CWE-88— Argument Injection or Modification
The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.— MITRE CWE catalog
499 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-88page 7 of 10
- CVE-2026-45068HIGHCVSS 7.5EG 7.52026-05-27
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, SendmailTransport in -t mode appended recipient addresses to the sendmail command line without a…
- CVE-2026-26514HIGHCVSS 7.5EG 7.52026-03-04
An Argument Injection vulnerability exists in bird-lg-go before commit 6187a4e. The traceroute module uses shlex.Split to parse user input without validation, allowing remote attackers to inject arbitrary flags (e.g., -w, -q) via the q par…
- CVE-2025-62847HIGHCVSS 7.5EG 7.52025-12-16
An improper neutralization of argument delimiters in a command vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to alter execution logic. We have alr…
- CVE-2022-37005HIGHCVSS 7.5EG 7.52022-08-10
The Settings application has an argument injection vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2022-29215HIGHCVSS 7.5EG 7.52022-05-21
RegionProtect is a plugin that allows users to manage certain events in certain regions of the world. Versions prior to 1.1.0 contain a YAML injection vulnerability that can cause an instant server crash if the passed arguments are not mat…
- CVE-2020-28367HIGHCVSS 7.5EG 7.52020-11-18
Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via malicious gcc flags specified via a #cgo directive.
- CVE-2020-14049HIGHCVSS 7.5EG 7.52020-06-22
Viber for Windows up to 13.2.0.39 does not properly quote its custom URI handler. A malicious website could launch Viber with arbitrary parameters, forcing a victim to send an NTLM authentication request, and either relay the request or ca…
- CVE-2019-18888HIGHCVSS 7.5EG 7.52019-11-21
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIME type validation should occur, then arb…
- CVE-2019-15541HIGHCVSS 7.5EG 7.52019-08-26
rustls-mio/examples/tlsserver.rs in the rustls crate before 0.16.0 for Rust allows attackers to cause a denial of service (loop of conn_event and ready) by arranging for a client to never be writable.
- CVE-2019-8321HIGHCVSS 7.5EG 7.52019-06-17
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::UserInteraction#verbose calls say without escaping, escape sequence injection is possible.
- CVE-2018-11025HIGHCVSS 7.5EG 7.52018-10-16
kernel/omap/drivers/mfd/twl6030-gpadc.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device /dev/twl6030-gpadc with the command 24832 an…
- CVE-2018-11024HIGHCVSS 7.5EG 7.52018-10-16
kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD (3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device /dev/gcioctl with the command 107743578…
- CVE-2018-11023HIGHCVSS 7.5EG 7.52018-10-16
kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD (3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device /dev/gcioctl with the command 322256015…
- CVE-2018-11022HIGHCVSS 7.5EG 7.52018-10-16
kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device /dev/gcioctl with the command 3224132973…
- CVE-2018-11021HIGHCVSS 7.5EG 7.52018-10-16
kernel/omap/drivers/video/omap2/dsscomp/device.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device /dev/dsscomp with the command 11180…
- CVE-2018-11019HIGHCVSS 7.5EG 7.52018-10-16
kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device /dev/gcioctl with the command 3221773726…
- CVE-2016-1000222HIGHCVSS 7.5EG 7.52017-06-16
Logstash prior to version 2.1.2, the CSV output can be attacked via engineered input that will create malicious formulas in the CSV data.
- CVE-2006-1865HIGHCVSS v2 7.5EG 7.52006-04-21
Argument injection vulnerability in Beagle before 0.2.5 allows attackers to execute arbitrary commands via crafted filenames that inject command line arguments when Beagle launches external helper applications while indexing.
- CVE-2004-0411HIGHCVSS v2 7.5EG 7.52004-07-07
The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) ssh, or (4) mailto URI, which allows remote attackers to manipulate the options that are p…
- CVE-2004-0121HIGHCVSS v2 7.5EG 7.52004-04-15
Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine…
- CVE-2002-0985HIGHCVSS v2 7.5EG 7.52002-09-24
Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavi…
- CVE-2001-1246HIGHCVSS v2 7.5EG 7.52001-06-30
PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters.
- CVE-2026-75912HIGHCVSS 7.4EG 7.42026-08-18
CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers to read arbitrary files by injecting git options into the unvalidated rev parameter. Attackers can supply rev values l…
- CVE-2026-7865HIGHCVSS 7.4EG 7.42026-05-05
A hidden console command is vulnerable to command injection flaw when control characters are passed to its second argument. A third party researcher Eugene Lim had discovered vulnerability in the way console command passes to a popen fu…
- CVE-2023-26310HIGHCVSS 7.4EG 7.42023-08-09
There is a command injection problem in the old version of the mobile phone backup app.
- CVE-2026-90809HIGHCVSS 7.3EG 7.32026-09-14
A vulnerability was identified in HKUDS nanobot up to 0.2.1. The affected element is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. Such manipulation leads to argume…
- CVE-2026-78637HIGHCVSS 7.3EG 7.32026-08-25
A vulnerability was detected in Fdawgs node-poppler up to 9.1.2/10.0.1. The impacted element is the function pdfInfo/pdfToText/pdfToCairo/pdfToPpm/pdfImages/pdfToHtml/pdfToPs/pdfFonts/pdfDetach/pdfAttach/pdfSeparate/pdfUnite of the file sr…
- CVE-2026-16796HIGHCVSS 7.3EG 7.32026-07-23
Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK before 1.18.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via…
- CVE-2026-50014HIGHCVSS 7.3EG 7.32026-06-25
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm passes the lockfile-controlled git resolution.commit value to git fetch without a -- separator or commit-format validation. For git dependencies fetched through the shallow-fetch…
- CVE-2026-12530HIGHCVSS 7.3EG 7.32026-06-17
Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK versions >= 1.1.3 and < 1.6.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpr…
- CVE-2026-53694HIGHCVSS 7.3EG 7.32026-06-10
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Nomachine allows Argument Injection.This issue affects Nomachine: before 9.5.7, before 8.23.2.
- CVE-2026-26194HIGHCVSS 7.3EG 7.32026-03-05
Gogs is an open source self-hosted Git service. Prior to version 0.14.2, there's a security issue in gogs where deleting a release can fail if a user controlled tag name is passed to git without the right separator, this lets git options g…
- CVE-2022-36069HIGHCVSS 7.3EG 7.32022-09-07
Poetry is a dependency manager for Python. When handling dependencies that come from a Git repository instead of a registry, Poetry uses various commands, such as `git clone`. These commands are constructed using user input (e.g. the repos…
- CVE-2001-0667HIGHCVSS 7.3EG 7.32001-10-30
Internet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0, allows remote attackers to execute commands by spawning Telnet with a log file option on the command line and writing arbitrary code into an …
- CVE-2026-76866HIGHCVSS 7.2EG 7.22026-09-15
Netcore NR255-V firmware version 1.5.130703 builds root-run command lines from unquoted user-supplied DDNS input in DDNSset_cgi.c and related ddns_Proc.c components, enabling os command argument injection. Attackers can exploit the unsanit…
- CVE-2026-35585HIGHCVSS 7.2EG 7.22026-04-07
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.0.0 until 2.33.8, the hook system in File Browser — which executes administrator-defined shel…
- CVE-2025-3945HIGHCVSS 7.2EG 7.22025-05-22
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows Command Delimiters. This issue affects Niagara Framewor…
- CVE-2024-9131HIGHCVSS 7.2EG 7.22025-01-10
A user with administrator privileges can perform command injection
- CVE-2023-0633HIGHCVSS 7.2EG 7.22023-09-25
In Docker Desktop on Windows before 4.12.0 an argument injection to installer may result in local privilege escalation (LPE).This issue affects Docker Desktop: before 4.12.0.
- CVE-2021-46850HIGHCVSS 7.2EG 7.22022-10-24
myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote administrative user can execute arbitrary commands via the v_sftp_license parameter when send…
- CVE-2022-37027HIGHCVSS 7.2EG 7.22022-09-21
Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can modify the Runtime Options in the web interface can inject Java Runtime Options. These take effect after a restart. Fo…
- CVE-2022-24376HIGHCVSS 7.2EG 7.22022-06-10
All versions of package git-promise are vulnerable to Command Injection due to an inappropriate fix of a prior [vulnerability](https://security.snyk.io/vuln/SNYK-JS-GITPROMISE-567476) in this package. **Note:** Please note that the vulnera…
- CVE-2022-23915HIGHCVSS 7.2EG 7.22022-03-04
The package weblate from 0 and before 4.11.1 are vulnerable to Remote Code Execution (RCE) via argument injection when using git or mercurial repositories. Authenticated users, can change the behavior of the application in an unintended wa…
- CVE-2021-34816HIGHCVSS 7.2EG 7.22021-07-21
An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by installing plugins from an attacker-controlled source.
- CVE-2020-35136HIGHCVSS 7.2EG 7.22020-12-23
Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard can manipulate the backup function by inserting a payload into the filename for the zipfilename_template parameter to …
- CVE-2020-14421HIGHCVSS 7.2EG 7.22020-06-18
aaPanel through 6.6.6 allows remote authenticated users to execute arbitrary commands via the Script Content box on the Add Cron Job screen.
- CVE-2026-107802HIGHCVSS 7.1EG 7.12026-10-08
SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, src/SelectionTranslate.cpp embeds selected or pasted translation text in quoted Windows command lines using incomplete quote-only escaping. The affected BuildGrokTransl…
- CVE-2026-107734HIGHCVSS 7.1EG 7.12026-10-08
SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, an attacker-controlled SyncTeX source filename is substituted for the %f placeholder in an external editor command line without safe Windows argument quoting, and the r…
- CVE-2026-55673HIGHCVSS 7.1EG 7.12026-08-28
PowSyBl (Power System Blocks) is a framework to build power system oriented software. Prior to 7.2.2, UnixLocalCommandExecutor and WindowsLocalCommandExecutor concatenate command arguments and environment variables into strings interpreted…
- CVE-2026-54085HIGHCVSS 7.1EG 7.12026-08-27
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.2.0 through 4.14.6, multiple active response scripts pass attacker-influenced alert fields to privileged s…
Map vulnerabilities like CWE-88 to your infrastructure
EchelonGraph correlates every CVE — across CWE-88 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →