CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.
394 vulnerabilities with CWE-88
CVE-2024-41711
MEDIUM
Mitel 6800-6900w Series - Command Injection
CVSS 6.8
CVE-2024-41710
HIGH
KEV
Mitel 6800-6900w Series - Command Injection
CVSS 7.2
CVE-2024-39933
HIGH
Gogs < 0.13.0 - Argument Injection via Release Tagging
CVSS 7.7
CVE-2024-39930
CRITICAL
Gogs < 0.13.0 - Authenticated Remote Code Execution via SSH --split-string Argument Injection
CVSS 9.9
CVE-2024-35307
CRITICAL
Pandora FMS 700-776 - Unauthenticated Remote Code Execution via Realtime Graph Extension Argument Injection
CVSS 9.8
CVE-2024-2422
HIGH
LenelS2 NetBox <5.6.1 - Authenticated RCE
CVSS 8.8
CVE-2024-31966
MEDIUM
Mitel 6800/6900 Series SIP Phones Authenticated Argument Injection
CVSS 6.2
CVE-2024-32884
MEDIUM
gix-transport < 0.42.0 - Command Injection via SSH URL Username Smuggling
CVSS 6.4
CVE-2024-3684
HIGH
GitHub Enterprise Server < 3.9.13 - Authenticated Server-Side Request Forgery in Management Console
CVSS 8.0
CVE-2024-32462
HIGH
flatpak < 1.10.9, 1.12.9, 1.14.6, 1.15.8 - Sandbox Escape via Bubblewrap Argument Injection
CVSS 8.4
CVE-2024-3817
CRITICAL
HashiCorp's go-getter - Code Injection
CVSS 9.8
CVE-2024-3367
MEDIUM
Checkmk <2.2.0p26,<2.3.0b5 - Command Injection
CVSS 6.5
CVE-2024-3775
MEDIUM
aEnrich Technology a+HRD - Code Injection
CVSS 5.3
CVE-2024-24576
CRITICAL
Rust <1.77.2 - Command Injection
CVSS 10.0
CVE-2024-22182
HIGH
Commend WS203VICM < 1.7 - Unauthenticated Denial of Service via Crafted Web Server Messages
CVSS 8.6
CVE-2024-23731
CRITICAL
embedchain < 0.1.57 - Remote Code Execution via OpenAPI Loader YAML Deserialization
CVSS 9.8
CVE-2024-20287
MEDIUM
Cisco WAP371 Wireless-AC/N Dual Radio - Command Injection
CVSS 6.5
CVE-2023-50232
HIGH
Inductive Automation Ignition 8.1.0-8.1.33 - Remote Code Execution via getParams Argument Injection
CVSS 8.8
CVE-2023-44452
HIGH
Linux Mint Xreader - Remote Code Execution via CBT File Parsing Argument Injection
CVSS 7.8
CVE-2023-20260
MEDIUM
Cisco Prime Infrastructure - Privilege Escalation
CVSS 6.0
CVE-2023-6634
HIGH
LearnPress <4.2.5.7 - Command Injection
CVSS 8.1
CVE-2023-47804
HIGH
Apache OpenOffice < 4.1.15 - Unauthenticated Arbitrary Script Execution via Macro Link Activation
CVSS 8.8
CVE-2023-46681
HIGH
VR-S1000 Firmware < 2.37 - Authenticated OS Command Injection via CLI
CVSS 7.8
CVE-2023-6792
MEDIUM
PAN-OS 8.1.0-8.1.23 - Authenticated OS Command Injection via XML API
CVSS 5.5
CVE-2023-49096
HIGH
jellyfin < 10.8.13 - Unauthenticated Argument Injection via Video and Audio Stream Endpoints
CVSS 7.7
Details
Vulnerabilities
394