Git GUI allows you to use the Git source control management tools via a GUI. When a user clones an untrusted repository
Dell ThinOS 10, versions prior to 2508_10.0127, contains an Improper Neutralization of Argument Delimiters in a Command
Improper Neutralization of Argument Delimiters in the TeamViewer_service.exe component of TeamViewer Clients prior versi
An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local at
An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local at
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the run_cmd argument), that is vuln
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the put_file_to_qtn argument), that
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the get_file_from_qtn argument), th
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the get_syslog_from_qtn argument),
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the sync_time argument), that is vu
The Quantenna Wi-Fi chipset ships with a local control script, transmit_file, that is vulnerable to command injection. T
The Quantenna Wi-Fi chipset ships with a local control script, set_tx_pow, that is vulnerable to command injection. This
Headlamp is an extensible Kubernetes web UI. A command injection vulnerability was discovered in the codeSign.js script
An improper neutralization of argument delimiters in a command vulnerability has been reported to affect several QNAP op
Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loadi
A user with administrator privileges can perform command injection
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Tridium Niagara Fram
Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command in
Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command in
Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command in
Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command in
Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command in
Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command in
Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command in
In mcp-server-git versions prior to 2025.12.17, the git_diff and git_checkout functions passed user-controlled arguments
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.
An argument injection vulnerability in the diagnose and import pac commands in WatchGuard Fireware OS before 12.8.1, 12.
A vulnerability exists in Advantech iView that allows for argument injection in NetworkServlet.backupDatabase(). This i
A vulnerability exists in Advantech iView that allows for argument injection in the NetworkServlet.restoreDatabase(). T
A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments
Improper neutralization of argument delimiters in a command ('Argument Injection') issue exists in Defense Platform Home
Conventional Changelog generates changelogs and release notes from a project's commit messages and metadata. Prior to ve
A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Unifor
Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - GlobalBlock
matrix-appservice-irc is a Node.js IRC bridge for Matrix. The matrix-appservice-irc bridge up to version 3.0.3 contains
Atheos is a self-hosted browser-based cloud integrated development environment. Prior to version 6.0.4, improper use of
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in CRESTRON TOUCHSCREEN
Easywall 0.3.1 allows authenticated remote command execution via a command injection vulnerability in the /ports-save en
Rust is a programming language. The Rust Security Response WG was notified that the Rust standard library prior to versi
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code
A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not
The OpenAPI loader in Embedchain before 0.1.57 allows attackers to execute arbitrary code, related to the openapi.py yam
HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This
Argument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing unauthenticated attackers to e
Argument injection in Ivanti Connect Secure before version 22.7R2.2 and 9.1R18.9 and Ivanti Policy Secure before version
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version
Frequently Asked Questions
What is CWE-88?
CWE-88 (CWE-88) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-88?
There are 479 CVE records associated with CWE-88 in our database. Of these, 83 are critical severity, 203 are high severity, and 93 are medium severity.
How can I protect against CWE-88 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-88 using AI-powered security agents.
Detect CWE-88 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-88 vulnerabilities across your infrastructure.
Get Started