launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the in
exiftool-vendored provides cross-platform Node.js access to ExifTool. Prior to 35.19.0, exiftool-vendored starts ExifToo
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, a crafted UUID such a
# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of pote
GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_
Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF s
GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fail
rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricte
rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbi
GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.res
Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of
A low‑privileged local attacker who gains access to the UBR service account (e.g., via SSH) can escalate privileges to o
Code execution in AssistFeedbackService of TECNO Pova7 Pro 5G on Android allows local apps to execute arbitrary code as
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.9, a code
PHPUnit is a testing framework for PHP. In versions 12.5.21 and 13.1.5, PHPUnit forwards PHP INI settings to child proce
A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a rol
Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metach
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote co
Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-s
FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the e
A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manage
A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injec
An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.
A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit
hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecti
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version
In KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF vulnerability when processing th
Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57.19.1, 1.58.14.1, 1.
An Argument Injection vulnerability exists in bird-lg-go before commit 6187a4e. The traceroute module uses shlex.Split t
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4
BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git s
The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that
GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options wit
CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers
Gogs is an open source self-hosted Git service. Prior to version 0.14.2, there's a security issue in gogs where deleting
Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK vers
Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK befo
A vulnerability was detected in Fdawgs node-poppler up to 9.1.2/10.0.1. The impacted element is the function pdfInfo/pdf
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiyin
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiyin
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain b
In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings
Improper neutralization of delimiters in connection-URL construction allows connection-option injection in the MongoDB C
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I
SSHFS is a network filesystem client for connecting to SSH servers. From version 1.4 until 3.7.6, SSHFS accepts a bracke
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versio
Frequently Asked Questions
What is CWE-88?
CWE-88 (CWE-88) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-88?
There are 229 CVE records associated with CWE-88 in our database. Of these, 44 are critical severity, 92 are high severity, and 47 are medium severity.
How can I protect against CWE-88 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-88 using AI-powered security agents.
Detect CWE-88 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-88 vulnerabilities across your infrastructure.
Get Started