CWE-95
Medium likelihoodImproper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. "eval").
138 vulnerabilities with CWE-95
CVE-2026-52858
HIGH
Vim: Arbitrary Code Execution via Python Omni-Completion
CVSS 7.8
CVE-2026-47167
MEDIUM
Vim: Vimscript Code Injection in cucumber filetype plugin via crafted step-definition regex
CVSS 5.3
CVE-2026-11422
HIGH
Markdown Preview Enhanced 0.8.x Code Injection via WaveDrom Rendering
CVSS 7.1
CVE-2026-50733
HIGH
Markdown Preview Enhanced Arbitrary Code Execution via WaveDrom eval()
CVSS 8.8
CVE-2026-8914
HIGH
Teltonika Networks RUTOS - Command Injection in Profile Change Function
CVE-2026-48962
HIGH
IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob
CVSS 7.3
CVE-2026-46586
HIGH
Apache OFBiz: Improper Validation in traverseContent Service Enables Authenticated Groovy Code Execution
CVSS 8.8
CVE-2026-42603
HIGH
OWASP BLT: pre-commit-fix.yaml executes untrusted fork code via pull_request_target
CVSS 8.8
CVE-2026-31254
HIGH
flash-attention thru e724e2588 - Code Injection
CVSS 7.3
CVE-2026-44643
CRITICAL
Angular Expressions - Remote Code Execution using filters
CVSS 10.0
CVE-2026-44128
CRITICAL
SEPPmail Secure Email Gateway < 15.0.2.1 - Unauthenticated Remote Code Execution via Perl Eval Injection
CVE-2026-42079
HIGH
PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated Code with Builtins in Scope
CVSS 8.6
CVE-2026-6652
MEDIUM
Pagekit CMS StringStorage Template PhpEngine.php evaluate eval injection
CVSS 4.7
CVE-2026-40316
HIGH
OWASP BLT has RCE in Github Actions via untrusted Django model execution in workflow
CVSS 8.8
CVE-2026-39423
MEDIUM
Stored XSS via Eval Injection in EchartsRander Component
CVSS 5.4
CVE-2026-33618
HIGH
Chamilo LMS Affected by Remote Code Execution via eval() in Platform Settings
CVSS 8.8
CVE-2026-5971
HIGH
FoundationAgents MetaGPT XML action_node.py ActionNode.xml_fill eval injection
CVSS 7.3
CVE-2026-4837
MEDIUM
Eval Injection in Rapid7 Insight Agent
CVSS 6.6
CVE-2026-22666
HIGH
Dolibarr ERP/CRM < 23.0.2 Authenticated RCE via dol_eval_standard()
CVSS 7.2
CVE-2026-35002
CRITICAL
Agno < 2.3.24 field_type Eval Injection Arbitrary Code Execution
CVSS 9.8
CVE-2026-28505
CRITICAL
Tautulli: RCE via eval() sandbox bypass using lambda nested scope to escape co_names whitelist check
CVSS 10.0
CVE-2026-4851
CRITICAL
GRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe deserialization
CVSS 9.8
CVE-2026-4965
HIGH
letta-ai letta Incomplete Fix CVE-2025-6101 ast_parsers.py resolve_type eval injection
CVSS 7.3
CVE-2026-4001
CRITICAL
Woocommerce Custom Product Addons Pro <=5.4.1 - RCE
CVSS 9.8
CVE-2026-33017
CRITICAL
KEV
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
CVSS 9.8
Details
Vulnerabilities
138
Exploit Likelihood
Medium