Skip to main content

CWE archive

CWE-95 CVEs

Programmatic archive

152 CVEs tagged with CWE-9570 Critical, 59 High, 20 Medium, 3 Low, 0 Unrated.

CVE-2026-55415

Published Jul 28, 2026

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. F…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-45293

Published Jul 28, 2026

WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.14.1 until 3.4.1, the WordPress.WP.EnqueuedResourceParamete…

CVSS 8.6 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-61511

Published Jul 27, 2026

vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows u…

CVSS 9.3 · Critical
evidence mentions
7
Buzz score
40.3

CVE-2025-71408

Published Jul 24, 2026

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arg…

CVSS 8.5 · High
evidence mentions
5
Buzz score
25.9

CVE-2026-47391

Published Jul 21, 2026

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an unauthenticated A2A JSON-RPC endpoint and registers a `calc…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-64193

Published Jul 20, 2026

Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field of an…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
32.6

CVE-2026-40187

Published Jul 20, 2026

In egroupware version 26.0 and earlier, an authenticated administrator can achieve OS-level Remote Code Execution (RCE) by uploading a malicious eTemplate XML file (`.xet`) to the…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-46562

Published Jul 16, 2026

Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algo…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-14380

Published Jul 7, 2026

DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it in…

CVSS 8.8 · High
evidence mentions
5
Buzz score
34.4
Vendor/product tagsBeta · best-effort

CVE-2026-45406

Published Jun 26, 2026

Dokku is a docker-powered PaaS. Prior to 0.38.2, the openresty-vhosts plugin copies files from an app's openresty/http-includes/ git repository directory to the host and then inte…

CVSS 9.0 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-71361

Published Jun 24, 2026

picklescan before 0.0.29 fails to detect malicious idlelib.calltip.Calltip.fetch_tip calls in pickle files, allowing remote code execution. Attackers can embed undetected payloads…

CVSS 7.6 · High

CVE-2026-44939

Published Jun 19, 2026

A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-53875

Published Jun 17, 2026

picklescan before 1.0.3 contains a scanning bypass vulnerability in the scan_pytorch function that allows attackers to embed malicious magic numbers via dynamic eval using the __r…

CVSS 7.1 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-47103

Published Jun 17, 2026

Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary code by supplying malicious SCXML documen…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-52858

Published Jun 11, 2026

Vim is an open source, command line text editor. Prior to version 9.2.0561, the Python omni-completion script in python3complete.vim for Vim with the +python3 interpreter enabled…

CVSS 7.3 · High
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-47167

Published Jun 11, 2026

Vim is an open source, command line text editor. Prior to version 9.2.0496, a code injection vulnerability exists in s:stepmatch() in the cucumber filetype plugin (runtime/ftplugi…

CVSS 5.1 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-11422

Published Jun 5, 2026

Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability in the WaveDrom rendering pipeline that allows attackers to execute arbitrary…

CVSS 8.4 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-50733

Published Jun 5, 2026

Markdown Preview Enhanced before 0.8.28 parses WaveDrom diagrams by evaluating untrusted markdown content with eval(), allowing arbitrary JavaScript execution. The flaw affects ev…

CVSS 8.6 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-8914

Published Jun 5, 2026

In Teltonika Networks RUTOS devices, running versions 7.22 through 7.23.2 and TSWOS devices running versions 1.09 through 1.09.1, due to unsafe calls to an eval function in rpc-pr…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-48962

Published May 27, 2026

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied ou…

CVSS 7.3 · High
evidence mentions
19
Buzz score
50.0

CVE-2026-46586

Published May 19, 2026

Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability in Apache OFBiz. T…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-42603

Published May 11, 2026

OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Prior to 2.1.2, .github/workflows/pre-commit-fix.yaml…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-31254

Published May 11, 2026

The flash-attention project thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains a code injection vulnerability (CWE-94) in its training script. The script r…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44643

Published May 11, 2026

Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to 1.5.2, an attacker can write a malicious expression using filters that e…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44128

Published May 8, 2026

SEPPmail Secure Email Gateway before version 15.0.2.1 allows unauthenticated remote code execution in the new GINA UI because an endpoint passes attacker-controlled input from a p…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0
Showing 1-25 of 152 CVEsPage 1 of 7