← Back
CWE-426

655 CVEs • Abstraction: Base • Likelihood of Exploit: High

Untrusted Search Path

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

JSON object

Loading...

CVEs (655)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
7Windows 10 1809
Windows 10 21h2Windows 10 22h2+4 more
Jun 17, 2026
Jul 11, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Geolocation Service Remote Code Execution Vulnerability
1Zoom
1Rooms
Jun 17, 2026
Jul 11, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Insecure temporary file in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.
1Trendmicro
1Apex One
Jun 17, 2026
Jun 26, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An untrusted search path vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate their privileges on affected installations. Please note: an attacker...Show more
An untrusted search path vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate their privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This is a similar, but not identical vulnerability as CVE-2023-34144.Show less
1Trendmicro
1Apex One
Jun 17, 2026
Jun 26, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An untrusted search path vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate their privileges on affected installations. Please note: an attacker...Show more
An untrusted search path vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate their privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This is a similar, but not identical vulnerability as CVE-2023-34145.Show less
1Softexpert
1Excellence Suite
Jun 17, 2026
May 12, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42300/generic/gn_defaultframe/2.0/defaultframe_filter.php.
1Kodcloud
1Kodbox
Jun 17, 2026
May 12, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
kodbox 1.2.x through 1.3.7 has a Sensitive Information Leakage issue.
1Qualys
1Cloud Agent
Jun 17, 2026
Apr 18, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
Qualys Cloud Agent for macOS (versions 2.5.1-75 before 3.7) installer allows a local escalation of privilege bounded only to the time of installation and only on older macOSX (macOS 10.15 and older) versions. Attackers...Show more
Qualys Cloud Agent for macOS (versions 2.5.1-75 before 3.7) installer allows a local escalation of privilege bounded only to the time of installation and only on older macOSX (macOS 10.15 and older) versions. Attackers may exploit incorrect file permissions to give them ROOT command execution privileges on the host. During the install of the PKG, a step in the process involves extracting the package and copying files to several directories. Attackers may gain writable access to files during the install of PKG when extraction of the package and copying files to several directories, enabling a local escalation of privilege. Show less
1Wondershare
1Creative Centerr
Jun 17, 2026
Apr 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue found in Wondershare Technology Co.,Ltd Creative Centerr v.1.0.8 allows a remote attacker to execute arbitrary commands via the wondershareCC_setup_full10819.exe file.
1Wondershare
1Edraw Max
Jun 17, 2026
Apr 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue found in Wondershare Technology Co.,Ltd Edraw-max v.12.0.4 allows a remote attacker to execute arbitrary commands via the edraw-max_setup_full5371.exe file.
1Wondershare
1Pdf Reader
Jun 17, 2026
Apr 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue found in Wondershare Technology Co.,Ltd PDF Reader v.1.0.1 allows a remote attacker to execute arbitrary commands via the pdfreader_setup_full13143.exe file.
1Wondershare
1Pdfelement
Jun 17, 2026
Apr 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue found in Wondershare Technology Co.,Ltd PDFelement v9.1.1 allows a remote attacker to execute arbitrary commands via the pdfelement-pro_setup_full5239.exe file.
1Wondershare
1Dr.fone
Jun 17, 2026
Apr 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue found in Wondershare Technology Co.,Ltd Dr.Fone v.12.4.9 allows a remote attacker to execute arbitrary commands via the drfone_setup_full3360.exe file.
1Wondershare
1Anireel
Jun 17, 2026
Apr 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue found in Wondershare Technology Co.,Ltd Anireel 1.5.4 allows a remote attacker to execute arbitrary commands via the anireel_setup_full9589.exe file.
1Wondershare
1Recoverit
Jun 17, 2026
Apr 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue found in Wondershare Technology Co.,Ltd Recoverit v.10.6.3 allows a remote attacker to execute arbitrary commands via the recoverit_setup_full4134.exe file.
1Wondershare
1Repairit
Jun 17, 2026
Apr 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue found in Wondershare Technology Co.,Ltd Repairit v.3.5.4 allows a remote attacker to execute arbitrary commands via the repairit_setup_full5913.exe file.
1Wondershare
1Mobiletrans
Jun 17, 2026
Apr 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue found in Wondershare Technology Co.,Ltd MobileTrans v.4.0.2 allows a remote attacker to execute arbitrary commands via the mobiletrans_setup_full5793.exe file.
1Wondershare
1Democreator
Jun 17, 2026
Apr 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue found in Wondershare Technology Co., Ltd DemoCreator v.6.0.0 allows a remote attacker to execute arbitrary commands via the democreator_setup_full7743.exe file.
1Wondershare
1Uniconverter
Jun 17, 2026
Apr 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue found in Wondershare Technology Co., Ltd UniConverter v.14.0.0 allows a remote attacker to execute arbitrary commands via the uniconverter14_64bit_setup_full14204.exe file.
1Wondershare
1Filmora
Jun 17, 2026
Apr 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue found in Wondershare Technology Co, Ltd Filmora v.12.0.9 allows a remote attacker to execute arbitrary commands via the filmora_setup_full846.exe.
1Wondershare
1Edrawmind
Jun 17, 2026
Apr 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue found in Wondershare Technology Co, Ltd Edrawmind v.10.0.6 allows a remote attacker to executea arbitrary commands via the WindowsCodescs.dll file.