Vulnerabilities > Argument Injection or Modification

DATE CVE VULNERABILITY TITLE RISK
2020-07-29 CVE-2020-13699 Argument Injection or Modification vulnerability in Teamviewer
TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers.
network
low complexity
teamviewer CWE-88
8.8
2020-07-16 CVE-2020-3380 Argument Injection or Modification vulnerability in Cisco Data Center Network Manager
A vulnerability in the CLI of Cisco Data Center Network Manager (DCNM) could allow an authenticated, local attacker to elevate privileges to root and execute arbitrary commands on the underlying operating system.
local
low complexity
cisco CWE-88
7.8
2020-07-07 CVE-2020-5599 Argument Injection or Modification vulnerability in Mitsubishielectric Coreos 05.65.00.Bd/Y
TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains an improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability, which may allow a remote attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.
network
low complexity
mitsubishielectric CWE-88
critical
9.8
2020-06-22 CVE-2020-14049 Argument Injection or Modification vulnerability in Rakuten Viber
Viber for Windows up to 13.2.0.39 does not properly quote its custom URI handler.
network
low complexity
rakuten CWE-88
7.5
2020-06-18 CVE-2020-14421 Argument Injection or Modification vulnerability in Aapanel
aaPanel through 6.6.6 allows remote authenticated users to execute arbitrary commands via the Script Content box on the Add Cron Job screen.
network
low complexity
aapanel CWE-88
7.2
2020-06-16 CVE-2020-7496 Argument Injection or Modification vulnerability in SE Ecostruxure Operator Terminal Expert 3.1
A CWE-88: Argument Injection or Modification vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause unauthorized write access when opening the project file.
local
low complexity
se CWE-88
7.8
2020-05-21 CVE-2020-7808 Argument Injection or Modification vulnerability in Raonwiz Raon K Upload 2018.0.2.51
In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js) allows an attacker to modify arguments which causes downloading a random DLL and injection on it.
network
low complexity
raonwiz CWE-88
critical
9.8
2020-03-16 CVE-2020-1738 Argument Injection or Modification vulnerability in Redhat products
A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified.
local
high complexity
redhat CWE-88
3.9
2020-03-16 CVE-2020-5546 Argument Injection or Modification vulnerability in Mitsubishielectric Iu1-1M20-D Firmware 1.0.7
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier allows an attacker on the same network segment to stop the network functions or execute malware via a specially crafted packet.
low complexity
mitsubishielectric CWE-88
8.8
2020-03-02 CVE-2020-6799 Argument Injection or Modification vulnerability in Mozilla Firefox
Command line arguments could have been injected during Firefox invocation as a shell handler for certain unsupported file types.
network
low complexity
mozilla CWE-88
8.8