CWE-88— Argument Injection or Modification
The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.— MITRE CWE catalog
499 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-88page 6 of 10
- CVE-2026-4145HIGHCVSS 7.8EG 7.82026-04-15
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.
- CVE-2026-0634HIGHCVSS 7.8EG 7.82026-04-02
Code execution in AssistFeedbackService of TECNO Pova7 Pro 5G on Android allows local apps to execute arbitrary code as system via command injection.
- CVE-2025-41761HIGHCVSS 7.8EG 7.82026-03-09
A low‑privileged local attacker who gains access to the UBR service account (e.g., via SSH) can escalate privileges to obtain full system access. This is due to the service account being permitted to execute certain binaries (e.g., tcpdu…
- CVE-2026-27208HIGHCVSS 7.8EG 7.82026-02-24
bleon-ethical/api-gateway-deploy provides API gateway deployment. Version 1.0.0 is vulnerable to an attack chain involving OS Command Injection and Privilege Escalation. This allows an attacker to execute arbitrary commands with root privi…
- CVE-2025-15316HIGHCVSS 7.8EG 7.82026-02-09
Tanium addressed a local privilege escalation vulnerability in Tanium Server.
- CVE-2025-15315HIGHCVSS 7.8EG 7.82026-02-09
Tanium addressed a local privilege escalation vulnerability in Tanium Module Server.
- CVE-2025-61731HIGHCVSS 7.8EG 7.82026-01-28
Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" directive in a Go source file provides command-line arguments to provide to t…
- CVE-2025-6232HIGHCVSS 7.8EG 7.82025-07-17
An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying specific registry locations.
- CVE-2025-6231HIGHCVSS 7.8EG 7.82025-07-17
An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying an application configuration file.
- CVE-2025-0065HIGHCVSS 7.8EG 7.82025-01-28
Improper Neutralization of Argument Delimiters in the TeamViewer_service.exe component of TeamViewer Clients prior version 15.62 for Windows allows an attacker with local unprivileged access on a Windows system to elevate privileges via ar…
- CVE-2023-44452HIGHCVSS 7.8EG 7.82024-05-03
Linux Mint Xreader CBT File Parsing Argument Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required …
- CVE-2023-46681HIGHCVSS 7.8EG 7.82023-12-26
Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in VR-S1000 firmware Ver. 2.37 and earlier allows an authenticated attacker who can access to the product's command line interface to execute …
- CVE-2023-20224HIGHCVSS 7.8EG 7.82023-08-16
A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to insuf…
- CVE-2023-30577HIGHCVSS 7.8EG 7.82023-07-26
AMANDA (Advanced Maryland Automatic Network Disk Archiver) before tag-community-3.5.4 mishandles argument checking for runtar.c, a different vulnerability than CVE-2022-37705.
- CVE-2023-34395HIGHCVSS 7.8EG 7.82023-06-27
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Software Foundation Apache Airflow ODBC Provider. In OdbcHook, A privilege escalation vulnerability exists in a system due to contro…
- CVE-2022-47502HIGHCVSS 7.8EG 7.82023-03-24
Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. Links can be activated by clicks, or by automatic document events. The execution of such…
- CVE-2022-25973HIGHCVSS 7.8EG 7.82022-08-10
All versions of package mc-kill-port are vulnerable to Arbitrary Command Execution via the kill function, due to missing sanitization of the port argument.
- CVE-2022-26532HIGHCVSS 7.8EG 7.82022-05-24
A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN s…
- CVE-2022-30240HIGHCVSS 7.8EG 7.82022-05-09
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift JDBC Driver 1.2.40 through 1.2.55 may allow a local user to execute code. NOTE: this is different from CVE-2022-29972.
- CVE-2022-30239HIGHCVSS 7.8EG 7.82022-05-09
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Athena JDBC Driver 2.0.25 through 2.0.28 may allow a local user to execute code. NOTE: this is different from CVE-2022-29971.
- CVE-2022-29972HIGHCVSS 7.8EG 7.82022-05-09
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift ODBC Driver (1.4.14 through 1.4.21.1001 and 1.4.22 through 1.4.x before 1.4.52) may allow a local user to execute arbi…
- CVE-2022-29971HIGHCVSS 7.8EG 7.82022-05-09
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Athena ODBC Driver 1.1.1 through 1.1.x before 1.1.17 may allow a local user to execute arbitrary code.
- CVE-2021-21814HIGHCVSS 7.8EG 7.82021-08-13
Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line. filepattern is passed directly to strlen to determine the ending location of the char* passed in by the user, n…
- CVE-2020-7851HIGHCVSS 7.8EG 7.82021-04-19
Innorix Web-Based File Transfer Solution versuibs prior to and including 9.2.18.385 contains a vulnerability that could allow remote files to be downloaded and executed by setting the arguments to the internal method. A remote attacker cou…
- CVE-2020-7850HIGHCVSS 7.8EG 7.82021-03-29
NBBDownloader.ocx ActiveX Control in Groupware contains a vulnerability that could allow remote files to be downloaded and executed by setting the arguments to the activex method. A remote attacker could induce a user to access a crafted w…
- CVE-2020-17367HIGHCVSS 7.8EG 7.82020-08-11
Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to command injection.
- CVE-2020-3380HIGHCVSS 7.8EG 7.82020-07-16
A vulnerability in the CLI of Cisco Data Center Network Manager (DCNM) could allow an authenticated, local attacker to elevate privileges to root and execute arbitrary commands on the underlying operating system. The vulnerability is due t…
- CVE-2020-7496HIGHCVSS 7.8EG 7.82020-06-16
A CWE-88: Argument Injection or Modification vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause unauthorized write access when opening the project file.
- CVE-2019-5013HIGHCVSS 7.8EG 7.82019-10-24
An exploitable privilege escalation vulnerability exists in the Wacom, driver version 6.3.32-3, update helper service in the start/stopLaunchDProcess command. The command takes a user-supplied string argument and executes launchctl under r…
- CVE-2019-5012HIGHCVSS 7.8EG 7.82019-10-24
An exploitable privilege escalation vulnerability exists in the Wacom, driver version 6.3.32-3, update helper service in the startProcess command. The command takes a user-supplied script argument and executes it under root context. A user…
- CVE-2019-12578HIGHCVSS 7.8EG 7.82019-07-11
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The openvpn_launcher.64 binary is setuid root. Th…
- CVE-2019-1735HIGHCVSS 7.8EG 7.82019-05-15
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges on the underlying operating system of an affected device. The vulnerability is due to in…
- CVE-2019-1606HIGHCVSS 7.8EG 7.82019-03-08
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of …
- CVE-2022-37705HIGHCVSS 6.7EG 7.82023-04-16
A privilege escalation flaw was found in Amanda 3.5.1 in which the backup user can acquire root privileges. The vulnerable component is the runtar SUID program, which is a wrapper to run /usr/bin/tar with specific arguments that are contro…
- CVE-2026-84256HIGHCVSS 7.7EG 7.72026-09-07
An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a crafted certificate subject
- CVE-2025-53542HIGHCVSS 7.7EG 7.72025-07-10
Headlamp is an extensible Kubernetes web UI. A command injection vulnerability was discovered in the codeSign.js script used in the macOS packaging workflow of the Kubernetes Headlamp project. This issue arises due to the improper use of N…
- CVE-2025-3460HIGHCVSS 7.7EG 7.72025-06-08
The Quantenna Wi-Fi chipset ships with a local control script, set_tx_pow, that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is…
- CVE-2025-3459HIGHCVSS 7.7EG 7.72025-06-08
The Quantenna Wi-Fi chipset ships with a local control script, transmit_file, that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and…
- CVE-2025-32459HIGHCVSS 7.7EG 7.72025-06-08
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the sync_time argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Comm…
- CVE-2025-32458HIGHCVSS 7.7EG 7.72025-06-08
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the get_syslog_from_qtn argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters…
- CVE-2025-32457HIGHCVSS 7.7EG 7.72025-06-08
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the get_file_from_qtn argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters i…
- CVE-2025-32456HIGHCVSS 7.7EG 7.72025-06-08
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the put_file_to_qtn argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in …
- CVE-2025-32455HIGHCVSS 7.7EG 7.72025-06-08
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the run_cmd argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Comman…
- CVE-2024-39933HIGHCVSS 7.7EG 7.72024-07-04
Gogs through 0.13.0 allows argument injection during the tagging of a new release.
- CVE-2026-50147HIGHCVSS 7.6EG 7.62026-07-15
Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57.19.1, 1.58.14.1, 1.59.10, and 1.60.4, an attacker who can configure a Metabase database connection can read arbitrary files from the Metab…
- CVE-2026-29954HIGHCVSS 7.6EG 7.62026-03-30
In KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF vulnerability when processing the chartURL field of ResourceComposition resources. The field is only URL-encoded without validating the target address.…
- CVE-2004-0489HIGHCVSS v2 7.6EG 7.62004-07-07
Argument injection vulnerability in the SSH URI handler for Safari on Mac OS 10.3.3 and earlier allows remote attackers to (1) execute arbitrary code via the ProxyCommand option or (2) conduct port forwarding via the -R option.
- CVE-2026-105791HIGHCVSS 7.5EG 7.52026-10-06
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the run_shell tool in the CommandLineExecutor component of ufo/client/mcp/local_servers/cli_mcp_server.py validates only the…
- CVE-2026-85626HIGHCVSS 7.5EG 7.52026-09-04
git-mcp-server 2.15.1 contains an argument injection vulnerability in the ref and object parameters of git_log, git_diff, and git_show tools that lack leading-dash validation. Attackers can inject git command-line options like --output= to…
- CVE-2026-15793HIGHCVSS 7.5EG 7.52026-07-21
BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host.
Map vulnerabilities like CWE-88 to your infrastructure
EchelonGraph correlates every CVE — across CWE-88 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →