CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

Parent: CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

393 vulnerabilities with CWE-88
CVE-2025-40948 MEDIUM
Siemens Ruggedcom Rox MX5000 - Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
CVSS 6.8
CVE-2025-41761 HIGH
mbs-solutions universal_bacnet_router_firmware < 6.0.1.0 - Privilege Escalation via Sudo Permissions
CVSS 7.8
CVE-2025-70327 CRITICAL
TOTOLINK X5000R v9.1.0cu_2415_B20250515 - Command Injection
CVSS 9.8
CVE-2025-15316 MEDIUM
Tanium Server - Privilege Escalation
CVSS 6.7
CVE-2025-15315 MEDIUM
Tanium Module Server - Privilege Escalation
CVSS 6.7
CVE-2025-24293 HIGH
Rubygems Activestorage < 8.0.2.1 - Command Injection
CVSS 8.1
CVE-2025-61731 HIGH
cmd/go - Code Injection
CVSS 7.8
CVE-2025-67858 HIGH
Foomuuri < 0.31 - Argument Injection via JSON Configuration
CVE-2025-66002 MEDIUM
smb4k < 4.0.5 - Argument Injection via Mount Helper
CVE-2025-14946 MEDIUM
libnbd Crafted URI - SSH Argument Injection Code Execution
CVSS 4.8
CVE-2025-68144 HIGH
mcp-server-git <2025.12.17 - Code Injection
CVSS 7.1
CVE-2025-62847 HIGH
QNAP <5.2.7.3297 - Command Injection
CVSS 7.5
CVE-2025-12613 HIGH
Cloudinary <2.7.0 - Command Injection
CVSS 8.6
CVE-2025-12556 HIGH
IDIS ICM Viewer 1.6.0.10 and 1.7.1 - Argument Injection
CVSS 8.8
CVE-2025-36565 MEDIUM
Dell PowerProtect Data Domain 7.7.1.0-8.1.0.10, 7.13.1.0-7.13.1.25, 7.10.1.0-7.10.1.50 - Authenticated Command Injection
CVSS 6.7
CVE-2025-43905 MEDIUM
Dell Data Domain Operating System < 7.10.1.70 - Denial of Service
CVSS 4.3
CVE-2025-59489 HIGH
Unity Runtime <2025-10-02 - Code Injection
CVSS 7.4
CVE-2025-59937 CRITICAL
go-mail < 0.7.1 - ESMTP Parameter Smuggling via Mail Address Handling
CVSS 9.1
CVE-2025-59433 MEDIUM
Conventional Changelog <2.0.0 - Command Injection
CVSS 5.3
CVE-2025-47421 HIGH
CRESTRON TOUCHSCREENS x70 - Privilege Escalation
CVE-2025-43730 HIGH
Dell ThinOS < 2508 - Unauthenticated Argument Injection
CVSS 8.4
CVE-2025-57791 MEDIUM
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
CVSS 6.5
CVE-2025-6232 HIGH
Lenovo Vantage - Privilege Escalation
CVSS 7.8
CVE-2025-6231 HIGH
Lenovo Vantage - Privilege Escalation
CVSS 7.8
CVE-2025-53509 MEDIUM
Advantech iView - Command Injection
CVSS 6.5
Details
Vulnerabilities 393