Skip to content
Noroxi

CWE-913 · 84 records

Improper Control of Dynamically-Managed Code Resources

CVEs in this class

84 records

  • n8n Vulnerable to Remote Code Execution via Expression Injection

    HighCVSS 8.8KEVWeaponizedEPSS 99%

    n8n · n8nDec 19, 2025

  • CVE-2023-43177
    64This week

    CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.

    CriticalCVSS 9.8WeaponizedEPSS 82%

    crushftp · crushftpNov 17, 2023

  • vm2 Sandbox Escape vulnerability

    CriticalCVSS 9.8Proof of conceptEPSS 63%

    vm2 project · vm2Apr 6, 2023

  • vm2 vulnerable to Sandbox Escape before v3.9.11

    CriticalCVSS 10.0Proof of conceptEPSS 48%

    vm2 project · vm2Sep 6, 2022

  • TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root.

    CriticalCVSS 9.8Proof of conceptEPSS 29%

    terra-master · tosJan 30, 2021

  • Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting

    HighCVSS 7.2No exploitEPSS 47%

    citrix · virtual apps and desktopsJan 17, 2024

  • Langflow Privilege Escalation

    HighCVSS 8.8No exploitEPSS 21%

    langflow · langflowJul 30, 2024

  • The implementation of Action Message Format (AMF3) deserializers in Flamingo amf-serializer by Exadel, version 2.2.0, may allow instantiation of arbitrary class

    CriticalCVSS 9.8No exploitEPSS 8%

    exadel · flamingoJun 11, 2018

  • NocoBase Affected by Sandbox Escape to RCE via console._stdout Prototype Chain Traversal in Workflow Script Node

    CriticalCVSS 9.9Proof of conceptEPSS 7%

    nocobase · nocobaseMar 31, 2026

  • vm2 Sandbox escape vulnerability

    CriticalCVSS 10.0No exploitEPSS 4%

    vm2 project · vm2Apr 14, 2023

  • An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2.

    CriticalCVSS 9.8No exploitEPSS 3%

    xfce · thunarMay 11, 2021

  • distribute-cache.c in ImageMagick re-uses objects after they have been destroyed, which allows remote attackers to have unspecified impact v

    CriticalCVSS 9.8No exploitEPSS 3%

    imagemagick · imagemagickMar 17, 2017

  • vm2 before 3.11.7 Remote Code Execution via require.external

    CriticalCVSS 10.0No exploitEPSS 1%

    patriksimek · vm2Sep 17, 2026

  • vm2: Sandbox Breakout Using Promise Species

    CriticalCVSS 10.0No exploitEPSS 1%

    patriksimek · vm2Jun 12, 2026

  • vm2 before 3.11.8 Sandbox Escape via NodeVM

    CriticalCVSS 10.0No exploitEPSS 1%

    patriksimek · vm2Sep 17, 2026

  • vm2: GHSA-8hg8-63c5-gwmx patch bypass: nesting:true without explicit require still allows full RCE

    CriticalCVSS 10.0No exploitEPSS 1%

    patriksimek · vm2Jun 12, 2026

  • vm2 is an open source vm/sandbox for Node.js.

    CriticalCVSS 10.0No exploitEPSS 1%

    patriksimek · vm2Jun 12, 2026

  • vm2: Sandbox Breakout Using Dangerous Host Proto Mutators

    CriticalCVSS 9.8No exploitEPSS 1%

    patriksimek · vm2Aug 17, 2026

  • There is an Improper Control of Dynamically Managing Code Resources Vulnerability in Huawei Smartphone.Successful exploitation of this vulne

    CriticalCVSS 9.8No exploitEPSS 1%

    huawei · emuiAug 2, 2021

  • RestrictedPython vulnerable to arbitrary code execution via stack frame sandbox escape

    CriticalCVSS 9.9No exploitEPSS 1%

    zope · restrictedpythonJul 11, 2023

  • vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass

    CriticalCVSS 9.8No exploitEPSS 1%

    patriksimek · vm2Jun 12, 2026

  • Remote Code Execution via Unauthenticated Configuration Manipulation

    CriticalCVSS 9.8No exploitEPSS 1%

    phoenixcontact · charx sec-3000 firmwareJul 8, 2025

  • JSON Injection in DataHub

    CriticalCVSS 9.8No exploitEPSS 1%

    datahub · datahubFeb 10, 2023

  • NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space D

    CriticalCVSS 9.9No exploitEPSS 0%

    nasa · cryptolibApr 26, 2025

  • CVE-2024-2537
    39Monitor

    Electron Code Injection in Logi Tune macOS Application

    CriticalCVSS 9.8No exploitEPSS 0%

    logitech · logi tuneMar 15, 2024

All vulnerability classes