CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

Parent: CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

326 vulnerabilities with CWE-88
CVE-2020-7769 HIGH
nodemailer <6.4.16 - Command Injection
CVSS 8.6
CVE-2020-25268 HIGH
Ilias - Remote Code Execution
CVSS 8.8
CVE-2020-27129 MEDIUM
Cisco SD-WAN vManage Software - Command Injection
CVSS 6.7
CVE-2020-5648 CRITICAL
GOT 1000 series - Argument Injection
CVSS 9.8
CVE-2020-5657 MEDIUM
MELSEC iQ-R - Command Injection
CVSS 6.5
CVE-2020-15238 HIGH
Blueman <2.1.4 - Command Injection
CVSS 7.1
CVE-2020-5792 HIGH
Nagios XI 5.7.3 - Command Injection
CVSS 7.2
CVE-2020-14027 MEDIUM
Ozeki NG SMS Gateway <4.17.6 - SQL Injection
CVSS 5.3
CVE-2020-4492 MEDIUM
IBM Spectrum Scale < 4.2.3.21 - Denial of Service
CVSS 5.5
CVE-2020-15692 CRITICAL
Nim 1.2.4 - Command Injection
CVSS 9.8
CVE-2020-17367 HIGH
Firejail <0.9.62 - Command Injection
CVSS 7.8
CVE-2020-13699 HIGH
TeamViewer Unquoted URI Handler SMB Redirect
CVSS 8.8
CVE-2020-3380 HIGH
Cisco DCNM - Privilege Escalation
CVSS 7.8
CVE-2020-5599 CRITICAL
Mitsubishi Electric GOT2000 - Argument Injection
CVSS 9.8
CVE-2020-14049 HIGH
Viber for Windows <13.2.0.39 - Code Injection
CVSS 7.5
CVE-2020-14421 HIGH
aaPanel <6.6.6 - Command Injection
CVSS 7.2
CVE-2020-7496 HIGH
EcoStruxure Operator Terminal Expert <3.1 SP1 - Code Injection
CVSS 7.8
CVE-2020-7808 HIGH
RAONWIZ K Upload <v2018.0.2.51 - Code Injection
CVSS 8.7
CVE-2020-1738 LOW
Ansible Engine - Code Injection
CVSS 3.9
CVE-2020-5546 HIGH
Mitsubishi Electric MELQIC IU1 <1.0.7 - Command Injection
CVSS 8.8
CVE-2020-6799 HIGH
Firefox - Command Injection
CVSS 8.8
CVE-2019-10800 MEDIUM
codecov <2.0.16 - Code Injection
CVSS 6.5
CVE-2019-18888 HIGH
Symfony <4.3.8 - Command Injection
CVSS 7.5
CVE-2019-5013 HIGH
Wacom 6.3.32-3 - Privilege Escalation
CVSS 7.8
CVE-2019-5012 HIGH
Wacom 6.3.32-3 - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities 326