CWE · MITRE source
CWE-913Improper Control of Dynamically-Managed Code Resources
The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.
Many languages offer powerful features that allow the programmer to dynamically create or modify existing code, or resources used by code such as variables and objects. While these features can offer significant flexibility and reduce development time, they can be extremely dangerous if attackers can directly influence these code resources in unexpected ways.
Last updated: 22 August 2026 14:14 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: partial · 2 mapping(s) from 2 framework(s): STIG windows 10 1 (partial) · STIG windows 11 1 (partial)
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
DE.CM-09
- 2 hardening rules · 2 OS baselines
—
NIST 800-53 r5 controls that address this weakness (1)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
SC-18 | Mobile Code | SC | Requiring explicit authorization and ongoing control of mobile code implements proper management of dynamically loaded code resources. |
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2023-43177 UPD | 9.9 | 9.8 | 0.8180 | 2023-11-18 |
CVE-2023-29017 UPD | 9.7 | 10.0 | 0.6319 | 2023-04-06 |
CVE-2025-68613 KEV UPD | 9.6 | 9.9 | 0.9795 | 2025-12-19 |
CVE-2022-36067 UPD | 9.4 | 10.0 | 0.4787 | 2022-09-06 |
CVE-2023-50386 UPD | 9.1 | 8.8 | 0.8384 | 2024-02-09 |
CVE-2020-15568 UPD | 8.8 | 9.8 | 0.2920 | 2021-01-30 |
CVE-2024-5452 UPD | 8.7 | 9.8 | 0.2649 | 2024-06-06 |
CVE-2026-34156 UPD | 8.7 | 9.9 | 0.3650 | 2026-03-31 |
CVE-2006-7079 UPD | 8.3 | 9.8 | 0.1285 | 2007-03-02 |
CVE-2017-3202 UPD | 8.1 | 9.8 | 0.0818 | 2018-06-11 |
CVE-2023-29199 UPD | 7.9 | 9.8 | 0.0385 | 2023-04-14 |
CVE-2025-66398 | 7.9 | 9.6 | 0.1861 | 2026-01-01 |
CVE-2014-9852 UPD | 7.8 | 9.8 | 0.0293 | 2017-03-17 |
CVE-2021-32563 UPD | 7.8 | 9.8 | 0.0310 | 2021-05-11 |
CVE-2024-7297 UPD | 7.8 | 8.8 | 0.2135 | 2024-07-30 |
CVE-2026-53753 | 7.7 | 9.8 | 0.0209 | 2026-06-23 |
CVE-2026-23830 UPD | 7.6 | 10.0 | 0.0112 | 2026-01-28 |
CVE-2026-47210 | 7.6 | 9.8 | 0.0180 | 2026-06-12 |
CVE-2021-22387 UPD | 7.5 | 9.8 | 0.0095 | 2021-08-02 |
CVE-2022-44000 UPD | 7.5 | 9.8 | 0.0095 | 2022-11-16 |
CVE-2024-8953 UPD | 7.5 | 9.8 | 0.0118 | 2025-03-20 |
CVE-2026-22709 UPD | 7.5 | 9.8 | 0.0122 | 2026-01-26 |
CVE-2026-47131 | 7.5 | 10.0 | 0.0062 | 2026-06-12 |
CVE-2026-47208 | 7.5 | 10.0 | 0.0076 | 2026-06-12 |
CVE-2025-25270 UPD | 7.4 | 9.8 | 0.0063 | 2025-07-08 |