Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-88

44
CRITICAL
92
HIGH
47
MEDIUM
3
LOW
196 CVEs · Page 2/4
8.3
CVE-2024-52011

launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the in

8.2
CVE-2026-43893

exiftool-vendored provides cross-platform Node.js access to ExifTool. Prior to 35.19.0, exiftool-vendored starts ExifToo

8.2
CVE-2026-44712

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, a crafted UUID such a

8.1
CVE-2025-24293

# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of pote

8.1
CVE-2026-42284

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_

8.1
CVE-2026-41013

Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF s

8.1
CVE-2026-73624

GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fail

8.1
CVE-2026-53783

rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricte

8.1
CVE-2026-53790

rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbi

8.1
CVE-2026-76219

GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.res

7.8
CVE-2025-61731

Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of

7.8
CVE-2025-41761

A low‑privileged local attacker who gains access to the UBR service account (e.g., via SSH) can escalate privileges to o

7.8
CVE-2026-0634

Code execution in AssistFeedbackService of TECNO Pova7 Pro 5G on Android allows local apps to execute arbitrary code as

7.8
CVE-2026-4145

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow

7.8
CVE-2026-43943

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.9, a code

7.8
CVE-2026-41570

PHPUnit is a testing framework for PHP. In versions 12.5.21 and 13.1.5, PHPUnit forwards PHP INI settings to child proce

7.8
CVE-2026-11332

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a rol

7.8
CVE-2026-52750

Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metach

7.8
CVE-2026-46529

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote co

7.8
CVE-2026-47829

Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-s

7.8
CVE-2026-64624

FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the e

7.8
CVE-2026-16493

A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manage

7.8
CVE-2026-44189

A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injec

7.8
CVE-2026-43698

An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.

7.8
CVE-2026-18157

A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit

7.8
CVE-2026-68766

hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecti

7.7
CVE-2026-34769

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version

7.6
CVE-2026-29954

In KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF vulnerability when processing th

7.6
CVE-2026-50147

Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57.19.1, 1.58.14.1, 1.

7.5
CVE-2026-26514

An Argument Injection vulnerability exists in bird-lg-go before commit 6187a4e. The traceroute module uses shlex.Split t

7.5
CVE-2026-40938

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and

7.5
CVE-2026-48116

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti

7.5
CVE-2026-45068

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4

7.5
CVE-2026-15793

BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git s

7.5
CVE-2026-17347

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that

7.5
CVE-2026-76218

GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options wit

7.4
CVE-2026-75912

CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers

7.3
CVE-2026-26194

Gogs is an open source self-hosted Git service. Prior to version 0.14.2, there's a security issue in gogs where deleting

7.3
CVE-2026-12530

Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK vers

7.3
CVE-2026-16796

Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK befo

7.3
CVE-2026-78637

A vulnerability was detected in Fdawgs node-poppler up to 9.1.2/10.0.1. The impacted element is the function pdfInfo/pdf

7.2
CVE-2026-35585

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec

7.1
CVE-2026-1715

An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiyin

7.1
CVE-2026-1716

An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiyin

7.1
CVE-2026-4786

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain b

7.1
CVE-2026-49373

In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings

7.1
CVE-2026-81529

Improper neutralization of delimiters in connection-URL construction allows connection-option injection in the MongoDB C

7.1
CVE-2026-54085

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I

7.0
CVE-2026-48711

SSHFS is a network filesystem client for connecting to SSH servers. From version 1.4 until 3.7.6, SSHFS accepts a bracke

6.8
CVE-2025-40948

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versio

Frequently Asked Questions

What is CWE-88?

CWE-88 (CWE-88) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-88?

There are 229 CVE records associated with CWE-88 in our database. Of these, 44 are critical severity, 92 are high severity, and 47 are medium severity.

How can I protect against CWE-88 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-88 using AI-powered security agents.

Detect CWE-88 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-88 vulnerabilities across your infrastructure.

Get Started