CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.
394 vulnerabilities with CWE-88
CVE-2020-14027
MEDIUM
Ozeki NG SMS Gateway <4.17.6 - SQL Injection
CVSS 5.3
CVE-2020-4492
MEDIUM
IBM Spectrum Scale 4.2.0.0-4.2.3.21 and 5.0.0.0-5.0.4.3 - Denial of Service via Invalid Ioctl Arguments
CVSS 5.5
CVE-2020-15692
CRITICAL
Nim < 1.2.6 - Argument Injection via browsers.openDefaultBrowser
CVSS 9.8
CVE-2020-17367
HIGH
Firejail <0.9.62 - Command Injection
CVSS 7.8
CVE-2020-13699
HIGH
TeamViewer Unquoted URI Handler SMB Redirect
CVSS 8.8
CVE-2020-3380
HIGH
Cisco Data Center Network Manager < 11.4(1) - Authenticated Privilege Escalation via CLI Command Injection
CVSS 7.8
CVE-2020-5599
CRITICAL
Mitsubishi Electric GOT2000 - Argument Injection
CVSS 9.8
CVE-2020-14049
HIGH
Viber for Windows <13.2.0.39 - Code Injection
CVSS 7.5
CVE-2020-14421
HIGH
aaPanel < 6.6.6 - Authenticated Remote Code Execution via Cron Job Script Content
CVSS 7.2
CVE-2020-7496
HIGH
EcoStruxure Operator Terminal Expert <3.1 SP1 - Code Injection
CVSS 7.8
CVE-2020-7808
HIGH
RAONWIZ K Upload <v2018.0.2.51 - Code Injection
CVSS 8.7
CVE-2020-1738
LOW
Ansible Engine - Code Injection
CVSS 3.9
CVE-2020-5546
HIGH
Mitsubishi Electric MELQIC IU1 <1.0.7 - Command Injection
CVSS 8.8
CVE-2020-6799
HIGH
Firefox < 73.0 and Firefox ESR < 68.5.0 - Command Injection via Shell Handler File Type Association
CVSS 8.8
CVE-2019-10800
MEDIUM
codecov-python < 2.0.16 - OS Command Injection via Gcov Arguments
CVSS 6.5
CVE-2019-18888
HIGH
Symfony 2.8.0-2.8.50, 3.4.0-3.4.34, 4.2.0-4.2.11, 4.3.0-4.3.7 - Argument Injection via MIME Type Validation
CVSS 7.5
CVE-2019-5013
HIGH
Wacom 6.3.32-3 - Privilege Escalation
CVSS 7.8
CVE-2019-5012
HIGH
Wacom 6.3.32-3 - Privilege Escalation
CVSS 7.8
CVE-2019-12148
CRITICAL
Sangoma Session Border Controller 2.3.23-119 GA - Auth Bypass
CVSS 9.8
CVE-2019-12147
CRITICAL
Sangoma SBC 2.3.23-119 GA - Command Injection
CVSS 9.8
CVE-2019-11751
HIGH
Firefox < 69.0 and Firefox ESR < 68.1.0 - Argument Injection via Logging Parameters
CVSS 8.8
CVE-2019-15541
HIGH
rustls < 0.16.0 - Denial of Service via Client Writable State Manipulation
CVSS 7.5
CVE-2019-10746
CRITICAL
mixin-deep < 1.3.2 - Prototype Pollution via Constructor Payload
CVSS 9.8
CVE-2019-15498
HIGH
Vera Edge Home Controller <1.7.4452 - Command Injection
CVSS 8.8
CVE-2019-12264
HIGH
Wind River VxWorks <6.9.5 - Privilege Escalation
CVSS 7.1
Details
Vulnerabilities
394