CWE-913 · 84 records
Improper Control of Dynamically-Managed Code Resources
CVEs in this class
84 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
95Now | CVE-2025-68613Weaponized | n8n Vulnerable to Remote Code Execution via Expression Injectionn8n · n8n · CWE-913 | High8.8 | KEV | 99.0% | Dec 19, 2025 |
64This week | CVE-2023-43177Weaponized | CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.crushftp · crushftp · CWE-913 | Critical9.8 | — | 81.8% | Nov 17, 2023 |
58Plan | CVE-2023-29017Proof of concept | vm2 Sandbox Escape vulnerabilityvm2 project · vm2 · CWE-913 | Critical9.8 | — | 63.2% | Apr 6, 2023 |
54Plan | CVE-2022-36067Proof of concept | vm2 vulnerable to Sandbox Escape before v3.9.11vm2 project · vm2 · CWE-913 | Critical10.0 | — | 47.9% | Sep 6, 2022 |
48Plan | CVE-2020-15568Proof of concept | TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root.terra-master · tos · CWE-913 | Critical9.8 | — | 29.0% | Jan 30, 2021 |
42Plan | CVE-2023-6184No exploit | Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scriptingcitrix · virtual apps and desktops · CWE-913 | High7.2 | — | 46.6% | Jan 17, 2024 |
41Plan | CVE-2024-7297No exploit | Langflow Privilege Escalationlangflow · langflow · CWE-913 | High8.8 | — | 21.3% | Jul 30, 2024 |
41Plan | CVE-2017-3202No exploit | The implementation of Action Message Format (AMF3) deserializers in Flamingo amf-serializer by Exadel, version 2.2.0, may allow instantiation of arbitrary classexadel · flamingo · CWE-913 | Critical9.8 | — | 8.2% | Jun 11, 2018 |
41Plan | CVE-2026-34156Proof of concept | NocoBase Affected by Sandbox Escape to RCE via console._stdout Prototype Chain Traversal in Workflow Script Nodenocobase · nocobase · CWE-913 | Critical9.9 | — | 6.8% | Mar 31, 2026 |
41Plan | CVE-2023-29199No exploit | vm2 Sandbox escape vulnerabilityvm2 project · vm2 · CWE-913 | Critical10.0 | — | 3.9% | Apr 14, 2023 |
40Plan | CVE-2021-32563No exploit | An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2.xfce · thunar · CWE-913 | Critical9.8 | — | 3.0% | May 11, 2021 |
40Plan | CVE-2014-9852No exploit | distribute-cache.c in ImageMagick re-uses objects after they have been destroyed, which allows remote attackers to have unspecified impact vimagemagick · imagemagick · CWE-913 | Critical9.8 | — | 2.9% | Mar 17, 2017 |
40Plan | CVE-2026-92946No exploit | vm2 before 3.11.7 Remote Code Execution via require.externalpatriksimek · vm2 · CWE-913 | Critical10.0 | — | 0.9% | Sep 17, 2026 |
40Plan | CVE-2026-47208No exploit | vm2: Sandbox Breakout Using Promise Speciespatriksimek · vm2 · CWE-913 | Critical10.0 | — | 0.8% | Jun 12, 2026 |
40Plan | CVE-2026-92955No exploit | vm2 before 3.11.8 Sandbox Escape via NodeVMpatriksimek · vm2 · CWE-913 | Critical10.0 | — | 0.7% | Sep 17, 2026 |
40Plan | CVE-2026-47137No exploit | vm2: GHSA-8hg8-63c5-gwmx patch bypass: nesting:true without explicit require still allows full RCEpatriksimek · vm2 · CWE-913 | Critical10.0 | — | 0.7% | Jun 12, 2026 |
40Plan | CVE-2026-47131No exploit | vm2 is an open source vm/sandbox for Node.js.patriksimek · vm2 · CWE-913 | Critical10.0 | — | 0.6% | Jun 12, 2026 |
39Monitor | CVE-2026-47698No exploit | vm2: Sandbox Breakout Using Dangerous Host Proto Mutatorspatriksimek · vm2 · CWE-913 | Critical9.8 | — | 1.0% | Aug 17, 2026 |
39Monitor | CVE-2021-22387No exploit | There is an Improper Control of Dynamically Managing Code Resources Vulnerability in Huawei Smartphone.Successful exploitation of this vulnehuawei · emui · CWE-913 | Critical9.8 | — | 0.9% | Aug 2, 2021 |
39Monitor | CVE-2023-37271No exploit | RestrictedPython vulnerable to arbitrary code execution via stack frame sandbox escapezope · restrictedpython · CWE-913 | Critical9.9 | — | 0.8% | Jul 11, 2023 |
39Monitor | CVE-2026-47210No exploit | vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypasspatriksimek · vm2 · CWE-913 | Critical9.8 | — | 0.8% | Jun 12, 2026 |
39Monitor | CVE-2025-25270No exploit | Remote Code Execution via Unauthenticated Configuration Manipulationphoenixcontact · charx sec-3000 firmware · CWE-913 | Critical9.8 | — | 0.7% | Jul 8, 2025 |
39Monitor | CVE-2023-25560No exploit | JSON Injection in DataHubdatahub · datahub · CWE-913 | Critical9.8 | — | 0.6% | Feb 10, 2023 |
39Monitor | CVE-2025-46673No exploit | NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space Dnasa · cryptolib · CWE-913 | Critical9.9 | — | 0.5% | Apr 26, 2025 |
39Monitor | CVE-2024-2537No exploit | Electron Code Injection in Logi Tune macOS Applicationlogitech · logi tune · CWE-913 | Critical9.8 | — | 0.3% | Mar 15, 2024 |
- CVE-2025-6861395Now
n8n Vulnerable to Remote Code Execution via Expression Injection
HighCVSS 8.8KEVWeaponizedEPSS 99%n8n · n8nDec 19, 2025
- CVE-2023-4317764This week
CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.
CriticalCVSS 9.8WeaponizedEPSS 82%crushftp · crushftpNov 17, 2023
- CVE-2023-2901758Plan
vm2 Sandbox Escape vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 63%vm2 project · vm2Apr 6, 2023
- CVE-2022-3606754Plan
vm2 vulnerable to Sandbox Escape before v3.9.11
CriticalCVSS 10.0Proof of conceptEPSS 48%vm2 project · vm2Sep 6, 2022
- CVE-2020-1556848Plan
TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root.
CriticalCVSS 9.8Proof of conceptEPSS 29%terra-master · tosJan 30, 2021
- CVE-2023-618442Plan
Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting
HighCVSS 7.2No exploitEPSS 47%citrix · virtual apps and desktopsJan 17, 2024
- CVE-2024-729741Plan
Langflow Privilege Escalation
HighCVSS 8.8No exploitEPSS 21%langflow · langflowJul 30, 2024
- CVE-2017-320241Plan
The implementation of Action Message Format (AMF3) deserializers in Flamingo amf-serializer by Exadel, version 2.2.0, may allow instantiation of arbitrary class
CriticalCVSS 9.8No exploitEPSS 8%exadel · flamingoJun 11, 2018
- CVE-2026-3415641Plan
NocoBase Affected by Sandbox Escape to RCE via console._stdout Prototype Chain Traversal in Workflow Script Node
CriticalCVSS 9.9Proof of conceptEPSS 7%nocobase · nocobaseMar 31, 2026
- CVE-2023-2919941Plan
vm2 Sandbox escape vulnerability
CriticalCVSS 10.0No exploitEPSS 4%vm2 project · vm2Apr 14, 2023
- CVE-2021-3256340Plan
An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2.
CriticalCVSS 9.8No exploitEPSS 3%xfce · thunarMay 11, 2021
- CVE-2014-985240Plan
distribute-cache.c in ImageMagick re-uses objects after they have been destroyed, which allows remote attackers to have unspecified impact v
CriticalCVSS 9.8No exploitEPSS 3%imagemagick · imagemagickMar 17, 2017
- CVE-2026-9294640Plan
vm2 before 3.11.7 Remote Code Execution via require.external
CriticalCVSS 10.0No exploitEPSS 1%patriksimek · vm2Sep 17, 2026
- CVE-2026-4720840Plan
vm2: Sandbox Breakout Using Promise Species
CriticalCVSS 10.0No exploitEPSS 1%patriksimek · vm2Jun 12, 2026
- CVE-2026-9295540Plan
vm2 before 3.11.8 Sandbox Escape via NodeVM
CriticalCVSS 10.0No exploitEPSS 1%patriksimek · vm2Sep 17, 2026
- CVE-2026-4713740Plan
vm2: GHSA-8hg8-63c5-gwmx patch bypass: nesting:true without explicit require still allows full RCE
CriticalCVSS 10.0No exploitEPSS 1%patriksimek · vm2Jun 12, 2026
- CVE-2026-4713140Plan
vm2 is an open source vm/sandbox for Node.js.
CriticalCVSS 10.0No exploitEPSS 1%patriksimek · vm2Jun 12, 2026
- CVE-2026-4769839Monitor
vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
CriticalCVSS 9.8No exploitEPSS 1%patriksimek · vm2Aug 17, 2026
- CVE-2021-2238739Monitor
There is an Improper Control of Dynamically Managing Code Resources Vulnerability in Huawei Smartphone.Successful exploitation of this vulne
CriticalCVSS 9.8No exploitEPSS 1%huawei · emuiAug 2, 2021
- CVE-2023-3727139Monitor
RestrictedPython vulnerable to arbitrary code execution via stack frame sandbox escape
CriticalCVSS 9.9No exploitEPSS 1%zope · restrictedpythonJul 11, 2023
- CVE-2026-4721039Monitor
vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass
CriticalCVSS 9.8No exploitEPSS 1%patriksimek · vm2Jun 12, 2026
- CVE-2025-2527039Monitor
Remote Code Execution via Unauthenticated Configuration Manipulation
CriticalCVSS 9.8No exploitEPSS 1%phoenixcontact · charx sec-3000 firmwareJul 8, 2025
- CVE-2023-2556039Monitor
JSON Injection in DataHub
CriticalCVSS 9.8No exploitEPSS 1%datahub · datahubFeb 10, 2023
- CVE-2025-4667339Monitor
NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space D
CriticalCVSS 9.9No exploitEPSS 0%nasa · cryptolibApr 26, 2025
- CVE-2024-253739Monitor
Electron Code Injection in Logi Tune macOS Application
CriticalCVSS 9.8No exploitEPSS 0%logitech · logi tuneMar 15, 2024