VYPR

CWE-913

Improper Control of Dynamically-Managed Code Resources

ClassIncomplete

Description

The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.

Many languages offer powerful features that allow the programmer to dynamically create or modify existing code, or resources used by code such as variables and objects. While these features can offer significant flexibility and reduce development time, they can be extremely dangerous if attackers can directly influence these code resources in unexpected ways.

Hierarchy (View 1000)

CVEs mapped to this weakness (117)

page 5 of 6
  • CVE-2020-3419MedNov 18, 2020
    risk 0.42cvss 6.5epss 0.02

    A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to join a Webex session without appearing on the participant list. This vulnerability is due to improper handling of authentication tokens by a vulnerable…

  • CVE-2019-15006MedDec 19, 2019
    risk 0.42cvss 6.5epss 0.02

    There was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in Confluence Server and Confluence Data Center. This plugin was used to facilitate communication with the Atlassian Companion application. The Confluence Previews plugin in Confluence…

  • CVE-2026-92217MedSep 16, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in a2ui-project a2ui up to 0.10.6. This affects the function processMessages of the file renderers/web_core/src/v0_9/processing/message-processor.ts of the component Message Parsing. This manipulation causes dynamically-determined object…

  • CVE-2026-84430MedSep 2, 2026
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in gouguoa up to 5.10.0/6.0.1. This vulnerability affects the function update of the file app/home/controller/Index.php of the component edit_personal Endpoint. Such manipulation of the argument position_id leads to…

  • CVE-2026-5251MedApr 1, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in z-9527 admin 1.0/2.0. This impacts an unknown function of the file /server/routes/user.js of the component User Update Endpoint. Such manipulation of the argument isAdmin with the input 1 leads to dynamically-determined object attributes. It is…

  • CVE-2026-5248MedApr 1, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in gougucms 4.08.18. This affects the function reg_submit of the file gougucms-master\app\home\controller\Login.php of the component User Registration Handler. Such manipulation of the argument level leads to dynamically-determined object…

  • CVE-2025-14695MedDec 15, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in SamuNatsu HaloBot up to 026b01d4a896d93eaaf9d5163a287dc9f267515b. Affected is the function html_renderer of the file plugins/html_renderer/index.js of the component Inter-plugin API. Executing manipulation of the argument action can lead to…

  • CVE-2025-14085MedDec 5, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. This impacts an unknown function of the file /app-api/v1/orders/. The manipulation of the argument orderId leads to improper control of dynamically-identified variables. Remote exploitation of the attack is…

  • CVE-2025-14051MedDec 4, 2025
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function getById/updateAddress/deleteAddress of the file /mall-ums/app-api/v1/addresses/. Executing manipulation can lead to improper control of dynamically-identified variables. The attack can be…

  • CVE-2025-9905HigSep 19, 2025
    risk 0.40cvss 7.3epss 0.00

    The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One can create a specially crafted .h5/.hdf5 model archive that, when loaded via Model.load_model, will trigger arbitrary code to be executed. This is achieved…

  • CVE-2018-19836MedDec 3, 2018
    risk 0.40cvss 6.1epss 0.01

    In Metinfo 6.1.3, include/interface/applogin.php allows setting arbitrary HTTP headers (including the Cookie header), and common.inc.php allows registering variables from the $_COOKIE value. This issue can, for example, be exploited in conjunction with CVE-2018-19835 to bypass…

  • CVE-2025-26405MedNov 11, 2025
    risk 0.38cvss 5.9epss 0.00

    Improper control of dynamically-managed code resources for some Intel(R) NPU Drivers within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service.…

  • CVE-2023-6184MedJan 18, 2024
    risk 0.36cvss 5.0epss 0.47

    Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting

  • CVE-2020-15372MedSep 25, 2020
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the command-line interface in Brocade Fabric OS before Brocade Fabric OS v8.2.2a1, 8.2.2c, v7.4.2g, v8.2.0_CBN3, v8.2.1e, v8.1.2k, v9.0.0, could allow a local authenticated attacker to modify shell variables, which may lead to an escalation of privileges or…

  • CVE-2022-27889MedJun 14, 2022
    risk 0.35cvss 5.3epss 0.01

    The Multipass service was found to have code paths that could be abused to cause a denial of service for authentication or authorization operations. A malicious attacker could perform an application-level denial of service attack, potentially causing authentication and/or…

  • CVE-2022-25355MedFeb 24, 2022
    risk 0.35cvss 5.3epss 0.01

    EC-CUBE 3.0.0 to 3.0.18-p3 and EC-CUBE 4.0.0 to 4.1.1 improperly handle HTTP Host header values, which may lead a remote unauthenticated attacker to direct the vulnerable version of EC-CUBE to send an Email with some forged reissue-password URL to EC-CUBE users.

  • CVE-2023-39983MedSep 2, 2023
    risk 0.34cvss 5.3epss 0.01

    A vulnerability that poses a potential risk of polluting the MXsecurity sqlite database and the nsm-web UI has been identified in MXsecurity versions prior to v1.0.1. This vulnerability might allow an unauthenticated remote attacker to register or add devices via the nsm-web…

  • CVE-2025-61780MedOct 10, 2025
    risk 0.31cvss 5.8epss 0.01

    Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, a possible information disclosure vulnerability existed in `Rack::Sendfile` when running behind a proxy that supports `x-sendfile` headers (such as Nginx). Specially crafted headers could…

  • CVE-2026-1770MedFeb 2, 2026
    risk 0.29cvss —epss 0.00

    Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass. By inserting malicious Groovy elements, an attacker may bypass sandbox restrictions and obtain…

  • CVE-2024-2537MedMar 15, 2024
    risk 0.29cvss 4.4epss 0.00

    Improper Control of Dynamically-Managed Code Resources vulnerability in Logitech Logi Tune on MacOS allows Local Code Inclusion.