Tanium addressed a local privilege escalation vulnerability in Tanium Module Server.
Tanium addressed a local privilege escalation vulnerability in Tanium Server.
OpenClaw 2026.3.1 contains an approval integrity vulnerability in system.run node-host execution where argv rewriting ch
Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input
An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDec
OpenClaw versions prior to 2026.2.21 contain an approval-integrity mismatch vulnerability in system.run that allows auth
Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-drive
Hex-Rays IDA Pro 9.2 and 9.3 before 9.3sp2 does not block Clang dependency-file generation (via argument injection), whi
GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --co
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm passes the lockfile-controlled git resolution.commit value
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to versions 5.4.
A security vulnerability has been detected in welovemedia FFmate up to 2.0.15. This vulnerability affects the function E
A vulnerability was found in PrefectHQ prefect up to 3.6.25.dev6. Affected by this issue is some unknown functionality o
dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, _run_dbt_command() in src/dbt_mcp/
mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.7.0, the
A vulnerability in the CLI of Cisco Secure FTD Software could allow an authenticated, local attacker to execute arbitrar
A vulnerability in the Cisco FXOS Software CLI feature for Cisco Secure Firewall ASA Software and Secure FTD Software co
An input validation vulnerability was reported in the LenovoProductivitySystemAddin used in Lenovo Vantage and Lenovo Ba
Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary File Write in TortoiseGit
Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the
GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keywor
phpMyFAQ before 4.1.7, when configured to use PostgreSQL via the native pgsql PHP extension, declares an incorrect LIKE
A security vulnerability has been detected in linlinjava litemall up to 1.8.0. Affected by this vulnerability is the fun
xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line invocation (xidown/core/scanner.py and downloader.py
An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDec
Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp a
Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimu
The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could l
An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability allows local users
A Improper Neutralization of Argument Delimiters vulnerability in Foomuuri can lead to integrity loss of the firewall co
Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to t
Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in upKeeper Solutions u
A hidden console command is vulnerable to command injection flaw when control characters are passed to its second argume
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Nomachine allows Arg
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
Pyenv provides simple Python version management. Prior to 2.8.0, is_version_safe() in libexec/pyenv-version-file-read ac
Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 5.1
PowSyBl (Power System Blocks) is a framework to build power system oriented software. Prior to 7.2.2, UnixLocalCommandEx
go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was dis
A vulnerability was found in Pagure. An argument injection in Git during retrieval of the repository history leads to re
Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General regi
DevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arb
go-mail is a comprehensive library for sending mails with Go. In versions 0.7.0 and below, due to incorrect handling of
Jellyfin is an open source self hosted media server. Versions before 10.10.7 are vulnerable to argument injection in FFm
Argument injection in special agent configuration in Checkmk <2.4.0p1, <2.3.0p32, <2.2.0p42 and 2.1.0 allows authenticat
A flaw was found in Ansible Automation Platform’s EDA component where user-supplied Git URLs are passed unsanitized to t
An argument injection vulnerability exists in the affected product that could allow an attacker to execute arbitrary cod
Versions of the package cloudinary before 2.7.0 are vulnerable to Arbitrary Argument Injection due to improper parsing o
Frequently Asked Questions
What is CWE-88?
CWE-88 (CWE-88) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-88?
There are 479 CVE records associated with CWE-88 in our database. Of these, 83 are critical severity, 203 are high severity, and 93 are medium severity.
How can I protect against CWE-88 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-88 using AI-powered security agents.
Detect CWE-88 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-88 vulnerabilities across your infrastructure.
Get Started