CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.
394 vulnerabilities with CWE-88
CVE-2023-6269
CRITICAL
Atos Unify OpenScape <V10 R3.4.0, V10R10.12.00, V10R11.05.02 - Comm...
CVSS 10.0
CVE-2023-0633
HIGH
Docker Desktop < 4.12.0 - Local Privilege Escalation via Installer Argument Injection
CVSS 7.2
CVE-2023-26143
MEDIUM
blamer < 1.0.4 - Arbitrary Argument Injection via blameByFile API
CVSS 6.5
CVE-2023-39288
MEDIUM
Mitel MiVoice Connect <9.6.2304.102 - Command Injection
CVSS 5.5
CVE-2023-39287
MEDIUM
Mitel MiVoice Connect <19.3 SP3 - Command Injection
CVSS 5.5
CVE-2023-20224
HIGH
Cisco ThousandEyes Enterprise Agent - Privilege Escalation
CVSS 7.8
CVE-2023-26310
HIGH
Mobile Phone Backup App - Command Injection
CVSS 7.4
CVE-2023-33378
CRITICAL
Connected IO <2.1.0 - Command Injection
CVSS 9.8
CVE-2023-33376
CRITICAL
Connected IO <2.1.0 - Command Injection
CVSS 9.8
CVE-2023-30577
HIGH
AMANDA <tag-community-3.5.4 - Info Disclosure
CVSS 7.8
CVE-2023-34395
HIGH
Apache Airflow ODBC Provider < 4.0.0 - Command Injection via ODBC Driver Parameters
CVSS 7.8
CVE-2023-25356
HIGH
CoreDial sipXcom <=21.04 - Command Injection
CVSS 8.8
CVE-2022-31749
MEDIUM
WatchGuard Fireware OS <12.8.1-12.5.10 - Command Injection
CVSS 6.5
CVE-2022-37705
MEDIUM
Amanda 3.5.1 - Privilege Escalation via runtar SUID Argument Injection
CVSS 6.7
CVE-2022-47502
HIGH
Apache OpenOffice < 4.1.13 - Arbitrary Script Execution via Macro Link URI Scheme
CVSS 7.8
CVE-2022-40677
HIGH
Fortinet FortiNAC <9.4.0 - Command Injection
CVSS 7.2
CVE-2022-4864
MEDIUM
froxlor/froxlor <2.0.0-beta1 - Command Injection
CVSS 5.4
CVE-2022-46883
HIGH
Mozilla Firefox <106 - Memory Corruption
CVSS 8.8
CVE-2022-47926
CRITICAL
AyaCMS 3.1.2 - Unauthenticated File Deletion via fst_del.inc.php
CVSS 9.8
CVE-2022-44731
MEDIUM
SIMATIC WinCC OA - Command Injection
CVSS 5.4
CVE-2022-23740
HIGH
GitHub Enterprise Server 3.7.0 - Remote Code Execution via GitHub Pages Build
CVSS 8.8
CVE-2022-45062
CRITICAL
Xfce xfce4-settings <4.16.4-4.17.1 - Command Injection
CVSS 9.8
CVE-2022-42968
CRITICAL
Gitea < 1.17.3 - OS Command Injection via Git Ref Argument Mishandling
CVSS 9.8
CVE-2022-3140
MEDIUM
LibreOffice <7.4.1 and <7.3.6 - Macro Execution via Office URI Scheme
CVSS 6.3
CVE-2022-20930
MEDIUM
Cisco SD-WAN Software < 20.6.2 - Authenticated Arbitrary File Write via CLI Command Injection
CVSS 6.7
Details
Vulnerabilities
394