CWE-88
388 CVEs • Abstraction: Base
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.
CVEs (388)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 1Data Center Network Manager Jun 17, 2026 Jul 16, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in the CLI of Cisco Data Center Network Manager (DCNM) could allow an authenticated, local attacker to elevate privileges to root and execute arbitrary commands on the underlying operating system. The vul...Show more |
TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains an improper neutralization of argument deli...Show more |
Viber for Windows up to 13.2.0.39 does not properly quote its custom URI handler. A malicious website could launch Viber with arbitrary parameters, forcing a victim to send an NTLM authentication request, and either rela...Show more |
aaPanel through 6.6.6 allows remote authenticated users to execute arbitrary commands via the Script Content box on the Add Cron Job screen. |
1Se 1Ecostruxure Operator Terminal Expert Jun 17, 2026 Jun 16, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A CWE-88: Argument Injection or Modification vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause unauthorized write access when opening...Show more |
In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js) allows an attacker to modify arguments which causes downloading a random DLL and injection on it. |
1Redhat 4Ansible Ansible TowerCloudforms Management Engine+1 moreJun 17, 2026 Mar 16, 2020 N/A· v4 3.9 LOW· v3 2.6 LOW· v2 A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacke...Show more |
1Mitsubishielectric 1Iu1 1m20 D Firmware Jun 17, 2026 Mar 16, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and ear...Show more |
Command line arguments could have been injected during Firefox invocation as a shell handler for certain unsupported file types. This required Firefox to be configured as the default handler for a given file type and for...Show more |
2Fedoraproject Sensiolabs2Fedora SymfonyJun 17, 2026 Nov 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIME type validation sho...Show more |
An exploitable privilege escalation vulnerability exists in the Wacom, driver version 6.3.32-3, update helper service in the start/stopLaunchDProcess command. The command takes a user-supplied string argument and execute...Show more |
An exploitable privilege escalation vulnerability exists in the Wacom, driver version 6.3.32-3, update helper service in the startProcess command. The command takes a user-supplied script argument and executes it under r...Show more |
1Sangoma 1Session Border Controller Firmware Jun 17, 2026 Oct 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to an authentication bypass via an argument injection vulnerability involving special characters in the username field. Upon successfu...Show more |
1Sangoma 1Session Border Controller Firmware Jun 17, 2026 Oct 22, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to Argument Injection via special characters in the username field. Upon successful exploitation, a remote unauthenticated user can cr...Show more |
Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks on malicious links in a chat application. This can be used to write a log file to...Show more |
rustls-mio/examples/tlsserver.rs in the rustls crate before 0.16.0 for Rust allows attackers to cause a denial of service (loop of conn_event and ready) by arranging for a client to never be writable. |
3Fedoraproject Mixin Deep ProjectOracle3Communications Cloud Native Core Network Function Cloud Native Environment FedoraMixin DeepJun 17, 2026 Aug 23, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload. |
cgi-bin/cmh/webcam.sh in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via --output argument injection in the username parameter to /cgi-bin/cmh/webcam.sh. |
3Belden SiemensWindriver7Garrettcom Magnum Dx940e Firmware Hirschmann HiosRuggedcom Win7000 Firmware+4 moreJun 17, 2026 Aug 5, 2019 N/A· v4 7.1 HIGH· v3 4.8 MEDIUM· v2 Wind River VxWorks 6.6, 6.7, 6.8, 6.9.3, 6.9.4, and Vx7 has Incorrect Access Control in IPv4 assignment by the ipdhcpc DHCP client component. |
1Londontrustmedia 1Private Internet Access Vpn Client Jun 17, 2026 Jul 11, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The openvpn_launcher.64 binary...Show more |