VulnSea

CWE-88

CVEs classified under CWE-88, newest first.

103 CVEsRSS

CVE-2026-28197High· 8.8
3d ago

An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially crafted input to a privileged administrative command, causing it to execute arbitrary code with root-level permission…

An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially crafted input to a privileged administrative command, causing it to execute arbitrary code with root-level permission…

TwilightCohesity · NetBackup Flex OSEPSS 0.37%via NVD
CVE-2026-54501Critical· 9.4
4d ago

Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance

Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance. From 1.15.0 until 1.22.8, Browsertrix improperly sanitizes Git URLs specified as Cust…

Midnightwebrecorder · browsertrixEPSS 1.2%via NVD
CVE-2026-93337High· 7.8
4d ago

NetworkManager-l2tp contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd directives by supplying mru or mtu property values containing trailing non-…

NetworkManager-l2tp contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd directives by supplying mru or mtu property values containing trailing non-…

Twilightnm-l2tp · NetworkManager-l2tpEPSS 0.15%via NVD
CVE-2026-89036High· 8.8
4d ago

Appwrite before 2.0.0 contains an argument injection vulnerability that allows authenticated users with functions.write or sites.write permissions to execute arbitrary commands by injecting TAB characters into the providerRootDirectory p…

Appwrite before 2.0.0 contains an argument injection vulnerability that allows authenticated users with functions.write or sites.write permissions to execute arbitrary commands by injecting TAB characters into the providerRootDirectory p…

Twilightappwrite · appwriteEPSS 0.70%via NVD
CVE-2026-86864High· 8.8
4d ago

pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the pg_dump argument vector as a bare trailing positional argument, without validation

pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the pg_dump argument vector as a bare trailing positional argument, without validation. Because pg_dump parses its options…

Twilightpgadmin · pgadmin_4EPSS 0.38%via NVD
CVE-2026-86862Medium· 6.5
4d ago

pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbname option given to pg_restore and psql

pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbname option given to pg_restore and psql. libpq expands a database name containing an equals sign into a full connecti…

Sunlitpgadmin · pgadmin_4EPSS 0.20%via NVD
CVE-2026-55061Low· 1.0
4d ago

uniget is a universal installer and updater for (container) tools

uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go parses UNIGET_EDITOR or EDITOR with strings.Split(editor, " ") and passes every space-delimited suffix as a…

Sunlituniget-org · cliEPSS 0.12%via NVD
CVE-2026-76866High· 7.2
6d ago

Netcore NR255-V firmware version 1.5.130703 builds root-run command lines from unquoted user-supplied DDNS input in DDNSset_cgi.c and related ddns_Proc.c components, enabling os command argument injection

Netcore NR255-V firmware version 1.5.130703 builds root-run command lines from unquoted user-supplied DDNS input in DDNSset_cgi.c and related ddns_Proc.c components, enabling os command argument injection. Attackers can exploit the unsan…

TwilightNetcore · NR255-VEPSS 0.43%via NVD
CVE-2026-76862High· 8.8
6d ago

Netcore NR255-V version 1.5.130703 contains an os command argument injection vulnerability in the Nettools tcpdump launch paths, including ntools_start_set_cgi, ntools_tcpdump_start_set_cgi, exe_default, and ntools_proc components

Netcore NR255-V version 1.5.130703 contains an os command argument injection vulnerability in the Nettools tcpdump launch paths, including ntools_start_set_cgi, ntools_tcpdump_start_set_cgi, exe_default, and ntools_proc components. Attac…

TwilightNetcore · NR255-VEPSS 0.41%via NVD
CVE-2026-54337Critical· 9.8PoC
6d ago

Fireshare facilitates self-hosted media and link sharing

Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.14, an argument Injection in the video upload function allows unauthenticated attacker to write/overwrite system files. Version 1.6.14 fixes the issue.

AbyssalShaneIsrael · fireshareEPSS 0.44%via NVD
CVE-2026-55887High· 8.7
6d ago

MCP Gateway allows easy and secure running and deployment of MCP servers

MCP Gateway allows easy and secure running and deployment of MCP servers. From 0.21.0 until 0.42.2, Docker MCP Gateway YAML-unmarshalled the attacker-controlled io.docker.server.metadata OCI image label into the broad catalog.Server stru…

Twilightdocker · mcp-gatewayEPSS 0.20%via NVD
CVE-2026-19624High· 7.8
1w ago

A flaw was found in NetworkManager-l2tp

A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto loads as root. A local unprivileged user can…

TwilightFedora · NetworkManager-l2tpEPSS 0.13%via NVD
CVE-2026-90809High· 7.3
1w ago

A vulnerability was identified in HKUDS nanobot up to 0.2.1

A vulnerability was identified in HKUDS nanobot up to 0.2.1. The affected element is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. Such manipulation leads to argu…

TwilightHKUDS · nanobotEPSS 0.33%via NVD
CVE-2023-22632Low· 2.7
1w ago

PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the FTP Server Count Sensor.

PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the FTP Server Count Sensor.

SunlitPaessler · PRTG Network MonitorEPSS 0.22%via NVD
CVE-2023-22631Low· 2.7
1w ago

PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the HTTP XML/REST Sensor.

PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the HTTP XML/REST Sensor.

SunlitPaessler · PRTG Network MonitorEPSS 0.22%via NVD
CVE-2026-90894High· 7.8
1w ago

Parallels Desktop runs prl_disp_service as root

Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_service.socket. PrlSrv_LoginLocal accepts peer credentials. No Parallels signature. No admin group. After login, Pr…

TwilightParallels · Parallels DesktopEPSS 0.15%via NVD
CVE-2026-90467Medium· 4.0
1w ago

aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines

aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines. Attackers can craft malicious addresses containing spaces and…

Sunlitcole · aiosmtplibEPSS 0.23%via NVD
CVE-2026-89459Medium· 5.5⚖ disputed
1w ago

kernel: s390/percpu: Fix MVIY_PERCPU() with older binutils (CVE-2026-89459)

A flaw was found in the Linux kernel's s390/percpu component. This vulnerability arises when the kernel is compiled with older versions of GNU as (prior to binutils 2.39). A parsing error prevents a crucial instruction from being correctly…

SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.11%via CSAF
CVE-2026-11765Low· 3.3
1w ago

Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Pen allows Argument Injection. This issue affects Pardus Pen: before 4.2.1.

Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Pen allows Argument Injection. This issue affects Pardus Pen: before 4.2.1.

SunlitTUBITAK BILGEM Software Technologies Research Institute · Pardus PenEPSS 0.12%via NVD
CVE-2026-89066High· 7.8
1w ago

Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 might allow context-dependent attackers to execute arbitrary commands on a developer workstation or continuous int…

Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 might allow context-dependent attackers to execute arbitrary commands on a developer workstation or continuous int…

TwilightAWS · projenEPSS 0.16%via NVD
CVE-2026-0304Medium· 4.8
1w ago

A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.

A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.

SunlitPalo Alto Networks · Cortex XDR Broker VMEPSS 0.22%via NVD
CVE-2026-8044High· 8.6
1w ago

CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability exists that could cause remote code execution by an attacker with a privileged account when malicious arguments are provided as back…

CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability exists that could cause remote code execution by an attacker with a privileged account when malicious arguments are provided as back…

TwilightSchneider Electric · EcoStruxure™ IT Data Center Expert (Formerly known as StruxureWare Data Center Expert)EPSS 0.43%via CVEORG
CVE-2026-87794High· 8.4
1w ago

bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend

bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combine…

Twilightnfriedly · bestzipEPSS 0.19%via NVD
CVE-2026-87818Medium· 6.5PoC
1w ago

GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands

GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create…

Twilightgitpython_project · gitpythonEPSS 0.24%via NVD
CVE-2026-78635Medium· 5.0
1w ago

The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments

The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments. When a scaleft:// protocol handler link contains a value beginning with a hyphen, the und…

SunlitOkta · Okta Privileged Access ClientEPSS 0.16%via NVD
CVE-2026-71377Critical· 9.8
1w ago

Command Argument Injection Vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11…

Command Argument Injection Vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11…

MidnightHitachi · Cosminexus Component ContainerEPSS 0.31%via NVD
CVE-2026-84256High· 7.7
2w ago

An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a crafted certificate subject

An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a crafted certificate subject

TwilightOpenVPN · OpenVPNEPSS 0.38%via NVD
CVE-2026-86060Critical· 9.8CISA KEVPoC
2w ago

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requ…

Hadalmikrotik · routerosEPSS 1.1%via NVD
CVE-2026-74237Medium· 6.5
2w ago

GFI Exinda AI and ClearView before 7.6.5 contains an argument injection vulnerability in the Tools Iperf Client functionality

GFI Exinda AI and ClearView before 7.6.5 contains an argument injection vulnerability in the Tools Iperf Client functionality. The web_tools_cmd() function constructs an iperf command using the server and options parameters without sanit…

SunlitGFI Software · GFI Exinda AIEPSS 0.23%via NVD
CVE-2026-85626High· 7.5PoC
2w ago

git-mcp-server 2.15.1 Argument Injection via Git Ref Parameters

git-mcp-server 2.15.1 contains an argument injection vulnerability in the ref and object parameters of git_log, git_diff, and git_show tools that lack leading-dash validation. Attackers can inject git command-line options like --output= …

Midnightcyanheads · git-mcp-serverEPSS 0.27%via CVEORG
CWE-88 vulnerabilities (CVEs) · VulnSea