CWE-88 · 398 kayıt
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
Bu sınıftaki CVE’ler
399 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2016-10033Silahlaştırılmış | The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail cphpmailer project · phpmailer · CWE-88 | Kritik9,8 | KEV | %99,7 | 30 Ara 2016 |
99Hemen | CVE-2026-24061Silahlaştırılmış | telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.gnu · inetutils · CWE-88 | Kritik9,8 | KEV | %99,0 | 21 Oca 2026 |
70Bu hafta | CVE-2024-41710Silahlaştırılmış | A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (mitel · 6970 firmware · CWE-88 | Yüksek7,2 | KEV | %41,6 | 12 Ağu 2024 |
69Bu hafta | CVE-2007-0882Silahlaştırılmış | Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "sun · sunos · CWE-88 | Kritik10,0 | — | %98,0 | 12 Şub 2007 |
68Bu hafta | CVE-2018-17456Silahlaştırılmış | Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows rgit-scm · git · CWE-88 | Kritik9,8 | — | %97,4 | 6 Eki 2018 |
67Bu hafta | CVE-2026-86060Silahlaştırılmış | SSH session privilege manipulation via a crafted username in Mikrotik RouterOSmikrotik · routeros · CWE-88 | Kritik9,2 | KEV | %1,8 | 5 Eyl 2026 |
61Bu hafta | CVE-2021-33564Kavram kanıtı | An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files dragonfly project · dragonfly · CWE-88 | Kritik9,8 | — | %72,1 | 29 May 2021 |
59Planlayın | CVE-2018-19518Silahlaştırılmış | University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of php · php · CWE-88 | Yüksek7,5 | — | %96,1 | 25 Kas 2018 |
58Planlayın | CVE-2022-23221Kavram kanıtı | H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGh2database · h2 · CWE-88 | Kritik9,8 | — | %64,8 | 19 Oca 2022 |
51Planlayın | CVE-2020-21224Kavram kanıtı | A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0.inspur · clusterengine · CWE-88 | Kritik9,8 | — | %38,7 | 22 Şub 2021 |
48Planlayın | CVE-2019-6453Kavram kanıtı | mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers.mirc · mirc · CWE-88 | Yüksek8,1 | — | %54,3 | 18 Şub 2019 |
47Planlayın | CVE-2024-52301Kavram kanıtı | Laravel allows environment manipulation via query stringlaravel · framework · CWE-88 | Yüksek8,7 | — | %44,8 | 12 Kas 2024 |
46Planlayın | CVE-2020-5792Silahlaştırılmış | Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user to write to arbitranagios · nagios xi · CWE-88 | Yüksek7,2 | — | %59,5 | 20 Eki 2020 |
45Planlayın | CVE-2022-25766İstismar yok | Remote Code Execution (RCE)ungit project · ungit · CWE-88 | Yüksek8,8 | — | %34,3 | 21 Mar 2022 |
45Planlayın | CVE-1999-0113Kavram kanıtı | Some implementations of rlogin allow root access if given a -froot parameter.ibm · aix · CWE-88 | Kritik10,0 | — | %17,2 | 23 May 1994 |
44Planlayın | CVE-2004-0121Kavram kanıtı | Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as argumemicrosoft · office · CWE-88 | Yüksek7,5 | — | %47,7 | 15 Nis 2004 |
44Planlayın | CVE-2021-1531İstismar yok | Cisco Modeling Labs Web UI Command Injection Vulnerabilitycisco · modeling labs · CWE-88 | Yüksek8,8 | — | %30,5 | 22 May 2021 |
43Planlayın | CVE-2020-13699Silahlaştırılmış | TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers.teamviewer · teamviewer · CWE-88 | Yüksek8,8 | — | %25,8 | 29 Tem 2020 |
43Planlayın | CVE-2004-0480İstismar yok | Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute arbitrary code via a notes: URI that usibm · lotus notes · CWE-88 | Kritik10,0 | — | %8,6 | 6 Ara 2004 |
42Planlayın | CVE-2021-3401İstismar yok | Bitcoin Core before 0.19.0 might allow remote attackers to execute arbitrary code when another application unsafely passes the -platformplugbitcoin · bitcoin · CWE-88 | Kritik9,8 | — | %10,5 | 4 Şub 2021 |
42Planlayın | CVE-2021-26937İstismar yok | encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or gnu · screen · CWE-88 | Kritik9,8 | — | %9,1 | 9 Şub 2021 |
42Planlayın | CVE-2023-6634Kavram kanıtı | LearnPress <= 4.2.5.7 - Command Injectionthimpress · learnpress · CWE-88 | Kritik9,8 | — | %8,5 | 11 Oca 2024 |
41Planlayın | CVE-2024-39930Kavram kanıtı | The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution.gogs · gogs · CWE-88 | Kritik9,9 | — | %7,7 | 4 Tem 2024 |
41Planlayın | CVE-2022-25865İstismar yok | The package workspace-tools before 0.18.4 are vulnerable to Command Injection via git argument injection.microsoft · workspace-tools · CWE-88 | Kritik9,8 | — | %7,0 | 13 May 2022 |
41Planlayın | CVE-2022-30284İstismar yok | In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client application that does not vapython-libnmap project · python-libnmap · CWE-88 | Kritik9,8 | — | %5,5 | 4 May 2022 |
- CVE-2016-1003399Hemen
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail c
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100phpmailer project · phpmailer30 Ara 2016
- CVE-2026-2406199Hemen
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99gnu · inetutils21 Oca 2026
- CVE-2024-4171070Bu hafta
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (
YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %42mitel · 6970 firmware12 Ağu 2024
- CVE-2007-088269Bu hafta
Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "
KritikCVSS 10,0SilahlaştırılmışEPSS %98sun · sunos12 Şub 2007
- CVE-2018-1745668Bu hafta
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows r
KritikCVSS 9,8SilahlaştırılmışEPSS %97git-scm · git6 Eki 2018
- CVE-2026-8606067Bu hafta
SSH session privilege manipulation via a crafted username in Mikrotik RouterOS
KritikCVSS 9,2KEVSilahlaştırılmışEPSS %2mikrotik · routeros5 Eyl 2026
- CVE-2021-3356461Bu hafta
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files
KritikCVSS 9,8Kavram kanıtıEPSS %72dragonfly project · dragonfly29 May 2021
- CVE-2018-1951859Planlayın
University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of
YüksekCVSS 7,5SilahlaştırılmışEPSS %96php · php25 Kas 2018
- CVE-2022-2322158Planlayın
H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTING
KritikCVSS 9,8Kavram kanıtıEPSS %65h2database · h219 Oca 2022
- CVE-2020-2122451Planlayın
A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0.
KritikCVSS 9,8Kavram kanıtıEPSS %39inspur · clusterengine22 Şub 2021
- CVE-2019-645348Planlayın
mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers.
YüksekCVSS 8,1Kavram kanıtıEPSS %54mirc · mirc18 Şub 2019
- CVE-2024-5230147Planlayın
Laravel allows environment manipulation via query string
YüksekCVSS 8,7Kavram kanıtıEPSS %45laravel · framework12 Kas 2024
- CVE-2020-579246Planlayın
Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user to write to arbitra
YüksekCVSS 7,2SilahlaştırılmışEPSS %59nagios · nagios xi20 Eki 2020
- CVE-2022-2576645Planlayın
Remote Code Execution (RCE)
YüksekCVSS 8,8İstismar yokEPSS %34ungit project · ungit21 Mar 2022
- CVE-1999-011345Planlayın
Some implementations of rlogin allow root access if given a -froot parameter.
KritikCVSS 10,0Kavram kanıtıEPSS %17ibm · aix23 May 1994
- CVE-2004-012144Planlayın
Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as argume
YüksekCVSS 7,5Kavram kanıtıEPSS %48microsoft · office15 Nis 2004
- CVE-2021-153144Planlayın
Cisco Modeling Labs Web UI Command Injection Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %30cisco · modeling labs22 May 2021
- CVE-2020-1369943Planlayın
TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers.
YüksekCVSS 8,8SilahlaştırılmışEPSS %26teamviewer · teamviewer29 Tem 2020
- CVE-2004-048043Planlayın
Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute arbitrary code via a notes: URI that us
KritikCVSS 10,0İstismar yokEPSS %9ibm · lotus notes6 Ara 2004
- CVE-2021-340142Planlayın
Bitcoin Core before 0.19.0 might allow remote attackers to execute arbitrary code when another application unsafely passes the -platformplug
KritikCVSS 9,8İstismar yokEPSS %10bitcoin · bitcoin4 Şub 2021
- CVE-2021-2693742Planlayın
encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or
KritikCVSS 9,8İstismar yokEPSS %9gnu · screen9 Şub 2021
- CVE-2023-663442Planlayın
LearnPress <= 4.2.5.7 - Command Injection
KritikCVSS 9,8Kavram kanıtıEPSS %9thimpress · learnpress11 Oca 2024
- CVE-2024-3993041Planlayın
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution.
KritikCVSS 9,9Kavram kanıtıEPSS %8gogs · gogs4 Tem 2024
- CVE-2022-2586541Planlayın
The package workspace-tools before 0.18.4 are vulnerable to Command Injection via git argument injection.
KritikCVSS 9,8İstismar yokEPSS %7microsoft · workspace-tools13 May 2022
- CVE-2022-3028441Planlayın
In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client application that does not va
KritikCVSS 9,8İstismar yokEPSS %5python-libnmap project · python-libnmap4 May 2022