OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems.
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the str_eval() f
Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to 1.5.2, an att
Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference
n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressi
Budibase is a low code platform for creating internal tools, workflows, and admin panels. Prior to version 3.30.4, an un
A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authentica
In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties i
IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in
Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability. This vulnerability allows remote
Chamilo is a learning management system. Prior to version 1.11.28, parameter from SOAP request is evaluated without filt
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api
The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up
GRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe deserialization. GRID::Machine
Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that al
Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to
Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScrip
Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EX
PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::
SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when D
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Pyth
SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SE
Affected devices do not properly sanitize contents of trace files. This could allow an attacker to inject code throug
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eva
In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage
OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/cl
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, a second-order expres
Dokku is a docker-powered PaaS. Prior to 0.38.2, the openresty-vhosts plugin copies files from an app's openresty/http-i
Chamilo LMS is a learning management system. Prior to .0.0-RC.3, the PlatformConfigurationController::decodeSettingArray
OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and m
OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and m
Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluate
Markdown Preview Enhanced before 0.8.28 parses WaveDrom diagrams by evaluating untrusted markdown content with eval(), a
DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is ass
Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitr
PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable t
WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.
Using string formatting and exception handling, an attacker may bypass n8n's python-task-executor sandbox restrictions a
Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitra
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.0, a
picklescan before 0.0.29 fails to detect malicious idlelib.calltip.Calltip.fetch_tip calls in pickle files, allowing rem
Vim is an open source, command line text editor. Prior to version 9.2.0561, the Python omni-completion script in python3
NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations m
Faker generates massive amounts of fake data in the browser and Node.js. Prior to 10.5.0, the faker.helpers.fake method
FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, src/Mod/BIM/bimcommands/Bi
FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, FreeCAD's BIM Workbench co
@cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary J
chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/ken
Legora before 2026-08-14 contains a cross-site scripting vulnerability that allows attackers to achieve arbitrary JavaSc
Frequently Asked Questions
What is CWE-95?
CWE-95 (CWE-95) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-95?
There are 83 CVE records associated with CWE-95 in our database. Of these, 29 are critical severity, 28 are high severity, and 7 are medium severity.
How can I protect against CWE-95 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-95 using AI-powered security agents.
Detect CWE-95 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-95 vulnerabilities across your infrastructure.
Get Started