CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.
359 vulnerabilities with CWE-88
CVE-2025-35010
HIGH
Microhard BulletLTE-NA2 and IPn4Gii-NA2 - Authenticated Command Injection via AT+MNPINGTM
CVSS 7.1
CVE-2025-35009
HIGH
Microhard BulletLTE-NA2 and IPn4Gii-NA2 Firmware - Authenticated Command Injection via AT+MNNETSP
CVSS 7.1
CVE-2025-35008
HIGH
Microhard BulletLTE-NA2 and IPn4Gii-NA2 Firmware < 1.2.0-r1132 - Authenticated Command Injection via AT+MMNAME
CVSS 7.1
CVE-2025-35007
HIGH
Microhard BulletLTE-NA2 and IPn4Gii-NA2 Firmware - Authenticated Command Injection via AT+MFRULE
CVSS 7.1
CVE-2025-35006
HIGH
Microhard BulletLTE-NA2 and IPn4Gii-NA2 Firmware - Authenticated Command Injection via AT+MFPORTFWD
CVSS 7.1
CVE-2025-35005
HIGH
Microhard BulletLTE-NA2 and IPn4Gii-NA2 Firmware - Authenticated Command Injection via AT+MFMAC
CVSS 7.1
CVE-2025-35004
HIGH
Microhard BulletLTE-NA2 and IPn4Gii-NA2 Firmware < 1.2.0-r1132 - Authenticated Command Injection via AT+MFIP
CVSS 7.1
CVE-2025-32459
HIGH
onsemi Quantenna Wi-Fi Firmware - OS Command Injection via router_command.sh sync_time Argument
CVSS 7.7
CVE-2025-32458
HIGH
onsemi Quantenna Wi-Fi Firmware - OS Command Injection via router_command.sh get_syslog_from_qtn Argument
CVSS 7.7
CVE-2025-32457
HIGH
onsemi Quantenna Wi-Fi Firmware - OS Command Injection via router_command.sh get_file_from_qtn Argument
CVSS 7.7
CVE-2025-32456
HIGH
onsemi Quantenna Wi-Fi Firmware - OS Command Injection via router_command.sh put_file_to_qtn Argument
CVSS 7.7
CVE-2025-32455
HIGH
onsemi Quantenna Wi-Fi Firmware - OS Command Injection via router_command.sh run_cmd Argument
CVSS 7.7
CVE-2025-49008
CRITICAL
Atheos < 6.0.4 - OS Command Injection via Execute.php Argument Injection
CVE-2025-3945
HIGH
Tridium Niagara <4.14.2-4.15.1-4.10.11 - Command Injection
CVSS 7.2
CVE-2025-1712
HIGH
Checkmk <2.4.0p1,<2.3.0p32,<2.2.0p42,2.1.0 - Command Injection
CVSS 8.8
CVE-2025-31499
HIGH
jellyfin < 10.10.7 - Authenticated Argument Injection in FFmpeg via Stream Endpoints
CVSS 8.8
CVE-2025-32931
CRITICAL
DevDojo Voyager <1.8.0 - Command Injection
CVSS 9.1
CVE-2025-29768
MEDIUM
Vim < 9.1.1198 - Data Loss via Crafted Zip File in zip.vim
CVSS 4.4
CVE-2025-27146
LOW
matrix-appservice-irc <3.0.3 - Command Injection
CVSS 2.7
CVE-2025-24845
MEDIUM
Defense Platform Home Edition <3.9.51.x - Command Injection
CVSS 5.5
CVE-2025-0065
HIGH
TeamViewer <15.62 - Privilege Escalation
CVSS 7.8
CVE-2025-23073
LOW
Wikimedia Foundation Mediawiki - GlobalBlocking Extension - Info Di...
CVSS 3.5
CVE-2025-21613
CRITICAL
go-git < 5.13.0 - Argument Injection via File Transport Protocol
CVSS 9.8
CVE-2024-58275
HIGH
Easywall 0.3.1 - Authenticated Remote Command Execution via Ports-Save Endpoint
CVE-2024-47516
CRITICAL
Pagure Repository History - Git Argument Injection Code Execution
CVSS 9.8
Details
Vulnerabilities
359