VYPR

CWE-913

Improper Control of Dynamically-Managed Code Resources

ClassIncomplete

Description

The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.

Many languages offer powerful features that allow the programmer to dynamically create or modify existing code, or resources used by code such as variables and objects. While these features can offer significant flexibility and reduce development time, they can be extremely dangerous if attackers can directly influence these code resources in unexpected ways.

Hierarchy (View 1000)

CVEs mapped to this weakness (101)

page 5 of 6
  • CVE-2022-25355MedFeb 24, 2022
    risk 0.35cvss 5.3epss 0.01

    EC-CUBE 3.0.0 to 3.0.18-p3 and EC-CUBE 4.0.0 to 4.1.1 improperly handle HTTP Host header values, which may lead a remote unauthenticated attacker to direct the vulnerable version of EC-CUBE to send an Email with some forged reissue-password URL to EC-CUBE users.

  • CVE-2023-39983MedSep 2, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability that poses a potential risk of polluting the MXsecurity sqlite database and the nsm-web UI has been identified in MXsecurity versions prior to v1.0.1. This vulnerability might allow an unauthenticated remote attacker to register or add devices via the nsm-web…

  • CVE-2025-61780MedOct 10, 2025
    risk 0.31cvss 5.8epss 0.00

    Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, a possible information disclosure vulnerability existed in `Rack::Sendfile` when running behind a proxy that supports `x-sendfile` headers (such as Nginx). Specially crafted headers could…

  • CVE-2026-1770MedFeb 2, 2026
    risk 0.29cvss epss 0.00

    Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass. By inserting malicious Groovy elements, an attacker may bypass sandbox restrictions and obtain…

  • CVE-2024-2537MedMar 15, 2024
    risk 0.29cvss 4.4epss 0.00

    Improper Control of Dynamically-Managed Code Resources vulnerability in Logitech Logi Tune on MacOS allows Local Code Inclusion.

  • CVE-2020-4100MedJul 15, 2020
    risk 0.29cvss 4.4epss 0.00

    "HCL Verse for Android was found to employ dynamic code loading. This mechanism allows a developer to specify which components of the application should not be loaded by default when the application is started. Typically, core components and additional dependencies are loaded…

  • CVE-2024-5401MedDec 4, 2025
    risk 0.28cvss 4.3epss 0.00

    Improper control of dynamically-managed code resources vulnerability in WebAPI component in Synology DiskStation Manager (DSM) before 7.1.1-42962-8 and 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote authenticated users to…

  • CVE-2021-26276MedJan 27, 2021
    risk 0.28cvss 5.3epss 0.01

    scripts/cli.js in the GoDaddy node-config-shield (aka Config Shield) package before 0.2.2 for Node.js calls eval when processing a set command. NOTE: the vendor reportedly states that this is not a vulnerability. The set command was not intended for use with untrusted data

  • CVE-2021-23262MedDec 2, 2021
    risk 0.27cvss 4.2epss 0.01

    Authenticated administrators may modify the main YAML configuration file and load a Java class resulting in RCE.

  • CVE-2021-23259MedDec 2, 2021
    risk 0.27cvss 4.2epss 0.01

    Authenticated users with Administrator or Developer roles may execute OS commands by Groovy Script which uses Groovy lib to render a webpage. The groovy script does not have security restrictions, which will cause attackers to execute arbitrary commands remotely(RCE).

  • CVE-2021-23258MedDec 2, 2021
    risk 0.27cvss 4.2epss 0.01

    Authenticated users with Administrator or Developer roles may execute OS commands by SPEL Expression in Spring beans. SPEL Expression does not have security restrictions, which will cause attackers to execute arbitrary commands remotely (RCE).

  • CVE-2020-25803MedOct 6, 2020
    risk 0.27cvss 4.2epss 0.01

    Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker template exposed objects. This issue affects: Crafter Software Crafter CMS 3.0 versions prior to 3.0.27;…

  • CVE-2020-25802MedOct 6, 2020
    risk 0.27cvss 4.2epss 0.01

    Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy scripting. This issue affects: Crafter Software Crafter CMS 3.0 versions prior to 3.0.27; 3.1 versions prior to…

  • CVE-2025-6107LowJun 16, 2025
    risk 0.20cvss 3.1epss 0.00

    A vulnerability was found in comfyanonymous comfyui 0.3.40. It has been classified as problematic. Affected is the function set_attr of the file /comfy/utils.py. The manipulation leads to dynamically-determined object attributes. It is possible to launch the attack remotely. The…

  • CVE-2024-40637MedJul 16, 2024
    risk 0.20cvss 4.2epss 0.00

    dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to build applications. When a user installs a package in dbt, it has the ability to override macros, materializations, and other core components of dbt. This is…

  • CVE-2023-35930LowJun 26, 2023
    risk 0.17cvss 3.7epss 0.00

    SpiceDB is an open source, Google Zanzibar-inspired, database system for creating and managing security-critical application permissions. Any user making a negative authorization decision based on the results of a `LookupResources` request with 1.22.0 is affected. For example,…

  • CVE-2025-6705MedJun 27, 2025
    risk 0.00cvss 5.3epss 0.00

    A vulnerability in the Eclipse Open VSX Registry’s automated publishing system could have allowed unauthorized uploads of extensions. Specifically, the system’s build scripts were executed without proper isolation, potentially exposing a privileged token. This token enabled…

  • CVE-2025-46675LowApr 27, 2025
    risk 0.00cvss 3.5epss 0.00

    In NASA CryptoLib before 1.3.2, the key state is not checked before use, potentially leading to spacecraft hijacking.

  • CVE-2025-46673MedApr 27, 2025
    risk 0.00cvss 4.9epss 0.00

    NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space Data Link Security protocol (SDLS).

  • CVE-2021-32813MedAug 3, 2021
    risk 0.00cvss 4.8epss 0.01

    Traefik is an HTTP reverse proxy and load balancer. Prior to version 2.4.13, there exists a potential header vulnerability in Traefik's handling of the Connection header. Active exploitation of this issue is unlikely, as it requires that a removed header would lead to a…