In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mim
AyaCMS 3.1.2 is vulnerable to file deletion via /aya/module/admin/fst_del.inc.php
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when
An Argument Injection or Modification vulnerability in the "Change Secret" username field as used in the Discovery compo
In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client applicat
The package ungit before 1.5.20 are vulnerable to Remote Code Execution (RCE) via argument injection. The issue occurs w
BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's
GoCD is a continuous delivery server. In GoCD versions prior to 22.1.0, it is possible for existing authenticated users
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
CRITICAL: An improper neutralization of argument delimiters in a command vulnerability was identified in GitHub Enterpri
Mozilla developers Gabriele Svelto, Yulia Startsev, Andrew McCreight and the Mozilla Fuzzing Team reported memory safety
Composer is a dependency manager for the PHP programming language. Integrators using Composer code to call `VcsDriver::g
The package simple-git before 3.3.0 are vulnerable to Command Injection via argument injection. When calling the .fetch(
The package libvcs before 0.11.1 are vulnerable to Command Injection via argument injection. When calling the update_rep
The package github.com/masterminds/vcs before 1.13.3 are vulnerable to Command Injection via argument injection. When hg
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When callin
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git a
The package simple-git before 3.5.0 are vulnerable to Command Injection due to an incomplete fix of [CVE-2022-24433](htt
The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(rem
The package czproject/git-php before 4.0.3 are vulnerable to Command Injection via git argument injection. When calling
The package workspace-tools before 0.18.4 are vulnerable to Command Injection via git argument injection. When calling t
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d
All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the --upload-pack feature
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Athena O
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Athena J
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift
A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 t
All versions of package mc-kill-port are vulnerable to Arbitrary Command Execution via the kill function, due to missing
RegionProtect is a plugin that allows users to manage certain events in certain regions of the world. Versions prior to
The Settings application has an argument injection vulnerability. Successful exploitation of this vulnerability may affe
Poetry is a dependency manager for Python. When handling dependencies that come from a Git repository instead of a regis
The package weblate from 0 and before 4.11.1 are vulnerable to Remote Code Execution (RCE) via argument injection when u
All versions of package git-promise are vulnerable to Command Injection due to an inappropriate fix of a prior [vulnerab
Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can
myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite and possib
This affects the package codecov before 2.0.16. The vulnerability occurs due to not sanitizing gcov arguments before bei
LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An addit
paymentrequest.py in Electrum before 4.2.2 allows a file:// URL in the r parameter of a payment request (e.g., within QR
In JetBrains TeamCity before 2022.04.2 build parameter injection was possible
A vulnerability has been identified in SIMATIC WinCC OA V3.15 (All versions < V3.15 P038), SIMATIC WinCC OA V3.16 (All v
Argument Injection in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.
The Crypt_GPG extension before 1.6.7 for PHP does not prevent additional options in GPG calls, which presents a risk for
Bitcoin Core before 0.19.0 might allow remote attackers to execute arbitrary code when another application unsafely pass
encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and ap
A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0. A remote attacker can send a maliciou
The fbgames protocol handler registered as part of Facebook Gameroom does not properly quote arguments passed to the exe
In JetBrains TeamCity before 2020.2.3, argument injection leading to remote code execution was possible.
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write
Frequently Asked Questions
What is CWE-88?
CWE-88 (CWE-88) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-88?
There are 479 CVE records associated with CWE-88 in our database. Of these, 83 are critical severity, 203 are high severity, and 93 are medium severity.
How can I protect against CWE-88 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-88 using AI-powered security agents.
Detect CWE-88 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-88 vulnerabilities across your infrastructure.
Get Started