The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.
Volume of CVEs assigned to CWE-913 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
92 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-68613HIGH n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnera | Dec 19, 2025 | 8.8 | 99 | YES | YES |
CVE-2023-43177CRITICAL CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes. | Nov 18, 2023 | 9.8 | 88 | NO | YES |
CVE-2023-50386HIGH Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Control Sphere vulnerability in A | Feb 9, 2024 | 8.8 | 82 | NO | YES |
CVE-2026-34156CRITICAL NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's Workflow Script Node executes u | Mar 31, 2026 | 9.9 | 76 | NO | YES |
CVE-2023-29017CRITICAL vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Prior to version 3.9.15, vm2 was not properly handling host objects passed to `Error.prepareS | Apr 6, 2023 | 9.8 | 68 | NO | NO |
CVE-2022-36067CRITICAL vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9.11, a threat actor can bypass the sandbox protections to gai | Sep 6, 2022 | 10.0 | 58 | NO | NO |
CVE-2020-15568CRITICAL TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php | Jan 30, 2021 | 9.8 | 57 | NO | YES |
CVE-2023-6184HIGH Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting | Jan 18, 2024 | 7.2 | 49 | NO | NO |
CVE-2006-7079CRITICAL Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables and conduct directory traversal | Mar 2, 2007 | 9.8 | 47 | NO | YES |
CVE-2024-5452CRITICAL A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement | Jun 6, 2024 | 9.8 | 44 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.