Skip to main content

CWE archive

CWE-88 CVEs

Programmatic archive

403 CVEs tagged with CWE-8886 Critical, 205 High, 102 Medium, 10 Low, 0 Unrated.

CVE-2025-49008

Published Jun 5, 2025

Atheos is a self-hosted browser-based cloud integrated development environment. Prior to version 6.0.4, improper use of `escapeshellcmd()` in `/components/codegit/traits/execute.p…

CVSS 9.4 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2025-1712

Published May 21, 2025

Argument injection in special agent configuration in Checkmk <2.4.0p1, <2.3.0p32, <2.2.0p42 and 2.1.0 allows authenticated attackers to write arbitrary files

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-31499

Published Apr 15, 2025

Jellyfin is an open source self hosted media server. Versions before 10.10.7 are vulnerable to argument injection in FFmpeg. This can be leveraged to possibly achieve remote code…

CVSS 7.6 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-32931

Published Apr 14, 2025

DevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arbitrary OS commands via a specific php artisan command.

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2024-47516

Published Mar 26, 2025

A vulnerability was found in Pagure. An argument injection in Git during retrieval of the repository history leads to remote code execution on the Pagure instance.

CVSS 9.8 · Critical

CVE-2025-27146

Published Feb 25, 2025

matrix-appservice-irc is a Node.js IRC bridge for Matrix. The matrix-appservice-irc bridge up to version 3.0.3 contains a vulnerability which can lead to arbitrary IRC command exe…

CVSS 2.7 · Low
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-24845

Published Feb 6, 2025

Improper neutralization of argument delimiters in a command ('Argument Injection') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker provides…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-0065

Published Jan 28, 2025

Improper Neutralization of Argument Delimiters in the TeamViewer_service.exe component of TeamViewer Clients prior version 15.62 for Windows allows an attacker with local unprivil…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4

CVE-2022-31749

Published Jan 28, 2025

An argument injection vulnerability in the diagnose and import pac commands in WatchGuard Fireware OS before 12.8.1, 12.1.4, and 12.5.10 allows an authenticated remote attacker wi…

CVSS 6.5 · Medium

CVE-2025-23073

Published Jan 14, 2025

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - GlobalBlocking Extension allows Retrieve Embedded Sensitive Data. Thi…

CVSS 3.5 · Low
evidence mentions
2
Buzz score
21.0

CVE-2025-21613

Published Jan 6, 2025

go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful explo…

CVSS 9.2 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-51532

Published Dec 19, 2024

Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A low privileged attacker with local access could pot…

CVSS 7.1 · High

CVE-2024-11633

Published Dec 10, 2024

Argument injection in Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-1484

Published Nov 15, 2024

A vulnerability in the web UI of Cisco&nbsp;SD-WAN vManage Software could allow an authenticated, remote attacker to inject arbitrary commands on an affected system and cause a de…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 151-175 of 403 CVEsPage 7 of 17