Skip to main content

CWE archive

CWE-88 CVEs

Programmatic archive

391 CVEs tagged with CWE-8882 Critical, 199 High, 100 Medium, 10 Low, 0 Unrated.

CVE-2026-43698

Published Jul 27, 2026

An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root priv…

CVSS 7.8 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-16796

Published Jul 23, 2026

Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK before 1.18.1 might allow a remote authenticated user to execut…

CVSS 8.4 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-44210

Published Jul 23, 2026

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Versions prior to 3.31.0 ship w…

CVSS 5.8 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-44189

Published Jul 22, 2026

A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injection vulnerability allows an attacker to craft a malicious…

CVSS 7.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-16493

Published Jul 21, 2026

A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manager.py constructs git clone commands without a '--' (end-of-o…

CVSS 7.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-15793

Published Jul 21, 2026

BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-64624

Published Jul 20, 2026

FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can…

CVSS 8.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-44968

Published Jul 16, 2026

dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, _run_dbt_command() in src/dbt_mcp/dbt_cli/tools.py appended unsanitized node_selection and re…

CVSS 6.3 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-52891

Published Jul 15, 2026

Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filenames into paths later passed to child_process.exec() for…

CVSS 9.9 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-49987

Published Jul 15, 2026

Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, src/core/git/gitCommand.ts execGitShallowClone passes the --remote-branch value directly to git…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-50147

Published Jul 15, 2026

Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57.19.1, 1.58.14.1, 1.59.10, and 1.60.4, an attacker who can configure a Metabase…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-45068

Published Jul 14, 2026

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, SendmailTransport in -t mode appende…

CVSS 8.7 · High
evidence mentions
6
Buzz score
24.5
Vendor/product tagsBeta · best-effort

CVE-2026-61459

Published Jul 10, 2026

MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass…

CVSS 9.3 · Critical
evidence mentions
5
Buzz score
28.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-47829

Published Jul 9, 2026

Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-57572

Published Jul 6, 2026

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed into Chrom…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-40047

Published Jul 6, 2026

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component. The camel-docling component invokes the extern…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
25.6
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-14459

Published Jul 3, 2026

Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows…

CVSS 8.8 · High
evidence mentions
1
Buzz score
15.9
Public PoC observed

CVE-2026-12856

Published Jun 29, 2026

A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extension incorrectly trusts all Markdown content in JavaDoc hovers…

CVSS 8.8 · High
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2026-54088

Published Jun 25, 2026

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, the Hook Authentication f…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-50014

Published Jun 25, 2026

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm passes the lockfile-controlled git resolution.commit value to git fetch without a -- separator or commit-format valida…

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-40079

Published Jun 25, 2026

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command Injection due to lack of sanitization in the escape_command…

CVSS 8.6 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-48793

Published Jun 24, 2026

Jellyfin is an open source self hosted media server. Prior to 10.11.10, a potential FFmpeg argument injection vulnerability exists in the subtitle conversion code path. SubtitleEn…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-54686

Published Jun 24, 2026

Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp accepted certain state-mutating terminal lifecycle hooks fro…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-11968

Published Jun 24, 2026

Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary File Write in TortoiseGit

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-44790

Published Jun 23, 2026

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could inject CLI fla…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 391 CVEsPage 1 of 16