CWE-913
Improper Control of Dynamically-Managed Code Resources
Description
The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.
Hierarchy (View 1000)
CVEs mapped to this weakness (101)
page 4 of 6| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-5763 | Med | 0.44 | 6.8 | 0.01 | Nov 3, 2023 | In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 6u211, or < 7u201, or < 8u191), allows remote attackers to load malicious code on the server via access to insecure ORB listeners. | ||
| CVE-2022-4318 | Hig | 0.44 | 7.8 | 0.00 | Sep 25, 2023 | A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable. | ||
| CVE-2022-39051 | Med | 0.44 | 6.8 | 0.01 | Sep 5, 2022 | Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverified 3th party package | ||
| CVE-2022-40635 | Med | 0.42 | 6.4 | 0.01 | Sep 13, 2022 | Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass. | ||
| CVE-2022-40634 | Med | 0.42 | 6.4 | 0.01 | Sep 13, 2022 | Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker SSTI. | ||
| CVE-2021-42809 | Med | 0.42 | 6.5 | 0.00 | Dec 20, 2021 | Improper Access Control of Dynamically-Managed Code Resources (DLL) in Thales Sentinel Protection Installer could allow the execution of arbitrary code. | ||
| CVE-2021-23448 | Med | 0.42 | 6.5 | 0.01 | Oct 11, 2021 | All versions of package config-handler are vulnerable to Prototype Pollution when loading config files. | ||
| CVE-2020-3419 | Med | 0.42 | 6.5 | 0.02 | Nov 18, 2020 | A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to join a Webex session without appearing on the participant list. This vulnerability is due to improper handling of authentication tokens by a vulnerable… | ||
| CVE-2019-15006 | Med | 0.42 | 6.5 | 0.02 | Dec 19, 2019 | There was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in Confluence Server and Confluence Data Center. This plugin was used to facilitate communication with the Atlassian Companion application. The Confluence Previews plugin in Confluence… | ||
| CVE-2026-5251 | — | Med | 0.41 | 6.3 | 0.00 | Apr 1, 2026 | A vulnerability was identified in z-9527 admin 1.0/2.0. This impacts an unknown function of the file /server/routes/user.js of the component User Update Endpoint. Such manipulation of the argument isAdmin with the input 1 leads to dynamically-determined object attributes. It is… | |
| CVE-2026-5248 | Med | 0.41 | 6.3 | 0.00 | Apr 1, 2026 | A vulnerability has been found in gougucms 4.08.18. This affects the function reg_submit of the file gougucms-master\app\home\controller\Login.php of the component User Registration Handler. Such manipulation of the argument level leads to dynamically-determined object… | ||
| CVE-2025-14695 | Med | 0.41 | 6.3 | 0.00 | Dec 15, 2025 | A vulnerability was determined in SamuNatsu HaloBot up to 026b01d4a896d93eaaf9d5163a287dc9f267515b. Affected is the function html_renderer of the file plugins/html_renderer/index.js of the component Inter-plugin API. Executing manipulation of the argument action can lead to… | ||
| CVE-2025-14085 | Med | 0.41 | 6.3 | 0.00 | Dec 5, 2025 | A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. This impacts an unknown function of the file /app-api/v1/orders/. The manipulation of the argument orderId leads to improper control of dynamically-identified variables. Remote exploitation of the attack is… | ||
| CVE-2025-14051 | Med | 0.41 | 6.3 | 0.00 | Dec 4, 2025 | A flaw has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function getById/updateAddress/deleteAddress of the file /mall-ums/app-api/v1/addresses/. Executing manipulation can lead to improper control of dynamically-identified variables. The attack can be… | ||
| CVE-2025-9905 | Hig | 0.40 | 7.3 | 0.00 | Sep 19, 2025 | The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One can create a specially crafted .h5/.hdf5 model archive that, when loaded via Model.load_model, will trigger arbitrary code to be executed. This is achieved… | ||
| CVE-2018-19836 | Med | 0.40 | 6.1 | 0.01 | Dec 3, 2018 | In Metinfo 6.1.3, include/interface/applogin.php allows setting arbitrary HTTP headers (including the Cookie header), and common.inc.php allows registering variables from the $_COOKIE value. This issue can, for example, be exploited in conjunction with CVE-2018-19835 to bypass… | ||
| CVE-2025-26405 | Med | 0.38 | 5.9 | 0.00 | Nov 11, 2025 | Improper control of dynamically-managed code resources for some Intel(R) NPU Drivers within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service.… | ||
| CVE-2023-6184 | Med | 0.36 | 5.0 | 0.47 | Jan 18, 2024 | Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting | ||
| CVE-2020-15372 | Med | 0.36 | 5.5 | 0.00 | Sep 25, 2020 | A vulnerability in the command-line interface in Brocade Fabric OS before Brocade Fabric OS v8.2.2a1, 8.2.2c, v7.4.2g, v8.2.0_CBN3, v8.2.1e, v8.1.2k, v9.0.0, could allow a local authenticated attacker to modify shell variables, which may lead to an escalation of privileges or… | ||
| CVE-2022-27889 | Med | 0.35 | 5.3 | 0.01 | Jun 14, 2022 | The Multipass service was found to have code paths that could be abused to cause a denial of service for authentication or authorization operations. A malicious attacker could perform an application-level denial of service attack, potentially causing authentication and/or… |
- risk 0.44cvss 6.8epss 0.01
In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 6u211, or < 7u201, or < 8u191), allows remote attackers to load malicious code on the server via access to insecure ORB listeners.
- risk 0.44cvss 7.8epss 0.00
A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.
- risk 0.44cvss 6.8epss 0.01
Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverified 3th party package
- risk 0.42cvss 6.4epss 0.01
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass.
- risk 0.42cvss 6.4epss 0.01
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker SSTI.
- risk 0.42cvss 6.5epss 0.00
Improper Access Control of Dynamically-Managed Code Resources (DLL) in Thales Sentinel Protection Installer could allow the execution of arbitrary code.
- risk 0.42cvss 6.5epss 0.01
All versions of package config-handler are vulnerable to Prototype Pollution when loading config files.
- risk 0.42cvss 6.5epss 0.02
A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to join a Webex session without appearing on the participant list. This vulnerability is due to improper handling of authentication tokens by a vulnerable…
- risk 0.42cvss 6.5epss 0.02
There was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in Confluence Server and Confluence Data Center. This plugin was used to facilitate communication with the Atlassian Companion application. The Confluence Previews plugin in Confluence…
- risk 0.41cvss 6.3epss 0.00
A vulnerability was identified in z-9527 admin 1.0/2.0. This impacts an unknown function of the file /server/routes/user.js of the component User Update Endpoint. Such manipulation of the argument isAdmin with the input 1 leads to dynamically-determined object attributes. It is…
- risk 0.41cvss 6.3epss 0.00
A vulnerability has been found in gougucms 4.08.18. This affects the function reg_submit of the file gougucms-master\app\home\controller\Login.php of the component User Registration Handler. Such manipulation of the argument level leads to dynamically-determined object…
- risk 0.41cvss 6.3epss 0.00
A vulnerability was determined in SamuNatsu HaloBot up to 026b01d4a896d93eaaf9d5163a287dc9f267515b. Affected is the function html_renderer of the file plugins/html_renderer/index.js of the component Inter-plugin API. Executing manipulation of the argument action can lead to…
- risk 0.41cvss 6.3epss 0.00
A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. This impacts an unknown function of the file /app-api/v1/orders/. The manipulation of the argument orderId leads to improper control of dynamically-identified variables. Remote exploitation of the attack is…
- risk 0.41cvss 6.3epss 0.00
A flaw has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function getById/updateAddress/deleteAddress of the file /mall-ums/app-api/v1/addresses/. Executing manipulation can lead to improper control of dynamically-identified variables. The attack can be…
- risk 0.40cvss 7.3epss 0.00
The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One can create a specially crafted .h5/.hdf5 model archive that, when loaded via Model.load_model, will trigger arbitrary code to be executed. This is achieved…
- risk 0.40cvss 6.1epss 0.01
In Metinfo 6.1.3, include/interface/applogin.php allows setting arbitrary HTTP headers (including the Cookie header), and common.inc.php allows registering variables from the $_COOKIE value. This issue can, for example, be exploited in conjunction with CVE-2018-19835 to bypass…
- risk 0.38cvss 5.9epss 0.00
Improper control of dynamically-managed code resources for some Intel(R) NPU Drivers within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service.…
- risk 0.36cvss 5.0epss 0.47
Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting
- risk 0.36cvss 5.5epss 0.00
A vulnerability in the command-line interface in Brocade Fabric OS before Brocade Fabric OS v8.2.2a1, 8.2.2c, v7.4.2g, v8.2.0_CBN3, v8.2.1e, v8.1.2k, v9.0.0, could allow a local authenticated attacker to modify shell variables, which may lead to an escalation of privileges or…
- risk 0.35cvss 5.3epss 0.01
The Multipass service was found to have code paths that could be abused to cause a denial of service for authentication or authorization operations. A malicious attacker could perform an application-level denial of service attack, potentially causing authentication and/or…