There is a Parameter injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may caus
APKLeaks is an open-source project for scanning APK file for URIs, endpoints & secrets. APKLeaks prior to v2.0.3 allows
Composer is a dependency manager for PHP. URLs for Mercurial repositories in the root composer.json and package source d
A vulnerability in the web UI of Cisco Modeling Labs could allow an authenticated, remote attacker to execute arbitrary
An issue was discovered in Echo ShareCare 8.15.5. The UnzipFile feature in Access/EligFeedParse_Sup/UnzipFile_Upd.cfm is
In the Amazon AWS WorkSpaces client 3.0.10 through 3.1.8 on Windows, argument injection in the workspaces:// URI handler
qutebrowser is an open source keyboard-focused browser with a minimal GUI. Starting with qutebrowser v1.7.0, the Windows
Discord Recon Server is a bot that allows one to do one's reconnaissance process from one's Discord. A vulnerability in
A vulnerability in the SSH Server process of Cisco IOS XR Software could allow an authenticated, remote attacker to over
The Device42 Main Appliance before 17.05.01 does not sanitize user input in its Nmap Discovery utility. An attacker (wit
NBBDownloader.ocx ActiveX Control in Groupware contains a vulnerability that could allow remote files to be downloaded a
Innorix Web-Based File Transfer Solution versuibs prior to and including 9.2.18.385 contains a vulnerability that could
Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the comman
An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary cod
`Bundler` is a package for managing application dependencies in Ruby. In `bundler` versions before 2.2.33, when working
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to inject arbitrary com
KuaiFanCMS V5.x contains an arbitrary file read vulnerability in the html_url parameter of the chakanhtml.module.php fil
By abusing the 'install rpm info detail' command, an attacker can escape the restricted clish shell on affected versions
shescape is a simple shell escape package for JavaScript. In shescape before version 1.1.3, anyone using _Shescape_ to d
Multiple vulnerabilities in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to acce
Multiple vulnerabilities in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to acce
An OS command argument injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated a
TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier insta
In Nim 1.2.4, the standard library browsers mishandles the URL argument to browsers.openDefaultBrowser. This argument ca
Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in TCP/IP function incl
Command line arguments could have been injected during Firefox invocation as a shell handler for certain unsupported fil
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in TCP function include
TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could
Remote Code Execution can occur via the external news feed in ILIAS 6.4 because of incorrect parameter sanitization for
In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js)
This affects the package nodemailer before 6.4.16. Use of crafted recipient email addresses may result in arbitrary comm
A CWE-88: Argument Injection or Modification vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pa
A vulnerability in the CLI of Cisco Data Center Network Manager (DCNM) could allow an authenticated, local attacker to e
Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to comm
Viber for Windows up to 13.2.0.39 does not properly quote its custom URI handler. A malicious website could launch Viber
aaPanel through 6.6.6 allows remote authenticated users to execute arbitrary commands via the Script Content box on the
Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user
Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard
Blueman is a GTK+ Bluetooth Manager. In Blueman before 2.1.4, the DhcpClient method of the D-Bus interface to blueman-me
A vulnerability in the remote management feature of Cisco SD-WAN vManage Software could allow an authenticated, local at
Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in TCP/IP function incl
IBM Spectrum Scale V5.0.0.0 through V5.0.4.3 and V4.2.0.0 through V4.2.3.21 could allow a local attacker to cause a deni
An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The database connection strings accept custom unsafe arg
A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified.
Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell t
A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocatio
mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep coul
The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to Argument Injection via special
The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to an authentication bypass via an
There was an argument injection vulnerability in Atlassian Sourcetree for macOS from version 1.2 before version 3.1.1 vi
Frequently Asked Questions
What is CWE-88?
CWE-88 (CWE-88) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-88?
There are 479 CVE records associated with CWE-88 in our database. Of these, 83 are critical severity, 203 are high severity, and 93 are medium severity.
How can I protect against CWE-88 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-88 using AI-powered security agents.
Detect CWE-88 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-88 vulnerabilities across your infrastructure.
Get Started