Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-95

Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. "eval").

148
Assigned CVEs
145th
Commonality Rank
8.5
Avg CVSS
2.7%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-95 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 23, 2020
6 years ago
Most Recent CVE
Jul 21, 2026
3 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

148 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-33017CRITICAL
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building
Mar 20, 20269.899YESYES
CVE-2025-24893CRITICAL
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to
Feb 20, 20259.899YESYES
CVE-2024-36401CRITICAL
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple OGC request parameters allow
Jul 1, 20249.898YESYES
CVE-2024-7954CRITICAL
The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can exe
Aug 23, 20249.889NOYES
CVE-2024-21650CRITICAL
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to a remote code execution (RCE) attack through its use
Jan 8, 20249.883NOYES
CVE-2023-7101HIGH
Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to
Dec 24, 20237.881YESYES
CVE-2024-36404CRITICAL
GeoTools is an open source Java library that provides tools for geospatial data. Prior to versions 31.2, 30.4, and 29.6, Remote Code Execution (RCE) is possible if an application u
Jul 2, 20249.880NOYES
CVE-2023-37462HIGH
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Improper escaping in the document `SkinsCode.XWikiSkinsSheet` leads to an i
Jul 14, 20238.880NOYES
CVE-2023-46731CRITICAL
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki doesn't properly escape the section URL parameter that is used in the
Nov 6, 20239.878NONO
CVE-2023-35150HIGH
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.40m-2 and prior to versions 14.4.8, 14.10.4, and 15.0
Jun 23, 20238.070NONO
View all 148 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
19%
5.0-5.9
16%
6.0-6.9
16%
26%
7.0-7.9
36%
11%
8.0-8.9
37%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
4 CVEs
2.7% of CVEs· 96th percentile
Metasploit
6 CVEs
4.1% of CVEs· 96th percentile
Nuclei
9 CVEs
6.1% of CVEs· 96th percentile
ExploitDB
4 CVEs
2.7% of CVEs· 91st percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products