İçeriğe atla
Noroxi

CWE-88 · 398 kayıt

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

Bu sınıftaki CVE’ler

399 kayıt

  • The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail c

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    phpmailer project · phpmailer30 Ara 2016

  • telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    gnu · inetutils21 Oca 2026

  • CVE-2024-41710
    70Bu hafta

    A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (

    YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %42

    mitel · 6970 firmware12 Ağu 2024

  • CVE-2007-0882
    69Bu hafta

    Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "

    KritikCVSS 10,0SilahlaştırılmışEPSS %98

    sun · sunos12 Şub 2007

  • CVE-2018-17456
    68Bu hafta

    Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows r

    KritikCVSS 9,8SilahlaştırılmışEPSS %97

    git-scm · git6 Eki 2018

  • CVE-2026-86060
    67Bu hafta

    SSH session privilege manipulation via a crafted username in Mikrotik RouterOS

    KritikCVSS 9,2KEVSilahlaştırılmışEPSS %2

    mikrotik · routeros5 Eyl 2026

  • CVE-2021-33564
    61Bu hafta

    An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files

    KritikCVSS 9,8Kavram kanıtıEPSS %72

    dragonfly project · dragonfly29 May 2021

  • CVE-2018-19518
    59Planlayın

    University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of

    YüksekCVSS 7,5SilahlaştırılmışEPSS %96

    php · php25 Kas 2018

  • CVE-2022-23221
    58Planlayın

    H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTING

    KritikCVSS 9,8Kavram kanıtıEPSS %65

    h2database · h219 Oca 2022

  • CVE-2020-21224
    51Planlayın

    A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0.

    KritikCVSS 9,8Kavram kanıtıEPSS %39

    inspur · clusterengine22 Şub 2021

  • CVE-2019-6453
    48Planlayın

    mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers.

    YüksekCVSS 8,1Kavram kanıtıEPSS %54

    mirc · mirc18 Şub 2019

  • CVE-2024-52301
    47Planlayın

    Laravel allows environment manipulation via query string

    YüksekCVSS 8,7Kavram kanıtıEPSS %45

    laravel · framework12 Kas 2024

  • CVE-2020-5792
    46Planlayın

    Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user to write to arbitra

    YüksekCVSS 7,2SilahlaştırılmışEPSS %59

    nagios · nagios xi20 Eki 2020

  • CVE-2022-25766
    45Planlayın

    Remote Code Execution (RCE)

    YüksekCVSS 8,8İstismar yokEPSS %34

    ungit project · ungit21 Mar 2022

  • CVE-1999-0113
    45Planlayın

    Some implementations of rlogin allow root access if given a -froot parameter.

    KritikCVSS 10,0Kavram kanıtıEPSS %17

    ibm · aix23 May 1994

  • CVE-2004-0121
    44Planlayın

    Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as argume

    YüksekCVSS 7,5Kavram kanıtıEPSS %48

    microsoft · office15 Nis 2004

  • CVE-2021-1531
    44Planlayın

    Cisco Modeling Labs Web UI Command Injection Vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %30

    cisco · modeling labs22 May 2021

  • CVE-2020-13699
    43Planlayın

    TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers.

    YüksekCVSS 8,8SilahlaştırılmışEPSS %26

    teamviewer · teamviewer29 Tem 2020

  • CVE-2004-0480
    43Planlayın

    Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute arbitrary code via a notes: URI that us

    KritikCVSS 10,0İstismar yokEPSS %9

    ibm · lotus notes6 Ara 2004

  • CVE-2021-3401
    42Planlayın

    Bitcoin Core before 0.19.0 might allow remote attackers to execute arbitrary code when another application unsafely passes the -platformplug

    KritikCVSS 9,8İstismar yokEPSS %10

    bitcoin · bitcoin4 Şub 2021

  • CVE-2021-26937
    42Planlayın

    encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or

    KritikCVSS 9,8İstismar yokEPSS %9

    gnu · screen9 Şub 2021

  • CVE-2023-6634
    42Planlayın

    LearnPress <= 4.2.5.7 - Command Injection

    KritikCVSS 9,8Kavram kanıtıEPSS %9

    thimpress · learnpress11 Oca 2024

  • CVE-2024-39930
    41Planlayın

    The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution.

    KritikCVSS 9,9Kavram kanıtıEPSS %8

    gogs · gogs4 Tem 2024

  • CVE-2022-25865
    41Planlayın

    The package workspace-tools before 0.18.4 are vulnerable to Command Injection via git argument injection.

    KritikCVSS 9,8İstismar yokEPSS %7

    microsoft · workspace-tools13 May 2022

  • CVE-2022-30284
    41Planlayın

    In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client application that does not va

    KritikCVSS 9,8İstismar yokEPSS %5

    python-libnmap project · python-libnmap4 May 2022

Tüm zafiyet sınıfları