CWE-88 · 399 записей
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
CVE этого класса
399 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2016-10033Готовый эксплойт | The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail cphpmailer project · phpmailer · CWE-88 | Критическая9,8 | KEV | 99,7 % | 30 дек. 2016 г. |
99Срочно | CVE-2026-24061Готовый эксплойт | telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.gnu · inetutils · CWE-88 | Критическая9,8 | KEV | 99,0 % | 21 янв. 2026 г. |
70На этой неделе | CVE-2024-41710Готовый эксплойт | A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (mitel · 6970 firmware · CWE-88 | Высокая7,2 | KEV | 41,6 % | 12 авг. 2024 г. |
69На этой неделе | CVE-2007-0882Готовый эксплойт | Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "sun · sunos · CWE-88 | Критическая10,0 | — | 98,0 % | 12 февр. 2007 г. |
68На этой неделе | CVE-2018-17456Готовый эксплойт | Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows rgit-scm · git · CWE-88 | Критическая9,8 | — | 97,4 % | 6 окт. 2018 г. |
67На этой неделе | CVE-2026-86060Готовый эксплойт | SSH session privilege manipulation via a crafted username in Mikrotik RouterOSmikrotik · routeros · CWE-88 | Критическая9,2 | KEV | 1,8 % | 5 сент. 2026 г. |
61На этой неделе | CVE-2021-33564Proof of concept | An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files dragonfly project · dragonfly · CWE-88 | Критическая9,8 | — | 72,1 % | 29 мая 2021 г. |
59В плане | CVE-2018-19518Готовый эксплойт | University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of php · php · CWE-88 | Высокая7,5 | — | 96,1 % | 25 нояб. 2018 г. |
58В плане | CVE-2022-23221Proof of concept | H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGh2database · h2 · CWE-88 | Критическая9,8 | — | 64,8 % | 19 янв. 2022 г. |
51В плане | CVE-2020-21224Proof of concept | A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0.inspur · clusterengine · CWE-88 | Критическая9,8 | — | 38,7 % | 22 февр. 2021 г. |
48В плане | CVE-2019-6453Proof of concept | mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers.mirc · mirc · CWE-88 | Высокая8,1 | — | 54,3 % | 18 февр. 2019 г. |
47В плане | CVE-2024-52301Proof of concept | Laravel allows environment manipulation via query stringlaravel · framework · CWE-88 | Высокая8,7 | — | 44,8 % | 12 нояб. 2024 г. |
46В плане | CVE-2020-5792Готовый эксплойт | Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user to write to arbitranagios · nagios xi · CWE-88 | Высокая7,2 | — | 59,5 % | 20 окт. 2020 г. |
45В плане | CVE-2022-25766Эксплойта нет | Remote Code Execution (RCE)ungit project · ungit · CWE-88 | Высокая8,8 | — | 34,3 % | 21 мар. 2022 г. |
45В плане | CVE-1999-0113Proof of concept | Some implementations of rlogin allow root access if given a -froot parameter.ibm · aix · CWE-88 | Критическая10,0 | — | 17,2 % | 23 мая 1994 г. |
44В плане | CVE-2004-0121Proof of concept | Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as argumemicrosoft · office · CWE-88 | Высокая7,5 | — | 47,7 % | 15 апр. 2004 г. |
44В плане | CVE-2021-1531Эксплойта нет | Cisco Modeling Labs Web UI Command Injection Vulnerabilitycisco · modeling labs · CWE-88 | Высокая8,8 | — | 30,5 % | 22 мая 2021 г. |
43В плане | CVE-2020-13699Готовый эксплойт | TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers.teamviewer · teamviewer · CWE-88 | Высокая8,8 | — | 25,8 % | 29 июл. 2020 г. |
43В плане | CVE-2004-0480Эксплойта нет | Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute arbitrary code via a notes: URI that usibm · lotus notes · CWE-88 | Критическая10,0 | — | 8,6 % | 6 дек. 2004 г. |
42В плане | CVE-2021-3401Эксплойта нет | Bitcoin Core before 0.19.0 might allow remote attackers to execute arbitrary code when another application unsafely passes the -platformplugbitcoin · bitcoin · CWE-88 | Критическая9,8 | — | 10,5 % | 4 февр. 2021 г. |
42В плане | CVE-2021-26937Эксплойта нет | encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or gnu · screen · CWE-88 | Критическая9,8 | — | 9,1 % | 9 февр. 2021 г. |
42В плане | CVE-2023-6634Proof of concept | LearnPress <= 4.2.5.7 - Command Injectionthimpress · learnpress · CWE-88 | Критическая9,8 | — | 8,5 % | 11 янв. 2024 г. |
41В плане | CVE-2024-39930Proof of concept | The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution.gogs · gogs · CWE-88 | Критическая9,9 | — | 7,7 % | 4 июл. 2024 г. |
41В плане | CVE-2022-25865Эксплойта нет | The package workspace-tools before 0.18.4 are vulnerable to Command Injection via git argument injection.microsoft · workspace-tools · CWE-88 | Критическая9,8 | — | 7,0 % | 13 мая 2022 г. |
41В плане | CVE-2022-30284Эксплойта нет | In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client application that does not vapython-libnmap project · python-libnmap · CWE-88 | Критическая9,8 | — | 5,5 % | 4 мая 2022 г. |
- CVE-2016-1003399Срочно
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail c
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %phpmailer project · phpmailer30 дек. 2016 г.
- CVE-2026-2406199Срочно
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %gnu · inetutils21 янв. 2026 г.
- CVE-2024-4171070На этой неделе
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (
ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 42 %mitel · 6970 firmware12 авг. 2024 г.
- CVE-2007-088269На этой неделе
Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "
КритическаяCVSS 10,0Готовый эксплойтEPSS 98 %sun · sunos12 февр. 2007 г.
- CVE-2018-1745668На этой неделе
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows r
КритическаяCVSS 9,8Готовый эксплойтEPSS 97 %git-scm · git6 окт. 2018 г.
- CVE-2026-8606067На этой неделе
SSH session privilege manipulation via a crafted username in Mikrotik RouterOS
КритическаяCVSS 9,2KEVГотовый эксплойтEPSS 2 %mikrotik · routeros5 сент. 2026 г.
- CVE-2021-3356461На этой неделе
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files
КритическаяCVSS 9,8Proof of conceptEPSS 72 %dragonfly project · dragonfly29 мая 2021 г.
- CVE-2018-1951859В плане
University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of
ВысокаяCVSS 7,5Готовый эксплойтEPSS 96 %php · php25 нояб. 2018 г.
- CVE-2022-2322158В плане
H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTING
КритическаяCVSS 9,8Proof of conceptEPSS 65 %h2database · h219 янв. 2022 г.
- CVE-2020-2122451В плане
A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0.
КритическаяCVSS 9,8Proof of conceptEPSS 39 %inspur · clusterengine22 февр. 2021 г.
- CVE-2019-645348В плане
mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers.
ВысокаяCVSS 8,1Proof of conceptEPSS 54 %mirc · mirc18 февр. 2019 г.
- CVE-2024-5230147В плане
Laravel allows environment manipulation via query string
ВысокаяCVSS 8,7Proof of conceptEPSS 45 %laravel · framework12 нояб. 2024 г.
- CVE-2020-579246В плане
Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user to write to arbitra
ВысокаяCVSS 7,2Готовый эксплойтEPSS 59 %nagios · nagios xi20 окт. 2020 г.
- CVE-2022-2576645В плане
Remote Code Execution (RCE)
ВысокаяCVSS 8,8Эксплойта нетEPSS 34 %ungit project · ungit21 мар. 2022 г.
- CVE-1999-011345В плане
Some implementations of rlogin allow root access if given a -froot parameter.
КритическаяCVSS 10,0Proof of conceptEPSS 17 %ibm · aix23 мая 1994 г.
- CVE-2004-012144В плане
Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as argume
ВысокаяCVSS 7,5Proof of conceptEPSS 48 %microsoft · office15 апр. 2004 г.
- CVE-2021-153144В плане
Cisco Modeling Labs Web UI Command Injection Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 30 %cisco · modeling labs22 мая 2021 г.
- CVE-2020-1369943В плане
TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers.
ВысокаяCVSS 8,8Готовый эксплойтEPSS 26 %teamviewer · teamviewer29 июл. 2020 г.
- CVE-2004-048043В плане
Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute arbitrary code via a notes: URI that us
КритическаяCVSS 10,0Эксплойта нетEPSS 9 %ibm · lotus notes6 дек. 2004 г.
- CVE-2021-340142В плане
Bitcoin Core before 0.19.0 might allow remote attackers to execute arbitrary code when another application unsafely passes the -platformplug
КритическаяCVSS 9,8Эксплойта нетEPSS 10 %bitcoin · bitcoin4 февр. 2021 г.
- CVE-2021-2693742В плане
encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or
КритическаяCVSS 9,8Эксплойта нетEPSS 9 %gnu · screen9 февр. 2021 г.
- CVE-2023-663442В плане
LearnPress <= 4.2.5.7 - Command Injection
КритическаяCVSS 9,8Proof of conceptEPSS 9 %thimpress · learnpress11 янв. 2024 г.
- CVE-2024-3993041В плане
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution.
КритическаяCVSS 9,9Proof of conceptEPSS 8 %gogs · gogs4 июл. 2024 г.
- CVE-2022-2586541В плане
The package workspace-tools before 0.18.4 are vulnerable to Command Injection via git argument injection.
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %microsoft · workspace-tools13 мая 2022 г.
- CVE-2022-3028441В плане
In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client application that does not va
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %python-libnmap project · python-libnmap4 мая 2022 г.