CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.
326 vulnerabilities with CWE-88
CVE-2025-32458
HIGH
Onsemi Qcs-ax3-s5 Firmware - Command Injection
CVSS 7.7
CVE-2025-32457
HIGH
Onsemi Qcs-ax3-s5 Firmware - Command Injection
CVSS 7.7
CVE-2025-32456
HIGH
Onsemi Qcs-ax3-s5 Firmware - Command Injection
CVSS 7.7
CVE-2025-32455
HIGH
Onsemi Qcs-ax3-s5 Firmware - Command Injection
CVSS 7.7
CVE-2025-49008
CRITICAL
Atheos <6.0.4 - Command Injection
CVE-2025-3945
HIGH
Tridium Niagara <4.14.2-4.15.1-4.10.11 - Command Injection
CVSS 7.2
CVE-2025-1712
HIGH
Checkmk <2.4.0p1,<2.3.0p32,<2.2.0p42,2.1.0 - Command Injection
CVSS 8.8
CVE-2025-31499
HIGH
Jellyfin < 10.10.7 - Remote Code Execution
CVSS 8.8
CVE-2025-32931
CRITICAL
DevDojo Voyager <1.8.0 - Command Injection
CVSS 9.1
CVE-2025-29768
MEDIUM
Vim <9.1.1198 - Info Disclosure
CVSS 4.4
CVE-2025-27146
LOW
matrix-appservice-irc <3.0.3 - Command Injection
CVSS 2.7
CVE-2025-24845
MEDIUM
Defense Platform Home Edition <3.9.51.x - Command Injection
CVSS 5.5
CVE-2025-0065
HIGH
TeamViewer <15.62 - Privilege Escalation
CVSS 7.8
CVE-2025-23073
LOW
Wikimedia Foundation Mediawiki - GlobalBlocking Extension - Info Di...
CVSS 3.5
CVE-2025-21613
CRITICAL
go-git <5.13 - Command Injection
CVSS 9.8
CVE-2024-58275
HIGH
Easywall 0.3.1 - Command Injection
CVE-2024-47516
CRITICAL
Pagure - RCE
CVSS 9.8
CVE-2024-9131
HIGH
Arista NG Firewall < 17.1.1 - Command Injection
CVSS 7.2
CVE-2024-51532
HIGH
Dell PowerStore - Command Injection
CVSS 7.1
CVE-2024-11633
CRITICAL
Ivanti Connect Secure <22.7R2.4 - Command Injection
CVSS 9.1
CVE-2024-39712
CRITICAL
Ivanti Connect Secure < 22.7 - Remote Code Execution
CVSS 9.1
CVE-2024-39711
CRITICAL
Ivanti Connect Secure < 22.7 - Remote Code Execution
CVSS 9.1
CVE-2024-39710
CRITICAL
Ivanti Connect Secure < 22.7 - Remote Code Execution
CVSS 9.1
CVE-2024-38656
CRITICAL
Ivanti Connect Secure <22.7R2.2,9.1R18.9 - Command Injection
CVSS 9.1
CVE-2024-38655
HIGH
Ivanti Connect/Ivanti Policy <22.7R2.1-9.1R18.9 - Command Injection
CVSS 7.2
Details
Vulnerabilities
326