Перейти к содержимому
Noroxi

CWE-913 · 84 записей

Improper Control of Dynamically-Managed Code Resources

CVE этого класса

84 записей

  • CVE-2025-68613
    95Срочно

    n8n Vulnerable to Remote Code Execution via Expression Injection

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 99 %

    n8n · n8n19 дек. 2025 г.

  • CVE-2023-43177
    64На этой неделе

    CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.

    КритическаяCVSS 9,8Готовый эксплойтEPSS 82 %

    crushftp · crushftp17 нояб. 2023 г.

  • CVE-2023-29017
    58В плане

    vm2 Sandbox Escape vulnerability

    КритическаяCVSS 9,8Proof of conceptEPSS 63 %

    vm2 project · vm26 апр. 2023 г.

  • CVE-2022-36067
    54В плане

    vm2 vulnerable to Sandbox Escape before v3.9.11

    КритическаяCVSS 10,0Proof of conceptEPSS 48 %

    vm2 project · vm26 сент. 2022 г.

  • CVE-2020-15568
    48В плане

    TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root.

    КритическаяCVSS 9,8Proof of conceptEPSS 29 %

    terra-master · tos30 янв. 2021 г.

  • CVE-2023-6184
    42В плане

    Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting

    ВысокаяCVSS 7,2Эксплойта нетEPSS 47 %

    citrix · virtual apps and desktops17 янв. 2024 г.

  • CVE-2024-7297
    41В плане

    Langflow Privilege Escalation

    ВысокаяCVSS 8,8Эксплойта нетEPSS 21 %

    langflow · langflow30 июл. 2024 г.

  • CVE-2017-3202
    41В плане

    The implementation of Action Message Format (AMF3) deserializers in Flamingo amf-serializer by Exadel, version 2.2.0, may allow instantiation of arbitrary class

    КритическаяCVSS 9,8Эксплойта нетEPSS 8 %

    exadel · flamingo11 июн. 2018 г.

  • CVE-2026-34156
    41В плане

    NocoBase Affected by Sandbox Escape to RCE via console._stdout Prototype Chain Traversal in Workflow Script Node

    КритическаяCVSS 9,9Proof of conceptEPSS 7 %

    nocobase · nocobase31 мар. 2026 г.

  • CVE-2023-29199
    41В плане

    vm2 Sandbox escape vulnerability

    КритическаяCVSS 10,0Эксплойта нетEPSS 4 %

    vm2 project · vm214 апр. 2023 г.

  • CVE-2021-32563
    40В плане

    An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    xfce · thunar11 мая 2021 г.

  • CVE-2014-9852
    40В плане

    distribute-cache.c in ImageMagick re-uses objects after they have been destroyed, which allows remote attackers to have unspecified impact v

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    imagemagick · imagemagick17 мар. 2017 г.

  • CVE-2026-92946
    40В плане

    vm2 before 3.11.7 Remote Code Execution via require.external

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    patriksimek · vm217 сент. 2026 г.

  • CVE-2026-47208
    40В плане

    vm2: Sandbox Breakout Using Promise Species

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    patriksimek · vm212 июн. 2026 г.

  • CVE-2026-92955
    40В плане

    vm2 before 3.11.8 Sandbox Escape via NodeVM

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    patriksimek · vm217 сент. 2026 г.

  • CVE-2026-47137
    40В плане

    vm2: GHSA-8hg8-63c5-gwmx patch bypass: nesting:true without explicit require still allows full RCE

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    patriksimek · vm212 июн. 2026 г.

  • CVE-2026-47131
    40В плане

    vm2 is an open source vm/sandbox for Node.js.

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    patriksimek · vm212 июн. 2026 г.

  • CVE-2026-47698
    39Наблюдать

    vm2: Sandbox Breakout Using Dangerous Host Proto Mutators

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    patriksimek · vm217 авг. 2026 г.

  • CVE-2021-22387
    39Наблюдать

    There is an Improper Control of Dynamically Managing Code Resources Vulnerability in Huawei Smartphone.Successful exploitation of this vulne

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    huawei · emui2 авг. 2021 г.

  • CVE-2023-37271
    39Наблюдать

    RestrictedPython vulnerable to arbitrary code execution via stack frame sandbox escape

    КритическаяCVSS 9,9Эксплойта нетEPSS 1 %

    zope · restrictedpython11 июл. 2023 г.

  • CVE-2026-47210
    39Наблюдать

    vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    patriksimek · vm212 июн. 2026 г.

  • CVE-2025-25270
    39Наблюдать

    Remote Code Execution via Unauthenticated Configuration Manipulation

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    phoenixcontact · charx sec-3000 firmware8 июл. 2025 г.

  • CVE-2023-25560
    39Наблюдать

    JSON Injection in DataHub

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    datahub · datahub10 февр. 2023 г.

  • CVE-2025-46673
    39Наблюдать

    NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space D

    КритическаяCVSS 9,9Эксплойта нетEPSS 0 %

    nasa · cryptolib26 апр. 2025 г.

  • CVE-2024-2537
    39Наблюдать

    Electron Code Injection in Logi Tune macOS Application

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    logitech · logi tune15 мар. 2024 г.

Все классы уязвимостей