CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

Parent: CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

326 vulnerabilities with CWE-88
CVE-2022-47926 CRITICAL
AyaCMS 3.1.2 - Path Traversal
CVSS 9.8
CVE-2022-44731 MEDIUM
SIMATIC WinCC OA - Command Injection
CVSS 5.4
CVE-2022-23740 HIGH
Github Enterprise Server - Remote Code Execution
CVSS 8.8
CVE-2022-45062 CRITICAL
Xfce xfce4-settings <4.16.4-4.17.1 - Command Injection
CVSS 9.8
CVE-2022-42968 CRITICAL
Gitea <1.17.3 - Code Injection
CVSS 9.8
CVE-2022-3140 MEDIUM
LibreOffice - RCE
CVSS 6.3
CVE-2022-20930 MEDIUM
Cisco Catalyst Sd-wan Manager < 20.6.2 - Denial of Service
CVSS 6.7
CVE-2022-37027 HIGH
Ahsay Cloud Backup Suite - Remote Code Execution
CVSS 7.2
CVE-2022-36069 HIGH
Poetry - Info Disclosure
CVSS 7.3
CVE-2022-36804 HIGH KEV
Atlassian Bitbucket Server/Data Center <7.6.17/<7.17.10/<7.21.4/<8....
CVSS 8.8
CVE-2022-1399 CRITICAL
Device42 CMDB <18.01.00 - Command Injection
CVSS 9.1
CVE-2022-37005 HIGH
Settings - Command Injection
CVSS 7.5
CVE-2022-25973 HIGH
mc-kill-port - Code Injection
CVSS 7.8
CVE-2022-36322 MEDIUM
JetBrains TeamCity <2022.04.2 - Code Injection
CVSS 5.4
CVE-2022-25900 HIGH
Git-clone - Command Injection
CVSS 8.1
CVE-2022-31084 HIGH
LDAP Account Manager <8.0 - Code Injection
CVSS 8.1
CVE-2022-31246 MEDIUM
Electrum <4.2.2 - DoS
CVSS 5.5
CVE-2022-24376 HIGH
git-promise - Command Injection
CVSS 7.2
CVE-2022-26532 HIGH
Zyxel USG/ZyWALL series <4.71 - Command Injection
CVSS 7.8
CVE-2022-29215 HIGH
RegionProtect <1.1.0 - Code Injection
CVSS 7.5
CVE-2022-29184 HIGH
GoCD <22.1.0 - Authenticated RCE
CVSS 8.8
CVE-2022-25865 HIGH
Microsoft Workspace-tools < 0.18.4 - Command Injection
CVSS 8.1
CVE-2022-30240 HIGH
Magnitude Simba Amazon Redshift JDBC Driver <1.2.55 - Command Injec...
CVSS 7.8
CVE-2022-30239 HIGH
Magnitude Simba Amazon Athena JDBC Driver <2.0.29 - Command Injection
CVSS 7.8
CVE-2022-29972 HIGH
Magnitude Simba Amazon Redshift ODBC Driver <1.4.52 - Command Injec...
CVSS 7.8
Details
Vulnerabilities 326