CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.
393 vulnerabilities with CWE-88
CVE-2026-2298
CRITICAL
Salesforce Marketing Cloud Engagement - Command Injection
CVSS 9.4
CVE-2026-4438
MEDIUM
gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames
CVSS 5.4
CVE-2026-4519
LOW
webbrowser.open() allows leading dashes in URLs
CVSS 3.3
CVE-2026-29608
MEDIUM
OpenClaw 2026.3.1 < 2026.3.2 - Approval Integrity Bypass via system.run argv Rewriting
CVSS 6.7
CVE-2026-22168
MEDIUM
OpenClaw < 2026.2.21 - Command Injection via cmd.exe /c Trailing Arguments in system.run
CVSS 6.5
CVE-2026-32304
CRITICAL
locutus < 3.0.14 - Remote Code Execution via create_function
CVSS 9.8
CVE-2026-1717
MEDIUM
Lenovo Vantage/Baiying - Privilege Escalation
CVSS 5.5
CVE-2026-1716
HIGH
Lenovo Vantage/Baiying - Privilege Escalation
CVSS 7.1
CVE-2026-1715
HIGH
Lenovo Vantage/Baiying - Privilege Escalation
CVSS 7.1
CVE-2026-25689
MEDIUM
Fortinet FortiDeceptor - Command Injection
CVSS 6.5
CVE-2026-3682
MEDIUM
welovemedia FFmate <=2.0.15 - Command Injection
CVSS 6.3
CVE-2026-26194
HIGH
Gogs < 0.14.2 - Argument Injection via Git Tag Deletion
CVSS 7.3
CVE-2026-20016
MEDIUM
Cisco FXOS Software - Command Injection
CVSS 6.0
CVE-2026-20063
MEDIUM
Cisco Secure FTD Software - Command Injection
CVSS 6.0
CVE-2026-26514
HIGH
bird-lg-go <6187a4e - Argument Injection
CVSS 7.5
CVE-2026-27947
HIGH
Group-Office <26.0.9 - Authenticated RCE
CVSS 8.8
CVE-2026-27613
CRITICAL
TinyWeb < 2.01 - Unauthenticated Argument Injection via CGI Parameter Bypass
CVSS 9.8
CVE-2026-27208
CRITICAL
bleon-ethical/api-gateway-deploy 1.0.0 - Command Injection
CVSS 9.2
CVE-2026-24126
MEDIUM
Weblate <5.16.0 - Command Injection
CVSS 6.6
CVE-2026-25134
HIGH
Group-Office <6.8.150, 25.0.82, 26.0.5 - RCE
CVSS 8.8
CVE-2026-24739
MEDIUM
Symfony <5.4.51-8.0.5 - Code Injection
CVSS 6.3
CVE-2026-22583
CRITICAL
Salesforce Marketing Cloud Engagement - Command Injection
CVSS 9.8
CVE-2026-22582
CRITICAL
Salesforce Marketing Cloud Engagement - Command Injection
CVSS 9.8
CVE-2026-0774
HIGH
WatchYourLAN Configuration Page - arpstrs Argument Injection Code Execution
CVSS 8.8
CVE-2026-24061
CRITICAL
KEV
GNU Inetutils Telnet Authentication Bypass Exploit CVE-2026-24061
CVSS 9.8
Details
Vulnerabilities
393