← Back
CWE-426

655 CVEs • Abstraction: Base • Likelihood of Exploit: High

Untrusted Search Path

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

JSON object

Loading...

CVEs (655)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sonicwall
1Global Vpn Client
Jun 17, 2026
Oct 28, 2020
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
SonicWall Global VPN client version 4.10.4.0314 and earlier allows unprivileged windows user to elevate privileges to SYSTEM through loaded process hijacking vulnerability.
1Checkpoint
1Zonealarm
Jun 17, 2026
Oct 27, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to escalate privileges while restoring files in Anti-Ransomware.
1Nvidia
1Geforce Experience
Jun 17, 2026
Oct 23, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in NVIDIA Web Helper NodeJS Web Server in which an uncontrolled search path is used to load a node module, which may lead to code execu...Show more
NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in NVIDIA Web Helper NodeJS Web Server in which an uncontrolled search path is used to load a node module, which may lead to code execution, denial of service, escalation of privileges, and information disclosure.Show less
1Lenovo
1Diagnostics
Jun 17, 2026
Oct 14, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A DLL search path vulnerability was reported in Lenovo Diagnostics prior to version 4.35.4 that could allow a user with local access to execute code on the system.
1Eaton
19000x Programming And Configuration Software
Jun 17, 2026
Sep 30, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
A DLL Hijacking vulnerability in Eaton's 9000x Programming and Configuration Software v 2.0.38 and prior allows an attacker to execute arbitrary code by replacing the required DLLs with malicious DLLs when the software t...Show more
A DLL Hijacking vulnerability in Eaton's 9000x Programming and Configuration Software v 2.0.38 and prior allows an attacker to execute arbitrary code by replacing the required DLLs with malicious DLLs when the software try to load vci11un6.DLL and cinpl.DLL.Show less
1Postgresql
1Postgresql
Jun 17, 2026
Sep 16, 2020
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take prece...Show more
The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights.Show less
2Qt
Redhat
2Enterprise Linux
Qt
Jun 17, 2026
Sep 14, 2020
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.
1Mcafee
1Mcafee Agent
Jun 17, 2026
Sep 10, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
DLL Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to execute arbitrary code via careful placement of a malicious DLL.
1Ibm
1Aspera Connect
Jun 17, 2026
Sep 4, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
IBM Aspera Connect 3.9.9 could allow a remote attacker to execute arbitrary code on the system, caused by improper loading of Dynamic Link Libraries by the import feature. By persuading a victim to open a specially-craft...Show more
IBM Aspera Connect 3.9.9 could allow a remote attacker to execute arbitrary code on the system, caused by improper loading of Dynamic Link Libraries by the import feature. By persuading a victim to open a specially-crafted .DLL file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 183190.Show less
4Canonical
DebianOpensuse+1 more
4Debian Linux
LeapPostgresql+1 more
Jun 17, 2026
Aug 24, 2020
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially cr...Show more
It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially crafted script, during the installation or update of such extension. This affects PostgreSQL versions before 12.4, before 11.9, before 10.14, before 9.6.19, and before 9.5.23.Show less
1Osisoft
9Pi Api
Pi Buffer SubsystemPi Connector+6 more
Jun 17, 2026
Jul 24, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the local computer at Windows system privile...Show more
In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the local computer at Windows system privilege level, resulting in unauthorized information disclosure, deletion, or modification.Show less
1Lenovo
1Drivers Management
Jun 17, 2026
Jul 24, 2020
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
A DLL search path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevated privileges.
1Asus
1Screenpad2 Upgrade Tool
Jun 17, 2026
Jul 20, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
AsusScreenXpertServicec.exe and ScreenXpertUpgradeServiceManager.exe in ScreenPad2_Upgrade_Tool.msi V1.0.3 for ASUS PCs with ScreenPad 1.0 (UX450FDX, UX550GDX and UX550GEX) could lead to unsigned code execution with no a...Show more
AsusScreenXpertServicec.exe and ScreenXpertUpgradeServiceManager.exe in ScreenPad2_Upgrade_Tool.msi V1.0.3 for ASUS PCs with ScreenPad 1.0 (UX450FDX, UX550GDX and UX550GEX) could lead to unsigned code execution with no additional restrictions when a user puts an application at a particular path with a particular file name.Show less
2Netapp
Python
2Max Data
Python
Jun 17, 2026
Jul 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from arbitrary locations. The <executable-name>._pth file (e.g., the python._pth file) is not affected.
1Adobe
1Coldfusion
Jun 17, 2026
Jul 17, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation.
1Adobe
1Coldfusion
Jun 17, 2026
Jul 17, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation.
1Trendmicro
4Antivirus+ 2020
Internet Security 2020Maximum Security 2020+1 more
Jun 17, 2026
Jul 15, 2020
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
An untrusted search path remote code execution (RCE) vulnerability in the Trend Micro Secuity 2020 (v16.0.0.1146 and below) consumer family of products could allow an attacker to run arbitrary code on a vulnerable system...Show more
An untrusted search path remote code execution (RCE) vulnerability in the Trend Micro Secuity 2020 (v16.0.0.1146 and below) consumer family of products could allow an attacker to run arbitrary code on a vulnerable system. As the Trend Micro installer tries to load DLL files from its current directory, an arbitrary DLL could also be loaded with the same privileges as the installer if run as Administrator. User interaction is required to exploit the vulnerbaility in that the target must open a malicious directory or device.Show less
1Microsoft
1365 Apps
Jun 17, 2026
Jul 14, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A remote code execution vulnerability exists when Microsoft Office improperly validates input before loading dynamic link library (DLL) files, aka 'Microsoft Office Remote Code Execution Vulnerability'.
1Linuxfoundation
1Osquery
Jun 17, 2026
Jul 10, 2020
N/A· v4
8.2 HIGH· v3
4.4 MEDIUM· v2
osquery before version 4.4.0 enables a privilege escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user may write a zlib1.dll DLL, which osquery w...Show more
osquery before version 4.4.0 enables a privilege escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user may write a zlib1.dll DLL, which osquery will attempt to load. Since osquery runs with elevated privileges this enables local escalation. This is fixed in version 4.4.0.Show less
1Cymiinstaller322 Activex Project
1Cymiinstaller322 Activex
Jun 17, 2026
Jun 30, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
CyMiInstaller322 ActiveX which runs MIPLATFORM downloads files required to run applications. A vulnerability in downloading files by CyMiInstaller322 ActiveX caused by an attacker to download randomly generated DLL files...Show more
CyMiInstaller322 ActiveX which runs MIPLATFORM downloads files required to run applications. A vulnerability in downloading files by CyMiInstaller322 ActiveX caused by an attacker to download randomly generated DLL files and MIPLATFORM to load those DLLs due to insufficient verification.Show less