Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-95'

View all threats tagged with 'cwe-95'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-95

Threats Tagged 'cwe-95'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-44939: CWE-95 Improper neutralization of directives in dynamically evaluated code ('eval injection') in SUSE RancherCVE-2026-44939
0

A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to break out of an image, and execute e.g. malicious containers.

Join the discussion
CVE-2026-11422: CWE-95 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in shd101wyy Markdown Preview EnhancedCVE-2026-11422
0

Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability in the WaveDrom rendering pipeline that allows attackers to execute arbitrary JavaScript by embedding malicious content in a wavedrom fenced code block within a crafted Markdown document. Attackers can exploit the unsanitized passing of wavedrom block content to window.eval() in the VS Code webview context to abuse the extension's message passing and invoke arbitrary file writes on the local filesystem.

Join the discussion
CVE-2026-8914: CWE-95 Improper neutralization of directives in dynamically evaluated code ('eval injection') in Teltonika Networks RUTOSCVE-2026-8914
0

In Teltonika Networks RUTOS devices, running versions 7.22 through 7.23.2 and TSWOS devices running versions 1.09 through 1.09.1, due to unsafe calls to an eval function in rpc-profile, a vulnerability exists where a lower privileged user could perform command injection as the root user.

Join the discussion
CVE-2026-48962: CWE-95 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in PMQS IO::CompressCVE-2026-48962
0

CVE-2026-48962 is a high-severity vulnerability in the PMQS IO::Compress Perl module before version 2.220. It allows an attacker to execute arbitrary Perl code via a specially crafted output glob string in File::GlobMapper. This occurs because the output glob is wrapped in double quotes and evaluated with Perl's eval function without proper sanitization, enabling code injection. The vulnerability can lead to arbitrary code execution with the privileges of the calling process.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Tag: cwe-95
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses