📦

perl

Vendor: larry_wall

Actively Exploited 0 CISA KEV List
PoC / Exploits 11 Code Available
Total RCEs 6 Remote Access
Total CVEs 25 Total Indexed
Avg. EPSS 4.47% Exploit Prob.
Latest CVE CVE-2026-57432 Jul 13

Security Vulnerability Index

Page 2 / 3
7.8 CVSS

Encode.pm, as distributed in Perl through 5.34.0, allows local users to gain privileges via a Trojan horse Encode::ConfigLocal library (in the current working directory) that preempts dynamic module loading. Exploitation requires an unusual configuration, and certain 2021 versions of Encode.pm (3.05 through 3.11). This issue occurs because the || operator evaluates @INC in a scalar context, and thus @INC has only an integer value.

EPSS: 1.40%
7.5 CVSS

regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls.

EPSS: 5.97%
8.6 CVSS

Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection.

EPSS: 4.88%
8.2 CVSS

Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.

EPSS: 11.33%
9.8 CVSS

Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations.

EPSS: 6.06%
9.1 CVSS

Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory.

EPSS: 9.52%
9.8 CVSS

Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.

EPSS: 11.68%
9.8 CVSS

Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.

EPSS: 12.09%
7.5 CVSS

In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.

EPSS: 7.34%
9.8 CVSS

Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbitrary code via a large item count.

EPSS: 10.87%