Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Cacti: Command Injection via escape_command() no-op in RRDtool execution
Jellyfin: Potential FFmpeg argument injection via unescaped subtitle file path
Warp: DCS lifecycle hook spoofing can alter terminal session metadata
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') in TortoiseGit
n8n: Arbitrary File Read via Git Node
Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()
Argument injection vulnerability in WordPress Toolkit before 6
mcp-server-kubernetes: kubectl-generic flag injection enables Kubernetes bearer token exfiltration
PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen
Potential local privileges escalation through argument injection in the nxchmod.sh script
Ghidra < 12.1- Command Injection via URL Annotation Click
Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution
Tenant-controlled comma smuggles arbitrary CIFS mount options
In JetBrains TeamCity before 2026
AnythingLLM: RCE via ripgrep --pre argument injection in filesystem-search-files agent skill
pam_usb: Shell injection via device UUID and username in pamusb-conf and pamusb-agent
Lumiverse: SMB `exists()` basename injection via smbclient `!cmd` escape
Lumiverse: RCE via MCP stdio argument injection
Argument Injection in prefecthq/prefect
IINA < 1.4.3 Command Execution via iina://open URL Scheme
Showing 1 - 20 of 1,000+ results