Skip to main content

CWE archive

CWE-88 CVEs

Programmatic archive

388 CVEs tagged with CWE-8882 Critical, 197 High, 99 Medium, 10 Low, 0 Unrated.

CVE-2025-46835

Published Jul 10, 2025

Git GUI allows you to use the Git source control management tools via a GUI. When a user clones an untrusted repository and is tricked into editing a file located in a maliciously…

CVSS 8.5 · High

CVE-2025-48385

Published Jul 8, 2025

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When cloning…

CVSS 8.6 · High

CVE-2025-49520

Published Jun 30, 2025

A flaw was found in Ansible Automation Platform’s EDA component where user-supplied Git URLs are passed unsanitized to the git ls-remote command. This vulnerability allows an auth…

CVSS 8.8 · High

CVE-2025-52480

Published Jun 25, 2025

Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General registry. Prior to version 1.9.5, if the clone URL returned by…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-49008

Published Jun 5, 2025

Atheos is a self-hosted browser-based cloud integrated development environment. Prior to version 6.0.4, improper use of `escapeshellcmd()` in `/components/codegit/traits/execute.p…

CVSS 9.4 · Critical

CVE-2025-1712

Published May 21, 2025

Argument injection in special agent configuration in Checkmk <2.4.0p1, <2.3.0p32, <2.2.0p42 and 2.1.0 allows authenticated attackers to write arbitrary files

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-31499

Published Apr 15, 2025

Jellyfin is an open source self hosted media server. Versions before 10.10.7 are vulnerable to argument injection in FFmpeg. This can be leveraged to possibly achieve remote code…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-32931

Published Apr 14, 2025

DevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arbitrary OS commands via a specific php artisan command.

CVSS 9.1 · Critical

CVE-2024-47516

Published Mar 26, 2025

A vulnerability was found in Pagure. An argument injection in Git during retrieval of the repository history leads to remote code execution on the Pagure instance.

CVSS 9.8 · Critical
Showing 126-150 of 388 CVEsPage 6 of 16