CWE-913
92 CVEs • Abstraction: Class
Improper Control of Dynamically-Managed Code Resources
The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.
CVEs (92)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass. |
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker SSTI. |
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9.11, a threat actor can bypass the sandbox protections to gain remote code execution rights on the ho...Show more |
Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverified 3th party package |
1Palantir 1Foundry Multipass Jun 17, 2026 Jun 14, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The Multipass service was found to have code paths that could be abused to cause a denial of service for authentication or authorization operations. A malicious attacker could perform an application-level denial of servi...Show more |
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker static methods. |
EC-CUBE 3.0.0 to 3.0.18-p3 and EC-CUBE 4.0.0 to 4.1.1 improperly handle HTTP Host header values, which may lead a remote unauthenticated attacker to direct the vulnerable version of EC-CUBE to send an Email with some for...Show more |
2Linux Netapp9Baseboard Management Controller Firmware H300e FirmwareH300s Firmware+6 moreJun 17, 2026 Feb 16, 2022 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 In the Linux kernel through 5.16.10, certain binary files may have the exec-all attribute if they were built in approximately 2003 (e.g., with GCC 3.2.2 and Linux kernel 2.4.20). This can cause execution of bytes located...Show more |
1Thalesgroup 1Sentinel Protection Installer Jun 17, 2026 Dec 20, 2021 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 Improper Access Control of Dynamically-Managed Code Resources (DLL) in Thales Sentinel Protection Installer could allow the execution of arbitrary code. |
Authenticated administrators may modify the main YAML configuration file and load a Java class resulting in RCE. |
Authenticated users with Administrator or Developer roles may execute OS commands by Groovy Script which uses Groovy lib to render a webpage. The groovy script does not have security restrictions, which will cause attack...Show more |
Authenticated users with Administrator or Developer roles may execute OS commands by SPEL Expression in Spring beans. SPEL Expression does not have security restrictions, which will cause attackers to execute arbitrary c...Show more |
Traefik is an HTTP reverse proxy and load balancer. Prior to version 2.4.13, there exists a potential header vulnerability in Traefik's handling of the Connection header. Active exploitation of this issue is unlikely, as...Show more |
There is an Improper Control of Dynamically Managing Code Resources Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may allow attempts to remotely execute commands. |
An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2. When called with a regular file as a command-line argument, it delegates to a different program (based on the file type) without user confirmation...Show more |
1Isolated Vm Project 1Isolated Vm Jun 17, 2026 Mar 30, 2021 N/A· v4 9.6 CRITICAL· v3 5.8 MEDIUM· v2 isolated-vm is a library for nodejs which gives you access to v8's Isolate interface. Versions of isolated-vm before v4.0.0 have API pitfalls which may make it easy for implementers to expose supposed secure isolates to...Show more |
TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php, in which an attacker can trigger a cal...Show more |
1Godaddy 1Node Config Shield Jun 17, 2026 Jan 27, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 scripts/cli.js in the GoDaddy node-config-shield (aka Config Shield) package before 0.2.2 for Node.js calls eval when processing a set command. NOTE: the vendor reportedly states that this is not a vulnerability. The set...Show more |
1Cisco 1Webex Meetings Server Jun 17, 2026 Nov 18, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to join a Webex session without appearing on the participant list. This vulnerability is due to impr...Show more |
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker template exposed objects. This issue affects: Cr...Show more |