CWE-88

Total CVEs
204
Vulnerabilities
Avg CVSS v3
8.2
High
Avg CVSS v2
6.8
Medium
Latest CVE
2025
Most Recent

Severity Distribution

Critical 64
31.4%
High 96
47.1%
Medium 41
20.1%
Low 3
1.5%

External References

All CVEs (204)

Page 1 of 9
CVSS:9.9(Critical)

A vulnerability has been identified in Siemens SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate user input to the ```ssmctl-client``` command. This c...

CWE-882024
CVSS:9.9(Critical)

The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated attackers can exploit this by opening an SSH connection...

CWE-882024
CVSS:9.9(Critical)

An exploitable vulnerability exists in the smart cameras RTSP configuration of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The device incorrectly handles spaces in the URL fiel...

CWE-882018
CVSS:9.8(Critical)

go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulne...

CWE-882025
CVSS:9.8(Critical)

A vulnerability was found in Pagure. An argument injection in Git during retrieval of the repository history leads to remote code execution on the Pagure instance.

CWE-882024
CVSS:9.8(Critical)

HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affect the go-getter/v2 branch and package.

CWE-882024
CVSS:9.8(Critical)

The OpenAPI loader in Embedchain before 0.1.57 allows attackers to execute arbitrary code, related to the openapi.py yaml.load function argument.

CWE-882024
CVSS:9.8(Critical)

An argument injection vulnerability has been identified in the administrative web interface of the Atos Unify OpenScape products "Session Border Controller" (SBC) and "Branch", before version V10 R3.4...

CWE-882023
CVSS:9.8(Critical)

Connected IO v2.1.0 and prior has an argument injection vulnerability in its AT command message in its communication protocol, enabling attackers to execute arbitrary OS commands on devices.

CWE-882023
CVSS:9.8(Critical)

Connected IO v2.1.0 and prior has an argument injection vulnerability in its iptables command message in its communication protocol, enabling attackers to execute arbitrary OS commands on devices.

CWE-882023
CVSS:9.8(Critical)

There is a command injection problem in the old version of the mobile phone backup app.

CWE-882023
CVSS:9.8(Critical)

AyaCMS 3.1.2 is vulnerable to file deletion via /aya/module/admin/fst_del.inc.php

CWE-882022
CVSS:9.8(Critical)

In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.

CWE-882022
CVSS:9.8(Critical)

Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.

CWE-882022
CVSS:9.8(Critical)

In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client application that does not validate arguments). NOTE: the vendor believes it would be unr...

CWE-882022
CVSS:9.8(Critical)

All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the --upload-pack feature of git.

CWE-882022
CVSS:9.8(Critical)

The package czproject/git-php before 4.0.3 are vulnerable to Command Injection via git argument injection. When calling the isRemoteUrlReadable($url, array $refs = NULL) function, both the url and ref...

CWE-882022
CVSS:9.8(Critical)

The package workspace-tools before 0.18.4 are vulnerable to Command Injection via git argument injection. When calling the fetchRemoteBranch(remote: string, remoteBranch: string, cwd: string) function...

CWE-882022
CVSS:9.8(Critical)

The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) function, the remote parameter is passed to the git f...

CWE-882022
CVSS:9.8(Critical)

The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function ...

CWE-882022
CVSS:9.8(Critical)

The package git-pull-or-clone before 2.0.2 are vulnerable to Command Injection due to the use of the --upload-pack feature of git which is also supported for git clone. The source includes the use of ...

CWE-882022
CVSS:9.8(Critical)

The package simple-git before 3.3.0 are vulnerable to Command Injection via argument injection. When calling the .fetch(remote, branch, handlerFn) function, both the remote and branch parameters are p...

CWE-882022
CVSS:9.8(Critical)

All versions of package git-promise are vulnerable to Command Injection due to an inappropriate fix of a prior [vulnerability](https://security.snyk.io/vuln/SNYK-JS-GITPROMISE-567476) in this package....

CWE-882022
CVSS:9.8(Critical)

The package simple-git before 3.5.0 are vulnerable to Command Injection due to an incomplete fix of [CVE-2022-24433](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-2421199) which only patches against...

CWE-882022