CWE-88: CWE-88

84
Total CVEs
25
Critical
40
High
8.0
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
12
2025
29
2024
15
2023
8
2022
14

Top Affected Vendors

1 Ivanti 5
2 Microhardcorp 4
3 Debian 4
4 Onsemi 3
5 Insightsoftware 2
6 Jellyfin 2
7 Salesforce 2
8 Dell 2
9 Weblate 2
10 Connectedio 2

All CWE-88 CVEs (84)

CVE-2026-26514
7.5

An argument injection vulnerability in bird-lg-go's traceroute module allows remote attackers to inject arbitrary command-line flags via the q paramet...

Mar 4, 2026
CVE-2025-62847
7.5

This CVE describes an argument injection vulnerability in QNAP operating systems where attackers can manipulate command arguments to alter execution l...

Dec 16, 2025
CVE-2022-29215
7.5

CVE-2022-29215 is a YAML injection vulnerability in the RegionProtect Minecraft plugin that allows malicious inputs to cause instant server crashes. T...

May 21, 2022
CVE-2025-59489
7.4

This vulnerability allows argument injection in Unity Runtime, enabling attackers to load malicious library code from unintended locations. Applicatio...

Oct 3, 2025
CVE-2024-9131
7.2

This CVE allows administrators to execute arbitrary commands through command injection in Arista products. Attackers with admin privileges can exploit...

Jan 10, 2025
CVE-2024-38655
7.2

This vulnerability allows remote authenticated attackers with admin privileges to execute arbitrary code on Ivanti Connect Secure and Policy Secure ga...

Nov 13, 2024
CVE-2024-41710
7.2

This vulnerability allows authenticated attackers with administrative privileges on Mitel SIP phones to execute arbitrary system commands through argu...

Aug 12, 2024
CVE-2023-0633
7.2

This vulnerability in Docker Desktop for Windows allows local attackers to escalate privileges through argument injection in the installer. Attackers ...

Sep 25, 2023
CVE-2022-40677
7.2

This vulnerability allows attackers to execute arbitrary commands on Fortinet FortiNAC systems by injecting malicious arguments through input paramete...

Feb 16, 2023
CVE-2022-23915
7.2

CVE-2022-23915 is a remote code execution vulnerability in Weblate, a web-based translation management system. Authenticated users can inject argument...

Mar 4, 2022
CVE-2021-34816
7.2

CVE-2021-34816 is an argument injection vulnerability in Etherpad's plugin management system that allows privileged users to execute arbitrary code on...

Jul 21, 2021
CVE-2025-35006
7.1

This vulnerability allows authenticated attackers to execute arbitrary commands on Microhard BulletLTE-NA2 and IPn4Gii-NA2 devices via command injecti...

Jun 8, 2025
CVE-2025-35008
7.1

This vulnerability allows authenticated attackers to execute arbitrary commands on Microhard BulletLTE-NA2 and IPn4Gii-NA2 devices via the AT+MMNAME c...

Jun 8, 2025
CVE-2025-35010
7.1

This vulnerability allows authenticated attackers to execute arbitrary commands on Microhard BulletLTE-NA2 and IPn4Gii-NA2 devices through improper in...

Jun 8, 2025
CVE-2025-35004
7.1

This vulnerability allows authenticated attackers to execute arbitrary commands on Microhard BulletLTE-NA2 and IPn4Gii-NA2 devices through improper in...

Jun 8, 2025
CVE-2024-41711
6.8

An argument injection vulnerability in Mitel SIP phones allows unauthenticated attackers with physical access to execute arbitrary system commands. Th...

Aug 13, 2024
CVE-2025-15315
6.7

CVE-2025-15315 is a local privilege escalation vulnerability in Tanium Module Server that allows authenticated local users to gain elevated privileges...

Feb 9, 2026
CVE-2025-15316
6.7

CVE-2025-15316 is a local privilege escalation vulnerability in Tanium Server that allows authenticated users with limited privileges to elevate their...

Feb 9, 2026
CVE-2026-24126
6.6

Weblate versions before 5.16.0 have an argument injection vulnerability in the SSH management console when adding SSH host keys. This allows attackers...

Feb 19, 2026
CVE-2025-52459
6.5

An argument injection vulnerability in Advantech iView's NetworkServlet.backupDatabase() function allows authenticated users to inject arbitrary argum...

Jul 11, 2025
CVE-2022-31749
6.5

CVE-2022-31749 is an argument injection vulnerability in WatchGuard Fireware OS that allows authenticated remote attackers with unprivileged credentia...

Jan 28, 2025
CVE-2021-1484
6.5

This vulnerability in Cisco SD-WAN vManage Software allows authenticated remote attackers to inject arbitrary commands through the web UI's device tem...

Nov 15, 2024
CVE-2026-24739
6.3

This vulnerability in Symfony's Process component on Windows allows argument corruption when spawning native executables from MSYS2-based shells like ...

Jan 28, 2026
CVE-2024-31966
6.2

This vulnerability allows authenticated attackers with administrative privileges on affected Mitel SIP phones to conduct argument injection attacks du...

May 2, 2024
CVE-2024-20444
5.5

This vulnerability allows authenticated remote attackers with network-admin privileges to execute arbitrary commands on Cisco Nexus Dashboard Fabric C...

Oct 2, 2024
CVE-2025-59433
5.3

CVE-2025-59433 is an argument injection vulnerability in @conventional-changelog/git-client's getTags() API that allows attackers to pass malicious pa...

Sep 22, 2025
CVE-2024-7573
5.3

The Relevanssi Live Ajax Search WordPress plugin has an argument injection vulnerability that allows unauthenticated attackers to manipulate search qu...

Aug 28, 2024
CVE-2025-14946
4.8

A vulnerability in libnbd allows arbitrary code execution when processing malicious URIs. Attackers can exploit this by tricking libnbd into opening s...

Dec 19, 2025
CVE-2025-29768
4.4

Vim versions before 9.1.1198 contain a vulnerability in zip.vim that could cause data loss when users view specially crafted zip files and press 'x' o...

Mar 13, 2025
CVE-2025-43905
4.3

This vulnerability allows low-privileged remote attackers to inject malicious arguments into commands on Dell PowerProtect Data Domain systems, potent...

Oct 7, 2025
CVE-2025-67858
N/A

This vulnerability allows attackers to manipulate JSON configuration data passed to nftables (nft) through Foomuuri, potentially leading to firewall r...

Jan 8, 2026
CVE-2025-66002
N/A

This CVE describes an argument injection vulnerability in smb4k's mount helper that allows local users to perform arbitrary unmounts. Attackers can ma...

Jan 8, 2026
CVE-2025-68144
N/A

This vulnerability in mcp-server-git allows attackers to pass malicious arguments that get interpreted as command-line flags to git commands, enabling...

Dec 17, 2025
CVE-2024-58275
N/A

Easywall 0.3.1 contains an authenticated remote command execution vulnerability in the /ports-save endpoint. Attackers with valid credentials can inje...

Dec 4, 2025

About CWE-88 (CWE-88)

Our database tracks 84 CVEs classified as CWE-88, with 25 rated critical and 40 rated high severity. The average CVSS score for CWE-88 vulnerabilities is 8.0.

External reference: View CWE-88 on MITRE CWE →

Monitor CWE-88 Vulnerabilities

Get alerted when new CWE-88 CVEs affect your infrastructure.

Start Monitoring Free