CWE-913— Improper Control of Dynamically-Managed Code Resources
The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.— MITRE CWE catalog
114 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-913page 2 of 3
- CVE-2024-7297HIGHCVSS 8.8EG 8.82024-07-30
Langflow versions prior to 1.0.13 suffer from a Privilege Escalation vulnerability, allowing a remote and low privileged attacker to gain super admin privileges by performing a mass assignment request on the '/api/v1/users' endpoint.
- CVE-2022-3225HIGHCVSS 8.8EG 8.82022-09-16
Improper Control of Dynamically-Managed Code Resources in GitHub repository budibase/budibase prior to 1.3.20.
- CVE-2022-39051HIGHCVSS 6.8EG 8.82022-09-05
Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverified 3th party package
- CVE-2025-13426HIGHCVSS 8.7EG 8.72025-12-05
A vulnerability exists in Google Apigee's JavaCallout policy https://docs.apigee.com/api-platform/reference/policies/java-callout-policy that allows for remote code execution. It is possible for a user to write a JavaCallout that inject…
- CVE-2022-31764HIGHCVSS 8.5EG 8.52025-02-06
The Lite UI of Apache ShardingSphere ElasticJob-UI allows an attacker to perform RCE by constructing a special JDBC URL of H2 database. This issue affects Apache ShardingSphere ElasticJob-UI version 3.0.1 and prior versions. This vulnerabi…
- CVE-2024-27135HIGHCVSS 8.5EG 8.52024-03-12
Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function worker, outside of the sandboxes designated for running user-provided functions. This vulne…
- CVE-2023-37271HIGHCVSS 8.4EG 8.42023-07-11
RestrictedPython is a tool that helps to define a subset of the Python language which allows users to provide a program input into a trusted environment. RestrictedPython does not check access to stack frames and their attributes. Stack fr…
- CVE-2026-48105HIGHCVSS 8.3EG 8.32026-08-21
Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's Raft FSM (`internal/cluster/raft/fsm.go:applyRegisterFile`) accepts attacker-chosen file paths in manifest-registration proposals wit…
- CVE-2023-25560HIGHCVSS 8.2EG 8.22023-02-11
DataHub is an open-source metadata platform. The AuthServiceClient which is responsible for creation of new accounts, verifying credentials, resetting them or requesting access tokens, crafts multiple JSON strings using format strings with…
- CVE-2026-65181HIGHCVSS 8.1EG 8.12026-09-09
Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a client with privileges to upload a file to remote storage and create a table to execute arbitrary Java code. Users are recommended to upgrade to version 4.5.2, whi…
- CVE-2022-43441HIGHCVSS 8.1EG 8.12023-03-16
A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1. A specially-crafted Javascript file can lead to arbitrary code execution. An attacker can provide malicious input to trig…
- CVE-2017-3200HIGHCVSS 8.1EG 8.12018-06-11
The Java implementation of AMF3 deserializers used in GraniteDS, version 3.1.1.G, may allow instantiation of arbitrary classes via their public parameter-less constructor and subsequently call arbitrary Java Beans setter methods. The abili…
- CVE-2022-2625HIGHCVSS 8.0EG 8.02022-08-18
A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and…
- CVE-2021-21413HIGHCVSS 8.0EG 8.02021-03-30
isolated-vm is a library for nodejs which gives you access to v8's Isolate interface. Versions of isolated-vm before v4.0.0 have API pitfalls which may make it easy for implementers to expose supposed secure isolates to the permissions of …
- CVE-2025-54065HIGHCVSS 7.9EG 7.92025-12-03
GZDoom is a feature centric port for all Doom engine games. GZDoom is an open source Doom engine. In versions 4.14.2 and earlier, ZScript actor state handling allows scripts to read arbitrary addresses, write constants into the JIT-compile…
- CVE-2022-4318HIGHCVSS 7.8EG 7.82023-09-25
A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.
- CVE-2022-25265HIGHCVSS 7.8EG 7.82022-02-16
In the Linux kernel through 5.16.10, certain binary files may have the exec-all attribute if they were built in approximately 2003 (e.g., with GCC 3.2.2 and Linux kernel 2.4.20). This can cause execution of bytes located in supposedly non-…
- CVE-2021-23267HIGHCVSS 7.6EG 7.62022-05-16
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker static methods.
- CVE-2026-12354HIGHCVSS 7.5EG 7.52026-09-15
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to ex…
- CVE-2025-31674HIGHCVSS 7.5EG 7.52025-03-31
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 be…
- CVE-2023-31032HIGHCVSS 7.5EG 7.52024-01-12
NVIDIA DGX A100 SBIOS contains a vulnerability where a user may cause a dynamic variable evaluation by local access. A successful exploit of this vulnerability may lead to denial of service.
- CVE-2012-2055HIGHCVSS 7.5EG 7.52012-04-05
GitHub Enterprise before 20120304 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the public_key[user_id] value via a modified URL for the public-key update form…
- CVE-2019-1617HIGHCVSS 7.4EG 7.42019-03-11
A vulnerability in the Fibre Channel over Ethernet (FCoE) N-port Virtualization (NPV) protocol implementation in Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulne…
- CVE-2019-1595HIGHCVSS 7.4EG 7.42019-03-06
A vulnerability in the Fibre Channel over Ethernet (FCoE) protocol implementation in Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerabili…
- CVE-2025-9905HIGHCVSS 7.3EG 7.32025-09-19
The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One can create a specially crafted .h5/.hdf5 model archive that, when loaded via Model.load_model, will trigger arbitrary …
- CVE-2026-48775MEDIUMCVSS 6.8EG 6.82026-06-16
LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 4.1.0 and prior, the JsonPlusSerializer can reconstruct Python objects from JSON checkpoint…
- CVE-2021-42809MEDIUMCVSS 6.5EG 6.52021-12-20
Improper Access Control of Dynamically-Managed Code Resources (DLL) in Thales Sentinel Protection Installer could allow the execution of arbitrary code.
- CVE-2020-3419MEDIUMCVSS 6.5EG 6.52020-11-18
A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to join a Webex session without appearing on the participant list. This vulnerability is due to improper handling of au…
- CVE-2020-1097MEDIUMCVSS 6.5EG 6.52020-09-11
<p>An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a use…
- CVE-2020-1091MEDIUMCVSS 6.5EG 6.52020-09-11
<p>An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a use…
- CVE-2019-15006MEDIUMCVSS 6.5EG 6.52019-12-19
There was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in Confluence Server and Confluence Data Center. This plugin was used to facilitate communication with the Atlassian Companion application. The Co…
- CVE-2022-40635MEDIUMCVSS 6.4EG 6.42022-09-13
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass.
- CVE-2022-40634MEDIUMCVSS 6.4EG 6.42022-09-13
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker SSTI.
- CVE-2026-105180MEDIUMCVSS 6.3EG 6.32026-10-05
A vulnerability was determined in Jeebase 0.0.1. This vulnerability affects the function updateUser of the file /user/update/info of the component UserService. Executing a manipulation of the argument user/tempUser can lead to dynamically-…
- CVE-2026-92217MEDIUMCVSS 6.3EG 6.32026-09-16
A vulnerability was determined in a2ui-project a2ui up to 0.10.6. This affects the function processMessages of the file renderers/web_core/src/v0_9/processing/message-processor.ts of the component Message Parsing. This manipulation causes …
- CVE-2026-84430MEDIUMCVSS 6.3EG 6.32026-09-02
A security vulnerability has been detected in gouguoa up to 5.10.0/6.0.1. This vulnerability affects the function update of the file app/home/controller/Index.php of the component edit_personal Endpoint. Such manipulation of the argument p…
- CVE-2026-5251MEDIUMCVSS 6.3EG 6.32026-04-01
A vulnerability was identified in z-9527 admin 1.0/2.0. This impacts an unknown function of the file /server/routes/user.js of the component User Update Endpoint. Such manipulation of the argument isAdmin with the input 1 leads to dynamica…
- CVE-2026-5248MEDIUMCVSS 6.3EG 6.32026-04-01
A vulnerability has been found in gougucms 4.08.18. This affects the function reg_submit of the file gougucms-master\app\home\controller\Login.php of the component User Registration Handler. Such manipulation of the argument level leads to…
- CVE-2025-14695MEDIUMCVSS 6.3EG 6.32025-12-15
A vulnerability was determined in SamuNatsu HaloBot up to 026b01d4a896d93eaaf9d5163a287dc9f267515b. Affected is the function html_renderer of the file plugins/html_renderer/index.js of the component Inter-plugin API. Executing manipulation…
- CVE-2025-14085MEDIUMCVSS 6.3EG 6.32025-12-05
A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. This impacts an unknown function of the file /app-api/v1/orders/. The manipulation of the argument orderId leads to improper control of dynamically-identified variables.…
- CVE-2025-14051MEDIUMCVSS 6.3EG 6.32025-12-04
A flaw has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function getById/updateAddress/deleteAddress of the file /mall-ums/app-api/v1/addresses/. Executing manipulation can lead to improper control of dynamically-ident…
- CVE-2023-6184MEDIUMCVSS 5.0EG 6.22024-01-18
Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting
- CVE-2018-19836MEDIUMCVSS 6.1EG 6.12018-12-03
In Metinfo 6.1.3, include/interface/applogin.php allows setting arbitrary HTTP headers (including the Cookie header), and common.inc.php allows registering variables from the $_COOKIE value. This issue can, for example, be exploited in con…
- CVE-2025-26405MEDIUMCVSS 5.9EG 5.92025-11-11
Improper control of dynamically-managed code resources for some Intel(R) NPU Drivers within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity …
- CVE-2020-15372MEDIUMCVSS 5.5EG 5.52020-09-25
A vulnerability in the command-line interface in Brocade Fabric OS before Brocade Fabric OS v8.2.2a1, 8.2.2c, v7.4.2g, v8.2.0_CBN3, v8.2.1e, v8.1.2k, v9.0.0, could allow a local authenticated attacker to modify shell variables, which may l…
- CVE-2025-61780MEDIUMCVSS 5.3EG 5.32025-10-10
Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, a possible information disclosure vulnerability existed in `Rack::Sendfile` when running behind a proxy that supports `x-sendfile` headers (such as N…
- CVE-2025-6705MEDIUMCVSS 5.3EG 5.32025-06-27
A vulnerability in the Eclipse Open VSX Registry’s automated publishing system could have allowed unauthorized uploads of extensions. Specifically, the system’s build scripts were executed without proper isolation, potentially exposing…
- CVE-2023-39983MEDIUMCVSS 5.3EG 5.32023-09-02
A vulnerability that poses a potential risk of polluting the MXsecurity sqlite database and the nsm-web UI has been identified in MXsecurity versions prior to v1.0.1. This vulnerability might allow an unauthenticated remote attacker to reg…
- CVE-2022-25355MEDIUMCVSS 5.3EG 5.32022-02-24
EC-CUBE 3.0.0 to 3.0.18-p3 and EC-CUBE 4.0.0 to 4.1.1 improperly handle HTTP Host header values, which may lead a remote unauthenticated attacker to direct the vulnerable version of EC-CUBE to send an Email with some forged reissue-passwor…
- CVE-2021-26276MEDIUMCVSS 5.3EG 5.32021-01-27
scripts/cli.js in the GoDaddy node-config-shield (aka Config Shield) package before 0.2.2 for Node.js calls eval when processing a set command. NOTE: the vendor reportedly states that this is not a vulnerability. The set command was not in…
Map vulnerabilities like CWE-913 to your infrastructure
EchelonGraph correlates every CVE — across CWE-913 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →