CWE-95: Eval Injection — known CVE vulnerabilities
CVEs classified under CWE-95 (Eval Injection), ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2026-61539 — CVSS 10.0 (critical): Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes…
CVE-2026-44643 — CVSS 10.0 (critical): Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to 1.5.2, an attacker can write a…
CVE-2025-68271 — CVSS 10.0 (critical): OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.0.0 to…
CVE-2013-10070: PHP-Charts v1.0 contains a PHP code execution vulnerability in wizard/url.php, where user-supplied GET parameter names are passed directly…
CVE-2022-36010 — CVSS 10.0 (critical): This library allows strings to be parsed as functions and stored as a specialized component, [`JsonFunctionValue`](https://github.com/oxyno-…
CVE-2025-53837 — CVSS 9.9 (critical): XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax…
CVE-2026-45579 — CVSS 9.9 (critical): DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, the…
CVE-2026-48273 — CVSS 9.9 (critical): ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that…
CVE-2026-85165 — CVSS 9.9 (critical): n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case…
CVE-2026-19295 — CVSS 9.9 (critical): IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process…
CVE-2026-77810 — CVSS 9.9 (critical): In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda…
CVE-2026-19626 — CVSS 9.9 (critical): A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated…
CVE-2026-73602 — CVSS 9.9 (critical): Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute…
CVE-2026-1470 — CVSS 9.9 (critical): n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressions supplied by…
CVE-2023-29511 — CVSS 9.9 (critical): XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights on a…
CVE-2022-41931 — CVSS 9.9 (critical): xwiki-platform-icon-ui is vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection'). Any user…
CVE-2022-41928 — CVSS 9.9 (critical): XWiki Platform vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in…
CVE-2026-80351 — CVSS 9.8 (critical): Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. An improper…
CVE-2026-54569 — CVSS 9.8 (critical): SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API…
CVE-2026-74899 — CVSS 9.8 (critical): openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in…
CVE-2026-15971 — CVSS 9.8 (critical): SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT…
CVE-2026-61511 — CVSS 9.8 (critical): vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method…
CVE-2026-47391 — CVSS 9.8 (critical): PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an unauthenticated A2A…
CVE-2026-64193 — CVSS 9.8 (critical): Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decomp…
CVE-2026-35002 — CVSS 9.8 (critical): Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to…
CVE-2026-4851 — CVSS 9.8 (critical): GRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe deserialization. GRID::Machine provides Remote…
CVE-2026-4001 — CVSS 9.8 (critical): The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including…
CVE-2025-50187 — CVSS 9.8 (critical): Chamilo is a learning management system. Prior to version 1.11.28, parameter from SOAP request is evaluated without filtering which leads…
CVE-2013-10051 — CVSS 9.8 (critical): A remote PHP code execution vulnerability exists in InstantCMS version 1.6 and earlier due to unsafe use of eval() within the search view…
CVE-2024-7954 — CVSS 9.8 (critical): The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A…
CVE-2024-39173 — CVSS 9.8 (critical): calculator-boilerplate v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the eval function at…
CVE-2024-36404 — CVSS 9.8 (critical): GeoTools is an open source Java library that provides tools for geospatial data. Prior to versions 31.2, 30.4, and 29.6, Remote Code…
CVE-2026-48317 — CVSS 9.6 (critical): Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')…
CVE-2025-40943 — CVSS 9.6 (critical): Affected devices do not properly sanitize contents of trace files. This could allow an attacker to inject code through social engineering…
CVE-2026-44939: A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through…
CVE-2025-31114: Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code execution due to the…
CVE-2026-44128: SEPPmail Secure Email Gateway before version 15.0.2.1 allows unauthenticated remote code execution in the new GINA UI because an endpoint…
CVE-2025-12140: The application contains an insecure 'redirectToUrl' mechanism that incorrectly processes the value of the 'redirectUrlParameter'…
CVE-2011-10033: The WordPress plugin is-human <= v1.4.2 contains an eval injection vulnerability in /is-human/engine.php that can be triggered via the…
CVE-2025-0868: A vulnerability, that could result in Remote Code Execution (RCE), has been found in DocsGPT. Due to improper parsing of JSON data using…
CVE-2026-75062: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in the default lf.query Python protocol in Google…
CVE-2026-39932 — CVSS 9.1 (critical): OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php…
CVE-2026-28370 — CVSS 9.1 (critical): In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger…
CVE-2025-27603 — CVSS 9.1 (critical): XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. A user that doesn't have programming…
CVE-2024-8512 — CVSS 9.1 (critical): The W3SPEEDSTER plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.26 via the 'script'…
CVE-2026-45406 — CVSS 9.0 (critical): Dokku is a docker-powered PaaS. Prior to 0.38.2, the openresty-vhosts plugin copies files from an app's openresty/http-includes/ git…
CVE-2025-4318: The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation. This could…
CVE-2026-19780 — CVSS 8.8 (high): Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on…
CVE-2026-82789 — CVSS 8.8 (high): An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI System(CHS). If…