Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-913

Improper Control of Dynamically-Managed Code Resources

The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.

92
Assigned CVEs
182nd
Commonality Rank
8.2
Avg CVSS
1.1%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-913 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 2, 2007
19 years ago
Most Recent CVE
Jun 23, 2026
31 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

92 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-68613HIGH
n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnera
Dec 19, 20258.899YESYES
CVE-2023-43177CRITICAL
CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.
Nov 18, 20239.888NOYES
CVE-2023-50386HIGH
Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Control Sphere vulnerability in A
Feb 9, 20248.882NOYES
CVE-2026-34156CRITICAL
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's Workflow Script Node executes u
Mar 31, 20269.976NOYES
CVE-2023-29017CRITICAL
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Prior to version 3.9.15, vm2 was not properly handling host objects passed to `Error.prepareS
Apr 6, 20239.868NONO
CVE-2022-36067CRITICAL
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9.11, a threat actor can bypass the sandbox protections to gai
Sep 6, 202210.058NONO
CVE-2020-15568CRITICAL
TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php
Jan 30, 20219.857NOYES
CVE-2023-6184HIGH
Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting
Jan 18, 20247.249NONO
CVE-2006-7079CRITICAL
Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables and conduct directory traversal
Mar 2, 20079.847NOYES
CVE-2024-5452CRITICAL
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement
Jun 6, 20249.844NONO
View all 92 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
11%
19%
5.0-5.9
16%
6.0-6.9
18%
26%
7.0-7.9
16%
11%
8.0-8.9
42%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
1 CVE
1.1% of CVEs· 91st percentile
Metasploit
3 CVEs
3.3% of CVEs· 95th percentile
Nuclei
4 CVEs
4.3% of CVEs· 95th percentile
ExploitDB
2 CVEs
2.2% of CVEs· 88th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products