boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-95

Weakness type CWE-95 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
44430

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▄▄█

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 1 · 2026-06 10 · 2026-07 10 · 2026-08 21

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-615119.375.6vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
CVE-2026-449399.467.7Command injection through unsanitized YAML parameter in Rancher
CVE-2026-471039.365.0Python StateMachine 3.0.0 < 3.2.0 RCE via SCXML eval() Injection
CVE-2026-671958.764.5Perspective 5.0.0 RCE via eval() Expression Injection
CVE-2025-43189.058.0Input validation issue in AWS Amplify Studio UI component properties
CVE-2026-401878.657.9Authenticated RCE via Malicious eTemplate Upload in EGroupware
CVE-2025-311149.356.2Fooocus webui vulnerable to Remote Code Execution
CVE-2026-350029.355.1Agno < 2.3.24 field_type Eval Injection Arbitrary Code Execution
CVE-2026-641939.854.7Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTEN…
CVE-2026-196269.453.4Remote Code Execution
CVE-2026-465629.853.1Yamcs: Remote Code Execution via Mission Database algorithm override
CVE-2026-473919.853.1PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` too…
CVE-2026-399329.452.9OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection
CVE-2026-736019.046.4Flowise before 3.1.3 Remote Code Execution via Custom MCP
CVE-2026-692649.445.1Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python s…
CVE-2026-89148.443.2Command injection in Profile change function
CVE-2026-483179.639.9Adobe Campaign Classic (ACC) | Improper Neutralization of Directives in Dynamically Eva…
CVE-2026-143808.839.5DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenc…
CVE-2026-130488.239.2Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message cata…
CVE-2026-736029.036.6Flowise before 3.1.3 Sandbox Escape to RCE

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
flowiseai4
orval-labs4
freecad2
picklescan2
shd101wyy2
vim2
adobe1
agno1
amazon1
dokku1
egroupware1
faker-js1
fgmacedo1
firecrawl1
hmbrand1