CWE-913 · 84 kayıt
Improper Control of Dynamically-Managed Code Resources
Bu sınıftaki CVE’ler
84 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
95Hemen | CVE-2025-68613Silahlaştırılmış | n8n Vulnerable to Remote Code Execution via Expression Injectionn8n · n8n · CWE-913 | Yüksek8,8 | KEV | %99,0 | 19 Ara 2025 |
64Bu hafta | CVE-2023-43177Silahlaştırılmış | CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.crushftp · crushftp · CWE-913 | Kritik9,8 | — | %81,8 | 17 Kas 2023 |
58Planlayın | CVE-2023-29017Kavram kanıtı | vm2 Sandbox Escape vulnerabilityvm2 project · vm2 · CWE-913 | Kritik9,8 | — | %63,2 | 6 Nis 2023 |
54Planlayın | CVE-2022-36067Kavram kanıtı | vm2 vulnerable to Sandbox Escape before v3.9.11vm2 project · vm2 · CWE-913 | Kritik10,0 | — | %47,9 | 6 Eyl 2022 |
48Planlayın | CVE-2020-15568Kavram kanıtı | TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root.terra-master · tos · CWE-913 | Kritik9,8 | — | %29,0 | 30 Oca 2021 |
42Planlayın | CVE-2023-6184İstismar yok | Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scriptingcitrix · virtual apps and desktops · CWE-913 | Yüksek7,2 | — | %46,6 | 17 Oca 2024 |
41Planlayın | CVE-2024-7297İstismar yok | Langflow Privilege Escalationlangflow · langflow · CWE-913 | Yüksek8,8 | — | %21,3 | 30 Tem 2024 |
41Planlayın | CVE-2017-3202İstismar yok | The implementation of Action Message Format (AMF3) deserializers in Flamingo amf-serializer by Exadel, version 2.2.0, may allow instantiation of arbitrary classexadel · flamingo · CWE-913 | Kritik9,8 | — | %8,2 | 11 Haz 2018 |
41Planlayın | CVE-2026-34156Kavram kanıtı | NocoBase Affected by Sandbox Escape to RCE via console._stdout Prototype Chain Traversal in Workflow Script Nodenocobase · nocobase · CWE-913 | Kritik9,9 | — | %6,8 | 31 Mar 2026 |
41Planlayın | CVE-2023-29199İstismar yok | vm2 Sandbox escape vulnerabilityvm2 project · vm2 · CWE-913 | Kritik10,0 | — | %3,9 | 14 Nis 2023 |
40Planlayın | CVE-2021-32563İstismar yok | An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2.xfce · thunar · CWE-913 | Kritik9,8 | — | %3,0 | 11 May 2021 |
40Planlayın | CVE-2014-9852İstismar yok | distribute-cache.c in ImageMagick re-uses objects after they have been destroyed, which allows remote attackers to have unspecified impact vimagemagick · imagemagick · CWE-913 | Kritik9,8 | — | %2,9 | 17 Mar 2017 |
40Planlayın | CVE-2026-92946İstismar yok | vm2 before 3.11.7 Remote Code Execution via require.externalpatriksimek · vm2 · CWE-913 | Kritik10,0 | — | %0,9 | 17 Eyl 2026 |
40Planlayın | CVE-2026-47208İstismar yok | vm2: Sandbox Breakout Using Promise Speciespatriksimek · vm2 · CWE-913 | Kritik10,0 | — | %0,8 | 12 Haz 2026 |
40Planlayın | CVE-2026-92955İstismar yok | vm2 before 3.11.8 Sandbox Escape via NodeVMpatriksimek · vm2 · CWE-913 | Kritik10,0 | — | %0,7 | 17 Eyl 2026 |
40Planlayın | CVE-2026-47137İstismar yok | vm2: GHSA-8hg8-63c5-gwmx patch bypass: nesting:true without explicit require still allows full RCEpatriksimek · vm2 · CWE-913 | Kritik10,0 | — | %0,7 | 12 Haz 2026 |
40Planlayın | CVE-2026-47131İstismar yok | vm2 is an open source vm/sandbox for Node.js.patriksimek · vm2 · CWE-913 | Kritik10,0 | — | %0,6 | 12 Haz 2026 |
39İzleyin | CVE-2026-47698İstismar yok | vm2: Sandbox Breakout Using Dangerous Host Proto Mutatorspatriksimek · vm2 · CWE-913 | Kritik9,8 | — | %1,0 | 17 Ağu 2026 |
39İzleyin | CVE-2021-22387İstismar yok | There is an Improper Control of Dynamically Managing Code Resources Vulnerability in Huawei Smartphone.Successful exploitation of this vulnehuawei · emui · CWE-913 | Kritik9,8 | — | %0,9 | 2 Ağu 2021 |
39İzleyin | CVE-2023-37271İstismar yok | RestrictedPython vulnerable to arbitrary code execution via stack frame sandbox escapezope · restrictedpython · CWE-913 | Kritik9,9 | — | %0,8 | 11 Tem 2023 |
39İzleyin | CVE-2026-47210İstismar yok | vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypasspatriksimek · vm2 · CWE-913 | Kritik9,8 | — | %0,8 | 12 Haz 2026 |
39İzleyin | CVE-2025-25270İstismar yok | Remote Code Execution via Unauthenticated Configuration Manipulationphoenixcontact · charx sec-3000 firmware · CWE-913 | Kritik9,8 | — | %0,7 | 8 Tem 2025 |
39İzleyin | CVE-2023-25560İstismar yok | JSON Injection in DataHubdatahub · datahub · CWE-913 | Kritik9,8 | — | %0,6 | 10 Şub 2023 |
39İzleyin | CVE-2025-46673İstismar yok | NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space Dnasa · cryptolib · CWE-913 | Kritik9,9 | — | %0,5 | 26 Nis 2025 |
39İzleyin | CVE-2024-2537İstismar yok | Electron Code Injection in Logi Tune macOS Applicationlogitech · logi tune · CWE-913 | Kritik9,8 | — | %0,3 | 15 Mar 2024 |
- CVE-2025-6861395Hemen
n8n Vulnerable to Remote Code Execution via Expression Injection
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %99n8n · n8n19 Ara 2025
- CVE-2023-4317764Bu hafta
CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.
KritikCVSS 9,8SilahlaştırılmışEPSS %82crushftp · crushftp17 Kas 2023
- CVE-2023-2901758Planlayın
vm2 Sandbox Escape vulnerability
KritikCVSS 9,8Kavram kanıtıEPSS %63vm2 project · vm26 Nis 2023
- CVE-2022-3606754Planlayın
vm2 vulnerable to Sandbox Escape before v3.9.11
KritikCVSS 10,0Kavram kanıtıEPSS %48vm2 project · vm26 Eyl 2022
- CVE-2020-1556848Planlayın
TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root.
KritikCVSS 9,8Kavram kanıtıEPSS %29terra-master · tos30 Oca 2021
- CVE-2023-618442Planlayın
Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting
YüksekCVSS 7,2İstismar yokEPSS %47citrix · virtual apps and desktops17 Oca 2024
- CVE-2024-729741Planlayın
Langflow Privilege Escalation
YüksekCVSS 8,8İstismar yokEPSS %21langflow · langflow30 Tem 2024
- CVE-2017-320241Planlayın
The implementation of Action Message Format (AMF3) deserializers in Flamingo amf-serializer by Exadel, version 2.2.0, may allow instantiation of arbitrary class
KritikCVSS 9,8İstismar yokEPSS %8exadel · flamingo11 Haz 2018
- CVE-2026-3415641Planlayın
NocoBase Affected by Sandbox Escape to RCE via console._stdout Prototype Chain Traversal in Workflow Script Node
KritikCVSS 9,9Kavram kanıtıEPSS %7nocobase · nocobase31 Mar 2026
- CVE-2023-2919941Planlayın
vm2 Sandbox escape vulnerability
KritikCVSS 10,0İstismar yokEPSS %4vm2 project · vm214 Nis 2023
- CVE-2021-3256340Planlayın
An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2.
KritikCVSS 9,8İstismar yokEPSS %3xfce · thunar11 May 2021
- CVE-2014-985240Planlayın
distribute-cache.c in ImageMagick re-uses objects after they have been destroyed, which allows remote attackers to have unspecified impact v
KritikCVSS 9,8İstismar yokEPSS %3imagemagick · imagemagick17 Mar 2017
- CVE-2026-9294640Planlayın
vm2 before 3.11.7 Remote Code Execution via require.external
KritikCVSS 10,0İstismar yokEPSS %1patriksimek · vm217 Eyl 2026
- CVE-2026-4720840Planlayın
vm2: Sandbox Breakout Using Promise Species
KritikCVSS 10,0İstismar yokEPSS %1patriksimek · vm212 Haz 2026
- CVE-2026-9295540Planlayın
vm2 before 3.11.8 Sandbox Escape via NodeVM
KritikCVSS 10,0İstismar yokEPSS %1patriksimek · vm217 Eyl 2026
- CVE-2026-4713740Planlayın
vm2: GHSA-8hg8-63c5-gwmx patch bypass: nesting:true without explicit require still allows full RCE
KritikCVSS 10,0İstismar yokEPSS %1patriksimek · vm212 Haz 2026
- CVE-2026-4713140Planlayın
vm2 is an open source vm/sandbox for Node.js.
KritikCVSS 10,0İstismar yokEPSS %1patriksimek · vm212 Haz 2026
- CVE-2026-4769839İzleyin
vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
KritikCVSS 9,8İstismar yokEPSS %1patriksimek · vm217 Ağu 2026
- CVE-2021-2238739İzleyin
There is an Improper Control of Dynamically Managing Code Resources Vulnerability in Huawei Smartphone.Successful exploitation of this vulne
KritikCVSS 9,8İstismar yokEPSS %1huawei · emui2 Ağu 2021
- CVE-2023-3727139İzleyin
RestrictedPython vulnerable to arbitrary code execution via stack frame sandbox escape
KritikCVSS 9,9İstismar yokEPSS %1zope · restrictedpython11 Tem 2023
- CVE-2026-4721039İzleyin
vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass
KritikCVSS 9,8İstismar yokEPSS %1patriksimek · vm212 Haz 2026
- CVE-2025-2527039İzleyin
Remote Code Execution via Unauthenticated Configuration Manipulation
KritikCVSS 9,8İstismar yokEPSS %1phoenixcontact · charx sec-3000 firmware8 Tem 2025
- CVE-2023-2556039İzleyin
JSON Injection in DataHub
KritikCVSS 9,8İstismar yokEPSS %1datahub · datahub10 Şub 2023
- CVE-2025-4667339İzleyin
NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space D
KritikCVSS 9,9İstismar yokEPSS %0nasa · cryptolib26 Nis 2025
- CVE-2024-253739İzleyin
Electron Code Injection in Logi Tune macOS Application
KritikCVSS 9,8İstismar yokEPSS %0logitech · logi tune15 Mar 2024