CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

Parent: CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

359 vulnerabilities with CWE-88
CVE-2024-3817 CRITICAL
HashiCorp's go-getter - Code Injection
CVSS 9.8
CVE-2024-3367 MEDIUM
Checkmk <2.2.0p26,<2.3.0b5 - Command Injection
CVSS 6.5
CVE-2024-3775 MEDIUM
aEnrich Technology a+HRD - Code Injection
CVSS 5.3
CVE-2024-24576 CRITICAL
Rust <1.77.2 - Command Injection
CVSS 10.0
CVE-2024-22182 HIGH
Commend WS203VICM < 1.7 - Unauthenticated Denial of Service via Crafted Web Server Messages
CVSS 8.6
CVE-2024-23731 CRITICAL
embedchain < 0.1.57 - Remote Code Execution via OpenAPI Loader YAML Deserialization
CVSS 9.8
CVE-2024-20287 MEDIUM
Cisco WAP371 Wireless-AC/N Dual Radio - Command Injection
CVSS 6.5
CVE-2023-50232 HIGH
Inductive Automation Ignition 8.1.0-8.1.33 - Remote Code Execution via getParams Argument Injection
CVSS 8.8
CVE-2023-44452 HIGH
Linux Mint Xreader - Remote Code Execution via CBT File Parsing Argument Injection
CVSS 7.8
CVE-2023-20260 MEDIUM
Cisco Prime Infrastructure - Privilege Escalation
CVSS 6.0
CVE-2023-6634 HIGH
LearnPress <4.2.5.7 - Command Injection
CVSS 8.1
CVE-2023-47804 HIGH
Apache OpenOffice < 4.1.15 - Unauthenticated Arbitrary Script Execution via Macro Link Activation
CVSS 8.8
CVE-2023-46681 HIGH
VR-S1000 Firmware < 2.37 - Authenticated OS Command Injection via CLI
CVSS 7.8
CVE-2023-6792 MEDIUM
PAN-OS 8.1.0-8.1.23 - Authenticated OS Command Injection via XML API
CVSS 5.5
CVE-2023-49096 HIGH
jellyfin < 10.8.13 - Unauthenticated Argument Injection via Video and Audio Stream Endpoints
CVSS 7.7
CVE-2023-6269 CRITICAL
Atos Unify OpenScape <V10 R3.4.0, V10R10.12.00, V10R11.05.02 - Comm...
CVSS 10.0
CVE-2023-0633 HIGH
Docker Desktop < 4.12.0 - Local Privilege Escalation via Installer Argument Injection
CVSS 7.2
CVE-2023-26143 MEDIUM
blamer < 1.0.4 - Arbitrary Argument Injection via blameByFile API
CVSS 6.5
CVE-2023-39288 MEDIUM
Mitel MiVoice Connect <9.6.2304.102 - Command Injection
CVSS 5.5
CVE-2023-39287 MEDIUM
Mitel MiVoice Connect <19.3 SP3 - Command Injection
CVSS 5.5
CVE-2023-20224 HIGH
Cisco ThousandEyes Enterprise Agent - Privilege Escalation
CVSS 7.8
CVE-2023-26310 HIGH
Mobile Phone Backup App - Command Injection
CVSS 7.4
CVE-2023-33378 CRITICAL
Connected IO <2.1.0 - Command Injection
CVSS 9.8
CVE-2023-33376 CRITICAL
Connected IO <2.1.0 - Command Injection
CVSS 9.8
CVE-2023-30577 HIGH
AMANDA <tag-community-3.5.4 - Info Disclosure
CVSS 7.8
Details
Vulnerabilities 359