CWE-427
1,220 CVEs • Abstraction: Base
Uncontrolled Search Path Element
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
CVEs (1,220)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Bitdefender 4Antivirus Plus Endpoint Security ToolInternet Security+1 moreJun 17, 2026 Jul 30, 2019 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 An issue was discovered in Bitdefender products for Windows (Bitdefender Endpoint Security Tool versions prior to 6.6.8.115; and Bitdefender Antivirus Plus, Bitdefender Internet Security, and Bitdefender Total Security v...Show more |
Akeo Consulting Rufus 3.0 and earlier is affected by: DLL search order hijacking. The impact is: Arbitrary code execution WITH escalation of privilege. The component is: Executable installers, portable executables (ALL e...Show more |
Adobe Dreamweaver direct download installer versions 19.0 and below, 18.0 and below have an Insecure Library Loading (DLL hijacking) vulnerability. Successful exploitation could lead to Privilege Escalation in the contex...Show more |
A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProClima (all versions prior to version 8.0.0) which could allow a malicious DLL file, with the same name of any resident DLLs inside the software insta...Show more |
Rapid7 Insight Agent, version 2.6.3 and prior, suffers from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when Insight Agent 2.6.3 and prior starts, the Python interpreter attempts to...Show more |
1Londontrustmedia 1Private Internet Access Vpn Client Jun 17, 2026 Jul 11, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The root_runner.64 binary is s...Show more |
A vulnerability in the loading mechanism of specific dynamic link libraries in Cisco Jabber for Windows could allow an authenticated, local attacker to perform a DLL preloading attack. To exploit this vulnerability, the...Show more |
3Haxx NetappOracle9Curl Enterprise Manager Ops CenterHttp Server+6 moreJun 17, 2026 Jul 2, 2019 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If tha...Show more |
2Dell Pc Doctor3Supportassist For Business Pcs Supportassist For Home PcsToolboxJun 17, 2026 Jun 25, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 PC-Doctor Toolbox before 7.3 has an Uncontrolled Search Path Element. |
1Londontrustmedia 1Private Internet Access Jun 17, 2026 Jun 21, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client 1.0.2 (build 02363) for Windows could allow an authenticated, local attacker to run arbitrary code with elevated privileges. On startup,...Show more |
1Zohocorp 18Manageengine Analytics Plus Manageengine Browser Security PlusManageengine Desktop Central+15 moreJun 17, 2026 Jun 18, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said product...Show more |
HiSuite 9.1.0.300 versions and earlier contains a DLL hijacking vulnerability. This vulnerability exists due to some DLL file is loaded by HiSuite improperly. And it allows an attacker to load this DLL file of the attack...Show more |
Privilege escalation due to insecure directory permissions affecting ViveportDesktopService in HTC VIVEPORT before 1.0.0.36 allows local attackers to escalate privileges via DLL hijacking. |
Creative Cloud Desktop Application (installer) versions 4.7.0.400 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation. |
A Uncontrolled Search Path Element (CWE-427) vulnerability exists in VideoXpert OpsCenter versions prior to 3.1 which could allow an attacker to cause the system to call an incorrect DLL. |
1F Secure 5Client Security Computer ProtectionInternet Security+2 moreJun 17, 2026 May 17, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In the F-Secure installer in F-Secure SAFE for Windows before 17.6, F-Secure Internet Security before 17.6, F-Secure Anti-Virus before 17.6, F-Secure Client Security Standard and Premium before 14.10, F-Secure PSB Workst...Show more |
VMware Workstation (15.x before 15.1.0) contains a DLL hijacking issue because some DLL files are improperly loaded by the application. Successful exploitation of this issue may allow attackers with normal user privilege...Show more |
1Nvidia 2Geforce Experience Gpu Display DriverJun 17, 2026 May 10, 2019 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in which it incorrectly loads Windows system DLLs without validating the path or signature (also known as a binary planting o...Show more |
GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to place malicious files within the installer file directory, which may allow an attacker to gain administrative privileges on a system dur...Show more |
GE Communicator, all versions prior to 4.0.517, allows an attacker to place malicious files within the working directory of the program, which may allow an attacker to manipulate widgets and UI elements. |