Перейти к содержимому
Noroxi

CWE-88 · 399 записей

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

CVE этого класса

399 записей

  • CVE-2016-10033
    99Срочно

    The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail c

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    phpmailer project · phpmailer30 дек. 2016 г.

  • CVE-2026-24061
    99Срочно

    telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    gnu · inetutils21 янв. 2026 г.

  • CVE-2024-41710
    70На этой неделе

    A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (

    ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 42 %

    mitel · 6970 firmware12 авг. 2024 г.

  • CVE-2007-0882
    69На этой неделе

    Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "

    КритическаяCVSS 10,0Готовый эксплойтEPSS 98 %

    sun · sunos12 февр. 2007 г.

  • CVE-2018-17456
    68На этой неделе

    Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows r

    КритическаяCVSS 9,8Готовый эксплойтEPSS 97 %

    git-scm · git6 окт. 2018 г.

  • CVE-2026-86060
    67На этой неделе

    SSH session privilege manipulation via a crafted username in Mikrotik RouterOS

    КритическаяCVSS 9,2KEVГотовый эксплойтEPSS 2 %

    mikrotik · routeros5 сент. 2026 г.

  • CVE-2021-33564
    61На этой неделе

    An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files

    КритическаяCVSS 9,8Proof of conceptEPSS 72 %

    dragonfly project · dragonfly29 мая 2021 г.

  • CVE-2018-19518
    59В плане

    University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of

    ВысокаяCVSS 7,5Готовый эксплойтEPSS 96 %

    php · php25 нояб. 2018 г.

  • CVE-2022-23221
    58В плане

    H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTING

    КритическаяCVSS 9,8Proof of conceptEPSS 65 %

    h2database · h219 янв. 2022 г.

  • CVE-2020-21224
    51В плане

    A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0.

    КритическаяCVSS 9,8Proof of conceptEPSS 39 %

    inspur · clusterengine22 февр. 2021 г.

  • CVE-2019-6453
    48В плане

    mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers.

    ВысокаяCVSS 8,1Proof of conceptEPSS 54 %

    mirc · mirc18 февр. 2019 г.

  • CVE-2024-52301
    47В плане

    Laravel allows environment manipulation via query string

    ВысокаяCVSS 8,7Proof of conceptEPSS 45 %

    laravel · framework12 нояб. 2024 г.

  • CVE-2020-5792
    46В плане

    Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user to write to arbitra

    ВысокаяCVSS 7,2Готовый эксплойтEPSS 59 %

    nagios · nagios xi20 окт. 2020 г.

  • CVE-2022-25766
    45В плане

    Remote Code Execution (RCE)

    ВысокаяCVSS 8,8Эксплойта нетEPSS 34 %

    ungit project · ungit21 мар. 2022 г.

  • CVE-1999-0113
    45В плане

    Some implementations of rlogin allow root access if given a -froot parameter.

    КритическаяCVSS 10,0Proof of conceptEPSS 17 %

    ibm · aix23 мая 1994 г.

  • CVE-2004-0121
    44В плане

    Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as argume

    ВысокаяCVSS 7,5Proof of conceptEPSS 48 %

    microsoft · office15 апр. 2004 г.

  • CVE-2021-1531
    44В плане

    Cisco Modeling Labs Web UI Command Injection Vulnerability

    ВысокаяCVSS 8,8Эксплойта нетEPSS 30 %

    cisco · modeling labs22 мая 2021 г.

  • CVE-2020-13699
    43В плане

    TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers.

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 26 %

    teamviewer · teamviewer29 июл. 2020 г.

  • CVE-2004-0480
    43В плане

    Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute arbitrary code via a notes: URI that us

    КритическаяCVSS 10,0Эксплойта нетEPSS 9 %

    ibm · lotus notes6 дек. 2004 г.

  • CVE-2021-3401
    42В плане

    Bitcoin Core before 0.19.0 might allow remote attackers to execute arbitrary code when another application unsafely passes the -platformplug

    КритическаяCVSS 9,8Эксплойта нетEPSS 10 %

    bitcoin · bitcoin4 февр. 2021 г.

  • CVE-2021-26937
    42В плане

    encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or

    КритическаяCVSS 9,8Эксплойта нетEPSS 9 %

    gnu · screen9 февр. 2021 г.

  • CVE-2023-6634
    42В плане

    LearnPress <= 4.2.5.7 - Command Injection

    КритическаяCVSS 9,8Proof of conceptEPSS 9 %

    thimpress · learnpress11 янв. 2024 г.

  • CVE-2024-39930
    41В плане

    The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution.

    КритическаяCVSS 9,9Proof of conceptEPSS 8 %

    gogs · gogs4 июл. 2024 г.

  • CVE-2022-25865
    41В плане

    The package workspace-tools before 0.18.4 are vulnerable to Command Injection via git argument injection.

    КритическаяCVSS 9,8Эксплойта нетEPSS 7 %

    microsoft · workspace-tools13 мая 2022 г.

  • CVE-2022-30284
    41В плане

    In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client application that does not va

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    python-libnmap project · python-libnmap4 мая 2022 г.

Все классы уязвимостей