CWE-913: CWE-913

22
Total CVEs
8
Critical
7
High
8.1
Avg CVSS

Yearly Trend

2026
1
2025
12
2024
1
2023
3
2022
2

Top Affected Vendors

1 Youlai 2
2 Craftercms 2
3 Vm2 Project 2
4 Xfce 1
5 Synology 1
6 N8n 1
7 Langflow 1
8 Apache 1
9 Huawei 1
10 Ivanti 1

All CWE-913 CVEs (22)

CVE-2023-29017
10.0

CVE-2023-29017 is a critical sandbox escape vulnerability in vm2 that allows attackers to bypass sandbox protections and execute arbitrary code on the...

Apr 6, 2023
CVE-2026-25049
9.9

This vulnerability allows authenticated users with workflow creation/modification permissions in n8n to execute arbitrary system commands on the host ...

Feb 4, 2026
CVE-2025-25270
9.8

This critical vulnerability allows unauthenticated remote attackers to modify device configurations, potentially leading to remote code execution with...

Jul 8, 2025
CVE-2023-29199
9.8

This vulnerability in vm2's exception sanitization logic allows attackers to bypass sandbox protections and execute arbitrary code on the host system....

Apr 14, 2023
CVE-2021-22387
9.8

This vulnerability in Huawei smartphones allows improper control of dynamically managed code resources, potentially enabling remote command execution....

Aug 2, 2021
CVE-2021-32563
9.8

Thunar file manager versions before 4.16.7 and 4.17.x before 4.17.2 automatically execute files without user confirmation when opened as command-line ...

May 11, 2021
CVE-2020-15568
9.8

CVE-2020-15568 is a critical remote code execution vulnerability in TerraMaster TOS that allows attackers to execute arbitrary commands as root throug...

Jan 30, 2021
CVE-2025-6384
9.1

This vulnerability allows authenticated developers in CrafterCMS to bypass Groovy sandbox restrictions and execute arbitrary operating system commands...

Jun 19, 2025
CVE-2025-13659
8.8

This vulnerability in Ivanti Endpoint Manager allows remote, unauthenticated attackers to write arbitrary files to the server, which could lead to rem...

Dec 9, 2025
CVE-2024-7297
8.8

Langflow versions before 1.0.13 contain a privilege escalation vulnerability where remote attackers with low privileges can gain super admin access by...

Jul 30, 2024
CVE-2022-3225
8.8

This vulnerability in Budibase allows attackers to execute arbitrary code by exploiting improper control of dynamically-managed code resources. It aff...

Sep 16, 2022
CVE-2022-31764
8.5

This vulnerability allows authenticated attackers to execute arbitrary code on Apache ShardingSphere ElasticJob-UI servers by exploiting a flaw in H2 ...

Feb 6, 2025
CVE-2023-25560
8.2

This vulnerability in DataHub's AuthServiceClient allows attackers to manipulate JSON strings with user-controlled data, potentially leading to authen...

Feb 11, 2023
CVE-2025-54065
7.9

CVE-2025-54065 is a critical memory corruption vulnerability in GZDoom that allows arbitrary code execution through crafted ZScript actor state handli...

Dec 3, 2025
CVE-2021-23267
7.6

This vulnerability allows authenticated developers in Crafter CMS Studio to execute arbitrary operating system commands through FreeMarker static meth...

May 16, 2022
CVE-2025-14695
6.3

This vulnerability in SamuNatsu HaloBot allows remote attackers to execute arbitrary code by manipulating the 'action' argument in the html_renderer p...

Dec 15, 2025
CVE-2025-14085
6.3

This vulnerability in youlaitech youlai-mall allows remote attackers to manipulate the orderId parameter in the /app-api/v1/orders/ endpoint, leading ...

Dec 5, 2025
CVE-2025-14051
6.3

This vulnerability in youlaitech youlai-mall allows attackers to manipulate dynamically-identified variables through the getById/updateAddress/deleteA...

Dec 4, 2025
CVE-2025-26405
5.9

This vulnerability in Intel NPU drivers allows unprivileged user applications to cause a denial of service through improper control of dynamically-man...

Nov 11, 2025
CVE-2025-46673
4.9

NASA CryptoLib versions before 1.3.2 fail to verify the operational state of Security Associations (SAs) before use, potentially allowing attackers to...

Apr 27, 2025
CVE-2024-5401
4.3

This vulnerability allows authenticated remote users to escalate privileges without authorization in Synology DiskStation Manager and Unified Controll...

Dec 4, 2025
CVE-2025-13426
N/A

This vulnerability in Google Apigee's JavaCallout policy allows attackers to inject malicious Java objects into the MessageContext, enabling remote co...

Dec 5, 2025

About CWE-913 (CWE-913)

Our database tracks 22 CVEs classified as CWE-913, with 8 rated critical and 7 rated high severity. The average CVSS score for CWE-913 vulnerabilities is 8.1.

External reference: View CWE-913 on MITRE CWE →

Monitor CWE-913 Vulnerabilities

Get alerted when new CWE-913 CVEs affect your infrastructure.

Start Monitoring Free