The product does not properly restrict reading from or writing to dynamically-identified variables.
Volume of CVEs assigned to CWE-914 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-44006CRITICAL vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary prototypes. This vulnerability | May 13, 2026 | 10.0 | 41 | NO | NO |
CVE-2026-34444CRITICAL Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in function | Apr 6, 2026 | 10.0 | 36 | NO | NO |
CVE-2025-14085HIGH A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. This impacts an unknown function of the file /app-api/v1/orders/. The manipulation of the argument orderId lea | Dec 5, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-14051HIGH A flaw has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function getById/updateAddress/deleteAddress of the file /mall-ums/app-api/v1/addresses/. Executing man | Dec 4, 2025 | 8.8 | 28 | NO | NO |
CVE-2024-54198HIGH In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, which can be | Dec 10, 2024 | 8.5 | 24 | NO | NO |
CVE-2024-24914HIGH Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vulnerability is available. | Nov 7, 2024 | 8.0 | 23 | NO | NO |
CVE-2023-33175HIGH ToUI is a Python package for creating user interfaces (websites and desktop apps) from HTML. ToUI is using Flask-Caching (SimpleCache) to store user variables. Websites that use `W | May 30, 2023 | 7.5 | 22 | NO | NO |
CVE-2026-35173MEDIUM Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, an IDOR / Mass Assignment issue exists in the Post model that allows authenticated users with post editing per | Apr 6, 2026 | 6.5 | 21 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.