boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-95

Weakness type CWE-95 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
77734

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▄▄█▇▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 1 · 2026-05 1 · 2026-06 10 · 2026-07 10 · 2026-08 27 · 2026-09 23 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-248939.8100.0KEVRemote code execution as guest via SolrSearchMacros request in xwiki
CVE-2024-364019.8100.0KEVRemote Code Execution (RCE) vulnerability in evaluating property name expressions in Ge…
CVE-2026-330179.397.8KEVLangflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
CVE-2023-71017.897.2KEVArbitrary Code Execution (ACE) Vulnerability
CVE-2026-615119.392.7—vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
CVE-2026-192959.988.0—Langflow is affected by multiple remote code execution vulnerabilities due to insuffici…
CVE-2026-399329.480.1—OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection
CVE-2026-196269.478.4—Remote Code Execution
CVE-2026-1007419.876.8—Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') …
CVE-2026-641939.872.3—Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTEN…
CVE-2026-471039.371.0—Python StateMachine 3.0.0 < 3.2.0 RCE via SCXML eval() Injection
CVE-2026-449399.469.7—Command injection through unsanitized YAML parameter in Rancher
CVE-2026-482739.968.8—ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval…
CVE-2026-6153910.067.8—Xinference: Remote code execution via unsafe `eval()` in Llama3 tool-call parsing
CVE-2026-616679.967.5—DIRAC: RCE in FileCatalog DatasetManager via SQL injection + eval
CVE-2026-671958.767.0—Perspective 5.0.0 RCE via eval() Expression Injection
CVE-2026-473919.866.2—PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` too…
CVE-2026-545699.865.9—SENAITE.CORE: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eva…
CVE-2026-350029.365.8—Agno < 2.3.24 field_type Eval Injection Arbitrary Code Execution
CVE-2026-692649.464.8—Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python s…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
flowiseai4
orval-labs4
adobe3
diracgrid2
freecad2
langflow-ai2
picklescan2
project-monai2
shd101wyy2
vim2
xwiki2
agno1
amazon1
apache1
aws1