CWE-88

CWE-88 · 4 records · 3 with a public proof-of-concept

Records the NVD classes under CWE-88, highest CVSS first.

  1. CRITICAL 9.8CVE-2026-54337public PoC

    Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.14, an argument Injection in the video upload function allows unauthenticated attacker to write/overwrite system files. Version 1.6.14 fixes the issue.

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 8.8CVE-2026-76862public PoC

    Netcore NR255-V version 1.5.130703 contains an os command argument injection vulnerability in the Nettools tcpdump launch paths, including ntools_start_set_cgi, ntools_tcpdump_start_set_cgi, exe_default, and ntools_proc components. Attackers can inject crafted

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.2CVE-2026-76866public PoC

    Netcore NR255-V firmware version 1.5.130703 builds root-run command lines from unquoted user-supplied DDNS input in DDNSset_cgi.c and related ddns_Proc.c components, enabling os command argument injection. Attackers can exploit the unsanitized parameters to in

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 4.4CVE-2026-71212

    xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line invocation (xidown/core/scanner.py and downloader.py) by appending the user-provided or scanned URL as a bare trailing positional argument, with no '--' end-of-options marker and no scheme val

    AI risk analysis on Exploit-DB.ai →