Vulnerabilities > Argument Injection or Modification

DATE CVE VULNERABILITY TITLE RISK
2022-06-17 CVE-2022-31246 Argument Injection or Modification vulnerability in Electrum
paymentrequest.py in Electrum before 4.2.2 allows a file:// URL in the r parameter of a payment request (e.g., within QR code data).
local
low complexity
electrum CWE-88
5.5
2022-06-10 CVE-2022-24376 Argument Injection or Modification vulnerability in Git-Promise Project Git-Promise
All versions of package git-promise are vulnerable to Command Injection due to an inappropriate fix of a prior [vulnerability](https://security.snyk.io/vuln/SNYK-JS-GITPROMISE-567476) in this package.
network
low complexity
git-promise-project CWE-88
critical
9.8
2022-06-02 CVE-2021-33473 Argument Injection or Modification vulnerability in Dragonfly Project Dragonfly 1.3.0
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled.
network
low complexity
dragonfly-project CWE-88
critical
9.1
2022-05-21 CVE-2022-29215 Argument Injection or Modification vulnerability in Regionprotect Project Regionprotect
RegionProtect is a plugin that allows users to manage certain events in certain regions of the world.
network
low complexity
regionprotect-project CWE-88
7.5
2022-05-13 CVE-2022-25865 Argument Injection or Modification vulnerability in Microsoft Workspace-Tools
The package workspace-tools before 0.18.4 are vulnerable to Command Injection via git argument injection.
network
low complexity
microsoft CWE-88
critical
9.8
2022-05-09 CVE-2022-29971 Argument Injection or Modification vulnerability in Insightsoftware Magnitude Simba Amazon Athena Odbc Driver
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Athena ODBC Driver 1.1.1 through 1.1.x before 1.1.17 may allow a local user to execute arbitrary code.
local
low complexity
insightsoftware CWE-88
7.8
2022-05-09 CVE-2022-29972 Argument Injection or Modification vulnerability in Insightsoftware Magnitude Simba Amazon Redshift Odbc Driver
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift ODBC Driver (1.4.14 through 1.4.21.1001 and 1.4.22 through 1.4.x before 1.4.52) may allow a local user to execute arbitrary code.
local
low complexity
insightsoftware CWE-88
7.8
2022-05-09 CVE-2022-30239 Argument Injection or Modification vulnerability in Insightsoftware Magnitude Simba Amazon Athena Jdbc Driver
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Athena JDBC Driver 2.0.25 through 2.0.28 may allow a local user to execute code.
local
low complexity
insightsoftware CWE-88
7.8
2022-05-09 CVE-2022-30240 Argument Injection or Modification vulnerability in Insightsoftware Magnitude Simba Amazon Redshift Jdbc Driver
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift JDBC Driver 1.2.40 through 1.2.55 may allow a local user to execute code.
local
low complexity
insightsoftware CWE-88
7.8
2022-05-04 CVE-2022-30284 Argument Injection or Modification vulnerability in Python-Libnmap Project Python-Libnmap
In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client application that does not validate arguments).
network
low complexity
python-libnmap-project CWE-88
critical
9.8