CWE-95

Medium likelihood

Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')

Parent: CWE-94 - Improper Control of Generation of Code ('Code Injection')

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. "eval").

126 vulnerabilities with CWE-95
CVE-2024-32649 MEDIUM
Vyper <0.3.10 - Code Injection
CVSS 5.3
CVE-2024-32647 MEDIUM
Vyper <0.3.10 - Code Injection
CVSS 5.3
CVE-2024-31996 CRITICAL
XWiki Platform <4.10.19, <15.5.4, <15.10-rc-1 - RCE
CVSS 10.0
CVE-2024-31986 CRITICAL
XWiki Platform <4.10.19-15.10-rc-1 - RCE
CVSS 9.0
CVE-2024-31984 CRITICAL
XWiki Platform <4.10.20, 15.5.4, 15.10-rc-1 - RCE
CVSS 9.9
CVE-2024-31982 CRITICAL
XWiki Platform <4.10.20,15.5.4,15.10-rc-1 - RCE
CVSS 10.0
CVE-2024-31465 CRITICAL
Xwiki < 14.10.20 - Code Injection
CVSS 9.9
CVE-2024-21650 CRITICAL
XWiki < 4.10.20 - Remote code execution
CVSS 10.0
CVE-2023-26323 HIGH
Xiaomi App Market - RCE
CVSS 7.6
CVE-2023-7245 HIGH
OpenVPN Connect <3.4.3/3.4.7 - RCE
CVSS 7.8
CVE-2023-50447 HIGH
Python Pillow < 10.1.0 - Code Injection
CVSS 8.1
CVE-2023-6735 HIGH
Checkmk < 2.0.0 - Improper Privilege Management
CVSS 8.8
CVE-2023-7224 HIGH
Openvpn Connect < 3.4.6 - Code Injection
CVSS 7.8
CVE-2023-7101 HIGH KEV
Jmcnamara Spreadsheet < 0.65 - Code Injection
CVSS 7.8
CVE-2023-50723 CRITICAL
Xwiki < 14.10.5 - Code Injection
CVSS 9.9
CVE-2023-50721 CRITICAL
Xwiki < 14.10.5 - Code Injection
CVSS 9.9
CVE-2023-48699 HIGH
fastbots <0.1.5 - RCE
CVSS 8.4
CVE-2023-46731 CRITICAL
XWiki Platform - Code Injection
CVSS 10.0
CVE-2023-37909 CRITICAL
Xwiki < 14.10.8 - Code Injection
CVSS 9.9
CVE-2023-40177 CRITICAL
Xwiki < 14.10.5 - Code Injection
CVSS 9.9
CVE-2023-37462 CRITICAL
Xwiki < 14.4.8 - Injection
CVSS 9.9
CVE-2023-35152 CRITICAL
Xwiki < 14.4.8 - Code Injection
CVSS 9.9
CVE-2023-35150 CRITICAL
Xwiki < 14.4.8 - Code Injection
CVSS 9.9
CVE-2023-30537 CRITICAL
Xwiki < 13.10.11 - Code Injection
CVSS 9.9
CVE-2023-29511 CRITICAL
XWiki Platform - RCE
CVSS 9.9
Details
Vulnerabilities 126
Exploit Likelihood Medium