CWE-913— Improper Control of Dynamically-Managed Code Resources
The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.— MITRE CWE catalog
114 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-913page 3 of 3
- CVE-2025-46673MEDIUMCVSS 4.9EG 4.92025-04-27
NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space Data Link Security protocol (SDLS).
- CVE-2021-32813MEDIUMCVSS 4.8EG 4.82021-08-03
Traefik is an HTTP reverse proxy and load balancer. Prior to version 2.4.13, there exists a potential header vulnerability in Traefik's handling of the Connection header. Active exploitation of this issue is unlikely, as it requires that a…
- CVE-2026-1770MEDIUMCVSS 4.5EG 4.52026-02-02
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass. By inserting malicious Groovy elements, an attacker may…
- CVE-2024-2537MEDIUMCVSS 4.4EG 4.42024-03-15
Improper Control of Dynamically-Managed Code Resources vulnerability in Logitech Logi Tune on MacOS allows Local Code Inclusion.
- CVE-2020-4100MEDIUMCVSS 4.4EG 4.42020-07-15
"HCL Verse for Android was found to employ dynamic code loading. This mechanism allows a developer to specify which components of the application should not be loaded by default when the application is started. Typically, core components a…
- CVE-2026-85408MEDIUMCVSS 4.3EG 4.32026-09-04
A vulnerability was determined in Eleveo Quality Management 9.7.0. Impacted is an unknown function of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the component Conversation Handler. This manipulation of the argument createdB…
- CVE-2021-23262MEDIUMCVSS 4.2EG 4.22021-12-02
Authenticated administrators may modify the main YAML configuration file and load a Java class resulting in RCE.
- CVE-2021-23259MEDIUMCVSS 4.2EG 4.22021-12-02
Authenticated users with Administrator or Developer roles may execute OS commands by Groovy Script which uses Groovy lib to render a webpage. The groovy script does not have security restrictions, which will cause attackers to execute arbi…
- CVE-2021-23258MEDIUMCVSS 4.2EG 4.22021-12-02
Authenticated users with Administrator or Developer roles may execute OS commands by SPEL Expression in Spring beans. SPEL Expression does not have security restrictions, which will cause attackers to execute arbitrary commands remotely (R…
- CVE-2020-25803MEDIUMCVSS 4.2EG 4.22020-10-06
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker template exposed objects. This issue affects: Crafter Software Craf…
- CVE-2020-25802MEDIUMCVSS 4.2EG 4.22020-10-06
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy scripting. This issue affects: Crafter Software Crafter CMS 3.0 version…
- CVE-2023-35930LOWCVSS 3.7EG 3.72023-06-26
SpiceDB is an open source, Google Zanzibar-inspired, database system for creating and managing security-critical application permissions. Any user making a negative authorization decision based on the results of a `LookupResources` request…
- CVE-2025-46675LOWCVSS 3.5EG 3.52025-04-27
In NASA CryptoLib before 1.3.2, the key state is not checked before use, potentially leading to spacecraft hijacking.
- CVE-2025-6107LOWCVSS 3.1EG 3.12025-06-16
A vulnerability was found in comfyanonymous comfyui 0.3.40. It has been classified as problematic. Affected is the function set_attr of the file /comfy/utils.py. The manipulation leads to dynamically-determined object attributes. It is pos…
Map vulnerabilities like CWE-913 to your infrastructure
EchelonGraph correlates every CVE — across CWE-913 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →