CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.
359 vulnerabilities with CWE-88
CVE-2021-21384
MEDIUM
shescape < 1.1.3 - Command Injection via Newline Character
CVSS 6.3
CVE-2021-24030
CRITICAL
Facebook Gameroom <1.26.0 - Code Injection
CVSS 9.8
CVE-2021-26937
CRITICAL
GNU Screen < 4.8.0 - Denial of Service via Crafted UTF-8 Character Sequence
CVSS 9.8
CVE-2021-3401
CRITICAL
Bitcoin Core < 0.19.0 - Remote Code Execution via -platformpluginpath Argument Injection
CVSS 9.8
CVE-2020-7851
HIGH
Innorix Web-Based File Transfer Solution <9.2.18.385 - RCE
CVSS 7.8
CVE-2020-7850
HIGH
Douzone NBBDownloader.ocx - Remote File Download and Execution via ActiveX Method
CVSS 7.8
CVE-2020-21224
CRITICAL
Inspur ClusterEngine V4.0 - Remote Code Execution via Malicious Login Packet
CVSS 9.8
CVE-2020-35136
HIGH
Dolibarr <12.0.3 - Authenticated RCE
CVSS 7.2
CVE-2020-7769
HIGH
nodemailer <6.4.16 - Command Injection
CVSS 8.6
CVE-2020-25268
HIGH
ILIAS 6.4 - Remote Code Execution via External News Feed Parameter
CVSS 8.8
CVE-2020-27129
MEDIUM
Cisco SD-WAN vManage Software - Command Injection
CVSS 6.7
CVE-2020-5648
CRITICAL
GOT 1000 series - Argument Injection
CVSS 9.8
CVE-2020-5657
MEDIUM
MELSEC iQ-R Series Firmware - Unauthenticated Denial of Service via Crafted TCP/IP Packet
CVSS 6.5
CVE-2020-15238
HIGH
Blueman < 2.1.4 - Command Injection via DhcpClient D-Bus Method
CVSS 7.1
CVE-2020-5792
HIGH
Nagios XI 5.7.3 - Command Injection
CVSS 7.2
CVE-2020-14027
MEDIUM
Ozeki NG SMS Gateway <4.17.6 - SQL Injection
CVSS 5.3
CVE-2020-4492
MEDIUM
IBM Spectrum Scale 4.2.0.0-4.2.3.21 and 5.0.0.0-5.0.4.3 - Denial of Service via Invalid Ioctl Arguments
CVSS 5.5
CVE-2020-15692
CRITICAL
Nim < 1.2.6 - Argument Injection via browsers.openDefaultBrowser
CVSS 9.8
CVE-2020-17367
HIGH
Firejail <0.9.62 - Command Injection
CVSS 7.8
CVE-2020-13699
HIGH
TeamViewer Unquoted URI Handler SMB Redirect
CVSS 8.8
CVE-2020-3380
HIGH
Cisco Data Center Network Manager < 11.4(1) - Authenticated Privilege Escalation via CLI Command Injection
CVSS 7.8
CVE-2020-5599
CRITICAL
Mitsubishi Electric GOT2000 - Argument Injection
CVSS 9.8
CVE-2020-14049
HIGH
Viber for Windows <13.2.0.39 - Code Injection
CVSS 7.5
CVE-2020-14421
HIGH
aaPanel < 6.6.6 - Authenticated Remote Code Execution via Cron Job Script Content
CVSS 7.2
CVE-2020-7496
HIGH
EcoStruxure Operator Terminal Expert <3.1 SP1 - Code Injection
CVSS 7.8
Details
Vulnerabilities
359