Skip to content
Noroxi

CWE-88 · 413 records

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

CVEs in this class

413 records

  • The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail c

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    phpmailer project · phpmailerDec 30, 2016

  • telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    gnu · inetutilsJan 21, 2026

  • CVE-2024-41710
    70This week

    A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (

    HighCVSS 7.2KEVWeaponizedEPSS 42%

    mitel · 6970 firmwareAug 12, 2024

  • CVE-2007-0882
    69This week

    Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "

    CriticalCVSS 10.0WeaponizedEPSS 98%

    sun · sunosFeb 12, 2007

  • CVE-2018-17456
    68This week

    Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows r

    CriticalCVSS 9.8WeaponizedEPSS 97%

    git-scm · gitOct 6, 2018

  • CVE-2026-86060
    68This week

    SSH session privilege manipulation via a crafted username in Mikrotik RouterOS

    CriticalCVSS 9.2KEVWeaponizedEPSS 6%

    mikrotik · routerosSep 5, 2026

  • CVE-2021-33564
    61This week

    An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files

    CriticalCVSS 9.8Proof of conceptEPSS 72%

    dragonfly project · dragonflyMay 29, 2021

  • University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of

    HighCVSS 7.5WeaponizedEPSS 96%

    php · phpNov 25, 2018

  • H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTING

    CriticalCVSS 9.8Proof of conceptEPSS 65%

    h2database · h2Jan 19, 2022

  • A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0.

    CriticalCVSS 9.8Proof of conceptEPSS 39%

    inspur · clusterengineFeb 22, 2021

  • mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers.

    HighCVSS 8.1Proof of conceptEPSS 54%

    mirc · mircFeb 18, 2019

  • Laravel allows environment manipulation via query string

    HighCVSS 8.7Proof of conceptEPSS 45%

    laravel · frameworkNov 12, 2024

  • Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user to write to arbitra

    HighCVSS 7.2WeaponizedEPSS 59%

    nagios · nagios xiOct 20, 2020

  • Remote Code Execution (RCE)

    HighCVSS 8.8No exploitEPSS 35%

    ungit project · ungitMar 21, 2022

  • Some implementations of rlogin allow root access if given a -froot parameter.

    CriticalCVSS 10.0Proof of conceptEPSS 17%

    ibm · aixMay 23, 1994

  • Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as argume

    HighCVSS 7.5Proof of conceptEPSS 48%

    microsoft · officeApr 15, 2004

  • Cisco Modeling Labs Web UI Command Injection Vulnerability

    HighCVSS 8.8No exploitEPSS 30%

    cisco · modeling labsMay 22, 2021

  • TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers.

    HighCVSS 8.8WeaponizedEPSS 26%

    teamviewer · teamviewerJul 29, 2020

  • Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute arbitrary code via a notes: URI that us

    CriticalCVSS 10.0No exploitEPSS 9%

    ibm · lotus notesDec 6, 2004

  • Bitcoin Core before 0.19.0 might allow remote attackers to execute arbitrary code when another application unsafely passes the -platformplug

    CriticalCVSS 9.8No exploitEPSS 10%

    bitcoin · bitcoinFeb 4, 2021

  • encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or

    CriticalCVSS 9.8No exploitEPSS 9%

    gnu · screenFeb 9, 2021

  • LearnPress <= 4.2.5.7 - Command Injection

    CriticalCVSS 9.8Proof of conceptEPSS 9%

    thimpress · learnpressJan 11, 2024

  • The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution.

    CriticalCVSS 9.9Proof of conceptEPSS 8%

    gogs · gogsJul 4, 2024

  • The package workspace-tools before 0.18.4 are vulnerable to Command Injection via git argument injection.

    CriticalCVSS 9.8No exploitEPSS 7%

    microsoft · workspace-toolsMay 13, 2022

  • In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client application that does not va

    CriticalCVSS 9.8No exploitEPSS 5%

    python-libnmap project · python-libnmapMay 4, 2022

All vulnerability classes