CWE-913

Improper Control of Dynamically-Managed Code Resources

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.

90 vulnerabilities with CWE-913
CVE-2025-61780 MEDIUM
Rack < 2.2.20 - Proxy Request Redirection via Untrusted x-sendfile Headers
CVSS 5.8
CVE-2025-9905 HIGH
Keras 3.0.0 to 3.11.3 HDF5 Model Load - Python Code Execution
CVSS 7.3
CVE-2025-25270 CRITICAL
Phoenix Contact CHARX SEC-3000 Series - Configuration-Based Root Code Execution
CVSS 9.8
CVE-2025-6705 MEDIUM
Eclipse Open VSX Registry - Privilege Escalation
CVSS 5.3
CVE-2025-6384 CRITICAL
CrafterCMS 4.0.0-4.2.2 - Authenticated Remote Code Execution via Groovy Sandbox Bypass
CVSS 9.1
CVE-2025-6107 LOW
comfyanonymous comfyui <0.3.40 - Code Injection
CVSS 3.1
CVE-2025-46675 LOW
NASA CryptoLib <1.3.2 - Memory Corruption
CVSS 3.5
CVE-2025-46673 MEDIUM
NASA CryptoLib <1.3.2 - Auth Bypass
CVSS 4.9
CVE-2025-31674 HIGH
Drupal Drupal core <10.3.13-11.1.3 - Object Injection
CVSS 7.5
CVE-2024-5401 MEDIUM
Synology DSM <7.1.1-42962-8, <7.2.1-69057-2, <7.2.2-72806 - Privile...
CVSS 4.3
CVE-2024-8953 CRITICAL
composio < 0.5.43 - Remote Code Execution via Mathematical Calculator Endpoint
CVSS 9.8
CVE-2024-7297 HIGH
Langflow < 1.0.13 - Privilege Escalation via Mass Assignment on Users Endpoint
CVSS 8.8
CVE-2024-5452 CRITICAL
pytorch_lightning < 2.3.3 - Remote Code Execution via Deepdiff Delta Dunder Attribute Bypass
CVSS 9.8
CVE-2024-2537 MEDIUM
Logitech Logi Tune - Local Code Inclusion
CVSS 4.4
CVE-2024-27135 HIGH
Apache Pulsar 2.4.0-2.10.5, 2.11.0-2.11.3, 3.0.0-3.0.2, 3.1.0-3.1.2, 3.2.0 - Remote Code Execution
CVSS 8.5
CVE-2023-50386 HIGH
Apache Solr Backup/Restore APIs RCE
CVSS 8.8
CVE-2023-6184 MEDIUM
Citrix Virtual Apps and Desktops - Cross-Site Scripting
CVSS 5.0
CVE-2023-31032 HIGH
NVIDIA DGX A100 SBIOS < 1.25 - Denial of Service via Dynamic Variable Evaluation
CVSS 7.5
CVE-2023-43177 CRITICAL
CrushFTP Unauthenticated RCE
CVSS 9.8
CVE-2023-5763 MEDIUM
Eclipse Glassfish 5.0.0-6.2.4 - Remote Code Execution via Insecure ORB Listeners
CVSS 6.8
CVE-2023-39983 MEDIUM
MXsecurity <1.0.1 - Info Disclosure
CVSS 5.3
CVE-2023-4041 CRITICAL
Silicon Labs Gecko Bootloader - Classic Buffer Overflow
CVSS 9.8
CVE-2023-37271 HIGH
RestrictedPython <6.1, 5.3 - Code Injection
CVSS 8.4
CVE-2023-35930 LOW
SpiceDB 1.22.0 - Incorrect Authorization Decision via LookupResources API
CVSS 3.7
CVE-2023-33175 CRITICAL
toui 2.0.1-2.4.0 - Unauthenticated Remote Code Execution via Flask-Caching SimpleCache
CVSS 9.1
Details
Vulnerabilities 90