Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-95
Weakness type CWE-95 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 77 | 73 | 4 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▄▄█▇▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 1 · 2026-05 1 · 2026-06 10 · 2026-07 10 · 2026-08 27 · 2026-09 23 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-24893 | 9.8 | 100.0 | KEV | Remote code execution as guest via SolrSearchMacros request in xwiki |
| CVE-2024-36401 | 9.8 | 100.0 | KEV | Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Ge… |
| CVE-2026-33017 | 9.3 | 97.8 | KEV | Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint |
| CVE-2023-7101 | 7.8 | 97.2 | KEV | Arbitrary Code Execution (ACE) Vulnerability |
| CVE-2026-61511 | 9.3 | 92.7 | — | vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php |
| CVE-2026-19295 | 9.9 | 88.0 | — | Langflow is affected by multiple remote code execution vulnerabilities due to insuffici… |
| CVE-2026-39932 | 9.4 | 80.1 | — | OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection |
| CVE-2026-19626 | 9.4 | 78.4 | — | Remote Code Execution |
| CVE-2026-100741 | 9.8 | 76.8 | — | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') … |
| CVE-2026-64193 | 9.8 | 72.3 | — | Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTEN… |
| CVE-2026-47103 | 9.3 | 71.0 | — | Python StateMachine 3.0.0 < 3.2.0 RCE via SCXML eval() Injection |
| CVE-2026-44939 | 9.4 | 69.7 | — | Command injection through unsanitized YAML parameter in Rancher |
| CVE-2026-48273 | 9.9 | 68.8 | — | ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval… |
| CVE-2026-61539 | 10.0 | 67.8 | — | Xinference: Remote code execution via unsafe `eval()` in Llama3 tool-call parsing |
| CVE-2026-61667 | 9.9 | 67.5 | — | DIRAC: RCE in FileCatalog DatasetManager via SQL injection + eval |
| CVE-2026-67195 | 8.7 | 67.0 | — | Perspective 5.0.0 RCE via eval() Expression Injection |
| CVE-2026-47391 | 9.8 | 66.2 | — | PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` too… |
| CVE-2026-54569 | 9.8 | 65.9 | — | SENAITE.CORE: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eva… |
| CVE-2026-35002 | 9.3 | 65.8 | — | Agno < 2.3.24 field_type Eval Injection Arbitrary Code Execution |
| CVE-2026-69264 | 9.4 | 64.8 | — | Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python s… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| flowiseai | 4 |
| orval-labs | 4 |
| adobe | 3 |
| diracgrid | 2 |
| freecad | 2 |
| langflow-ai | 2 |
| picklescan | 2 |
| project-monai | 2 |
| shd101wyy | 2 |
| vim | 2 |
| xwiki | 2 |
| agno | 1 |
| amazon | 1 |
| apache | 1 |
| aws | 1 |