote code execution via unsafe `eval()` in Llama3 tool-call parsing

    KritikCVSS 10,0İstismar yokEPSS %1

    xorbitsai · inference21 Ağu 2026

  • CVE-2021-23277
    40Planlayın

    Improper Neutralization of Directives in Dynamically Evaluated Code

    KritikCVSS 10,0İstismar yokEPSS %1

    eaton · intelligent power manager13 Nis 2021

  • CVE-2025-68271
    40Planlayın

    Unauthenticated Remote Code Execution in openc3-api

    KritikCVSS 10,0İstismar yokEPSS %1

    openc3 · cosmos13 Oca 2026

  • CVE-2026-22666
    39İzleyin

    Dolibarr ERP/CRM < 23.0.2 Authenticated RCE via dol_eval_standard()

    YüksekCVSS 8,6Kavram kanıtıEPSS %16

    dolibarr · dolibarr erp\/crm7 Nis 2026

Tüm zafiyet sınıfları