Vulnerabilities > Argument Injection or Modification

DATE CVE VULNERABILITY TITLE RISK
2021-04-19 CVE-2020-7851 Argument Injection or Modification vulnerability in Innorix File Transfer Solution
Innorix Web-Based File Transfer Solution versuibs prior to and including 9.2.18.385 contains a vulnerability that could allow remote files to be downloaded and executed by setting the arguments to the internal method.
local
low complexity
innorix CWE-88
7.8
2021-03-29 CVE-2020-7850 Argument Injection or Modification vulnerability in Douzone Nbbdownloader.Ocx 1.0.0.12
NBBDownloader.ocx ActiveX Control in Groupware contains a vulnerability that could allow remote files to be downloaded and executed by setting the arguments to the activex method.
local
low complexity
douzone CWE-88
7.8
2021-03-24 CVE-2021-1454 Argument Injection or Modification vulnerability in Cisco IOS XE and IOS XE Sd-Wan
Multiple vulnerabilities in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to access the underlying operating system with root privileges.
local
low complexity
cisco CWE-88
6.7
2021-03-24 CVE-2021-1383 Argument Injection or Modification vulnerability in Cisco IOS XE
Multiple vulnerabilities in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to access the underlying operating system with root privileges.
local
low complexity
cisco CWE-88
6.7
2021-03-10 CVE-2021-24030 Argument Injection or Modification vulnerability in Facebook Gameroom
The fbgames protocol handler registered as part of Facebook Gameroom does not properly quote arguments passed to the executable.
network
low complexity
facebook CWE-88
critical
9.8
2021-02-22 CVE-2020-21224 Argument Injection or Modification vulnerability in Inspur Clusterengine 4.0
A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0.
network
low complexity
inspur CWE-88
critical
9.8
2021-02-09 CVE-2021-26937 Argument Injection or Modification vulnerability in multiple products
encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence.
network
low complexity
gnu debian fedoraproject CWE-88
critical
9.8
2021-02-04 CVE-2021-3401 Argument Injection or Modification vulnerability in Bitcoin
Bitcoin Core before 0.19.0 might allow remote attackers to execute arbitrary code when another application unsafely passes the -platformpluginpath argument to the bitcoin-qt program, as demonstrated by an x-scheme-handler/bitcoin handler for a .desktop file or a web browser.
network
low complexity
bitcoin CWE-88
critical
9.8
2020-12-23 CVE-2020-35136 Argument Injection or Modification vulnerability in Dolibarr Erp/Crm 12.0.3
Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution.
network
low complexity
dolibarr CWE-88
7.2
2020-11-12 CVE-2020-7769 Argument Injection or Modification vulnerability in Nodemailer
This affects the package nodemailer before 6.4.16.
network
low complexity
nodemailer CWE-88
critical
9.8