CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.
393 vulnerabilities with CWE-88
CVE-2025-29768
MEDIUM
Vim < 9.1.1198 - Data Loss via Crafted Zip File in zip.vim
CVSS 4.4
CVE-2025-27146
LOW
matrix-appservice-irc <3.0.3 - Command Injection
CVSS 2.7
CVE-2025-24845
MEDIUM
Defense Platform Home Edition <3.9.51.x - Command Injection
CVSS 5.5
CVE-2025-0065
HIGH
TeamViewer <15.62 - Privilege Escalation
CVSS 7.8
CVE-2025-23073
LOW
Wikimedia Foundation Mediawiki - GlobalBlocking Extension - Info Di...
CVSS 3.5
CVE-2025-21613
CRITICAL
go-git < 5.13.0 - Argument Injection via File Transport Protocol
CVSS 9.8
CVE-2024-52011
HIGH
launch-editor < 2.9.0 - OS Command Injection via File Argument
CVSS 8.3
CVE-2024-58275
HIGH
Easywall 0.3.1 - Authenticated Remote Command Execution via Ports-Save Endpoint
CVE-2024-47516
CRITICAL
Pagure Repository History - Git Argument Injection Code Execution
CVSS 9.8
CVE-2024-9131
HIGH
Arista ng_firewall < 17.1.1 - Authenticated Command Injection
CVSS 7.2
CVE-2024-51532
HIGH
Dell PowerStore - Command Injection
CVSS 7.1
CVE-2024-11633
CRITICAL
Ivanti Connect Secure <22.7R2.4 - Command Injection
CVSS 9.1
CVE-2024-39712
CRITICAL
Ivanti Connect Secure < 22.7 and Policy Secure < 22.7 - Authenticated Remote Code Execution via Argument Injection
CVSS 9.1
CVE-2024-39711
CRITICAL
Ivanti Connect Secure < 22.7R2.1, 9.1R18.7 & Policy Secure < 22.7R1.1 - Authenticated RCE via Argument Injection
CVSS 9.1
CVE-2024-39710
CRITICAL
Ivanti Connect Secure < 22.7R2.1 / 9.1R18.7 & Policy Secure < 22.7R1.1 - Authenticated RCE via Argument Injection
CVSS 9.1
CVE-2024-38656
CRITICAL
Ivanti Connect Secure <22.7R2.2,9.1R18.9 - Command Injection
CVSS 9.1
CVE-2024-38655
HIGH
Ivanti Connect/Ivanti Policy <22.7R2.1-9.1R18.9 - Command Injection
CVSS 7.2
CVE-2024-52301
HIGH
Laravel Framework < 6.20.45 - Environment Manipulation via Crafted Query String
CVSS 7.5
CVE-2024-47553
CRITICAL
Siemens SINEC Security Monitor < V4.9.0 - Code Injection
CVSS 9.9
CVE-2024-21533
MEDIUM
ggit - Arbitrary Argument Injection via clone() API
CVSS 6.5
CVE-2024-20444
MEDIUM
Cisco Nexus Dashboard Fabric Controller - Command Injection
CVSS 5.5
CVE-2024-47611
MEDIUM
XZ Utils <5.6.2 - Command Injection
CVE-2024-43402
HIGH
Rust < 1.81.0 - OS Command Injection via Batch File Name Trailing Whitespace or Periods
CVSS 8.1
CVE-2024-7573
MEDIUM
Relevanssi Live Ajax Search <2.4 - Command Injection
CVSS 5.3
CVE-2024-41711
MEDIUM
Mitel 6800-6900w Series - Command Injection
CVSS 6.8
Details
Vulnerabilities
393