Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-95 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 44 | 43 | 0 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▄▄█
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 1 · 2026-06 10 · 2026-07 10 · 2026-08 21
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-61511 | 9.3 | 75.6 | — | vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php |
| CVE-2026-44939 | 9.4 | 67.7 | — | Command injection through unsanitized YAML parameter in Rancher |
| CVE-2026-47103 | 9.3 | 65.0 | — | Python StateMachine 3.0.0 < 3.2.0 RCE via SCXML eval() Injection |
| CVE-2026-67195 | 8.7 | 64.5 | — | Perspective 5.0.0 RCE via eval() Expression Injection |
| CVE-2025-4318 | 9.0 | 58.0 | — | Input validation issue in AWS Amplify Studio UI component properties |
| CVE-2026-40187 | 8.6 | 57.9 | — | Authenticated RCE via Malicious eTemplate Upload in EGroupware |
| CVE-2025-31114 | 9.3 | 56.2 | — | Fooocus webui vulnerable to Remote Code Execution |
| CVE-2026-35002 | 9.3 | 55.1 | — | Agno < 2.3.24 field_type Eval Injection Arbitrary Code Execution |
| CVE-2026-64193 | 9.8 | 54.7 | — | Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTEN… |
| CVE-2026-19626 | 9.4 | 53.4 | — | Remote Code Execution |
| CVE-2026-46562 | 9.8 | 53.1 | — | Yamcs: Remote Code Execution via Mission Database algorithm override |
| CVE-2026-47391 | 9.8 | 53.1 | — | PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` too… |
| CVE-2026-39932 | 9.4 | 52.9 | — | OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection |
| CVE-2026-73601 | 9.0 | 46.4 | — | Flowise before 3.1.3 Remote Code Execution via Custom MCP |
| CVE-2026-69264 | 9.4 | 45.1 | — | Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python s… |
| CVE-2026-8914 | 8.4 | 43.2 | — | Command injection in Profile change function |
| CVE-2026-48317 | 9.6 | 39.9 | — | Adobe Campaign Classic (ACC) | Improper Neutralization of Directives in Dynamically Eva… |
| CVE-2026-14380 | 8.8 | 39.5 | — | DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenc… |
| CVE-2026-13048 | 8.2 | 39.2 | — | Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message cata… |
| CVE-2026-73602 | 9.0 | 36.6 | — | Flowise before 3.1.3 Sandbox Escape to RCE |
| Vendor | CVEs |
|---|---|
| flowiseai | 4 |
| orval-labs | 4 |
| freecad | 2 |
| picklescan | 2 |
| shd101wyy | 2 |
| vim | 2 |
| adobe | 1 |
| agno | 1 |
| amazon | 1 |
| dokku | 1 |
| egroupware | 1 |
| faker-js | 1 |
| fgmacedo | 1 |
| firecrawl | 1 |
| hmbrand | 1 |