Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version
Argument injection in Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker with admin pr
Inductive Automation Ignition getParams Argument Injection Remote Code Execution Vulnerability. This vulnerability allow
LenelS2 NetBox access control and event monitoring system was discovered to contain an authenticated RCE in versions pri
A remote, unauthenticated attacker may be able to send crafted messages to the web server of the Commend WS203VICM caus
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. in versions before
The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via
Rust is a programming language. The fix for CVE-2024-24576, where `std::process::Command` incorrectly escaped arguments
A server side request forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an
Linux Mint Xreader CBT File Parsing Argument Injection Remote Code Execution Vulnerability. This vulnerability allows re
Gogs through 0.13.0 allows argument injection during the tagging of a new release.
Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit,
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.9 and Ivanti Policy Secure before version
Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerabi
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit,
A vulnerability in the web-based management interface of the Cisco WAP371 Wireless-AC/N Dual Radio Access Point (AP) wit
Argument injection in websphere_mq agent plugin in Checkmk 2.0.0, 2.1.0, <2.2.0p26 and <2.3.0b5 allows local attacker to
All versions of the package ggit are vulnerable to Arbitrary Argument Injection via the clone() API, which allows specif
A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to inj
gitoxide is a pure Rust implementation of Git. `gix-transport` does not check the username part of a URL for text that t
A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.
A vulnerability in the application CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager coul
A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC), formerly Cisco Data Center Network Manager (DCNM), co
aEnrich Technology a+HRD's functionality for downloading files using youtube-dl.exe does not properly restrict user inpu
The Relevanssi Live Ajax Search plugin for WordPress is vulnerable to argument injection in all versions up to, and incl
XZ Utils provide a general-purpose data-compression library plus command-line tools. When built for native Windows (MinG
An argument injection vulnerability has been identified in the administrative web interface of the Atos Unify OpenScape
Connected IO v2.1.0 and prior has an argument injection vulnerability in its iptables command message in its communicati
Connected IO v2.1.0 and prior has an argument injection vulnerability in its AT command message in its communication pro
CoreDial sipXcom up to and including 21.04 is vulnerable to Improper Neutralization of Argument Delimiters in a Command.
Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes ar
Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes ar
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Software Foun
AMANDA (Advanced Maryland Automatic Network Disk Archiver) before tag-community-3.5.4 mishandles argument checking for r
A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an a
Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in VR-S1000 firmware Ve
Jellyfin is a Free Software Media System for managing and streaming media. In affected versions there is an argument inj
There is a command injection problem in the old version of the mobile phone backup app.
A improper neutralization of argument delimiters in a command ('argument injection') in Fortinet FortiNAC versions 9.4.0
In Docker Desktop on Windows before 4.12.0 an argument injection to installer may result in local privilege escalation (
A privilege escalation flaw was found in Amanda 3.5.1 in which the backup user can acquire root privileges. The vulnerab
Versions of the package blamer before 1.0.4 are vulnerable to Arbitrary Argument Injection via the blameByFile() API. Th
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an au
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an au
An OS command injection vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated API
H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IG
CmsWing CMS 1.3.7 is affected by a Remote Code Execution (RCE) vulnerability via parameter: log rule
The package git-pull-or-clone before 2.0.2 are vulnerable to Command Injection due to the use of the --upload-pack featu
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.
Frequently Asked Questions
What is CWE-88?
CWE-88 (CWE-88) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-88?
There are 479 CVE records associated with CWE-88 in our database. Of these, 83 are critical severity, 203 are high severity, and 93 are medium severity.
How can I protect against CWE-88 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-88 using AI-powered security agents.
Detect CWE-88 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-88 vulnerabilities across your infrastructure.
Get Started