← Back
CWE-427

1,189 CVEs • Abstraction: Base

Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

JSON object

Loading...

CVEs (1,189)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Apr 1, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Mite for Perl before 0.013000 generates code with the current working directory ('.') added to the @INC path similar to CVE-2016-1238. If an attacker can place a malicious file in current working directory, it may be l...Show more
Mite for Perl before 0.013000 generates code with the current working directory ('.') added to the @INC path similar to CVE-2016-1238. If an attacker can place a malicious file in current working directory, it may be loaded instead of the intended file, potentially leading to arbitrary code execution. This affects the Mite distribution itself, and other distributions that contain code generated by Mite.Show less
1Microsoft
1Visual Studio Code
Jun 17, 2026
Mar 11, 2025
N/A· v4
7.3 HIGH· v3
N/A· v2
Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally.
1Microsoft
2Visual Studio 2019
Visual Studio 2022
Jun 17, 2026
Mar 11, 2025
N/A· v4
7.3 HIGH· v3
N/A· v2
Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
1Microsoft
3Visual Studio 2017
Visual Studio 2019Visual Studio 2022
Jun 17, 2026
Mar 11, 2025
N/A· v4
7.3 HIGH· v3
N/A· v2
Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
1Wondershare
1Filmora
Jun 17, 2026
Mar 4, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Wondershare filmora 9.2.11 is affected by Trojan Dll hijacking leading to privilege escalation.
1Carrier
1Block Load
Jun 17, 2026
Mar 4, 2025
7.1 HIGH· v4
7.8 HIGH· v3
N/A· v2
An Uncontrolled Search Path Element vulnerability exists which could allow a malicious actor to perform DLL hijacking and execute arbitrary code with escalated privileges.
-
-
Jun 17, 2026
Mar 1, 2025
7.3 HIGH· v4
7.0 HIGH· v3
6.0 MEDIUM· v2
A vulnerability was found in Blizzard Battle.Net up to 2.39.0.15212 on Windows and classified as critical. Affected by this issue is some unknown functionality in the library profapi.dll. The manipulation leads to uncont...Show more
A vulnerability was found in Blizzard Battle.Net up to 2.39.0.15212 on Windows and classified as critical. Affected by this issue is some unknown functionality in the library profapi.dll. The manipulation leads to uncontrolled search path. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. The vendor assigns this issue a low risk level.Show less
1Ibm
1I
Jun 17, 2026
Feb 24, 2025
N/A· v4
8.5 HIGH· v3
N/A· v2
IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user with the capability to compile or restore a program to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to ru...Show more
IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user with the capability to compile or restore a program to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege.Show less
1Trendmicro
1Housecall For Home Networks
Jun 17, 2026
Feb 22, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Trend Micro HouseCall for Home Networks version 5.3.1302 and below contains an uncontrolled search patch element vulnerability that could allow an attacker with low user privileges to create a malicious DLL that could le...Show more
Trend Micro HouseCall for Home Networks version 5.3.1302 and below contains an uncontrolled search patch element vulnerability that could allow an attacker with low user privileges to create a malicious DLL that could lead to escalated privileges.Show less
1Citrix
1Secure Access Client
Jun 17, 2026
Feb 20, 2025
5.9 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac
-
-
Jun 17, 2026
Feb 18, 2025
6.8 MEDIUM· v4
N/A· v3
N/A· v2
Rufus is a utility that helps format and create bootable USB flash drives. A DLL hijacking vulnerability in Rufus 4.6.2208 and earlier versions allows an attacker loading and executing a malicious DLL with escalated priv...Show more
Rufus is a utility that helps format and create bootable USB flash drives. A DLL hijacking vulnerability in Rufus 4.6.2208 and earlier versions allows an attacker loading and executing a malicious DLL with escalated privileges (since the executable has been granted higher privileges during the time of launch) due to the ability to inject a malicious `cfgmgr32.dll` in the same directory as the executable and have it side load automatically. This is fixed in commit `74dfa49`, which will be part of version 4.7. Users are advised to upgrade as soon as version 4.7 becomes available. There are no known workarounds for this vulnerability.Show less
-
-
Jun 17, 2026
Feb 18, 2025
N/A· v4
7.3 HIGH· v3
N/A· v2
Insecure Loading of Dynamic Link Libraries have been discovered in HVAC Energy Saving Program, which could allow local attackers to potentially disclose information or execute arbitray code on affected systems. This issu...Show more
Insecure Loading of Dynamic Link Libraries have been discovered in HVAC Energy Saving Program, which could allow local attackers to potentially disclose information or execute arbitray code on affected systems. This issue affects HVAC Energy Saving Program:.Show less
-
-
Jun 17, 2026
Feb 18, 2025
N/A· v4
7.3 HIGH· v3
N/A· v2
Insecure Loading of Dynamic Link Libraries have been discovered in USB-CONVERTERCABLE DRIVER, which could allow local attackers to potentially disclose information or execute arbitray code on affected systems. This issue...Show more
Insecure Loading of Dynamic Link Libraries have been discovered in USB-CONVERTERCABLE DRIVER, which could allow local attackers to potentially disclose information or execute arbitray code on affected systems. This issue affects USB-CONVERTERCABLE DRIVER:.Show less
-
-
Jun 17, 2026
Feb 12, 2025
5.4 MEDIUM· v4
6.7 MEDIUM· v3
N/A· v2
Uncontrolled search path for the Intel(R) RealSense D400 Series Universal Windows Platform (UWP) Driver for Windows(R) 10 all versions may allow an authenticated user to potentially enable escalation of privilege via loc...Show more
Uncontrolled search path for the Intel(R) RealSense D400 Series Universal Windows Platform (UWP) Driver for Windows(R) 10 all versions may allow an authenticated user to potentially enable escalation of privilege via local access.Show less
-
-
Jun 17, 2026
Feb 12, 2025
5.4 MEDIUM· v4
6.7 MEDIUM· v3
N/A· v2
Uncontrolled search path element in some BIOS and System Firmware Update Package for Intel(R) Server M50FCP family before version R01.02.0002 may allow a privileged user to potentially enable escalation of privilege via...Show more
Uncontrolled search path element in some BIOS and System Firmware Update Package for Intel(R) Server M50FCP family before version R01.02.0002 may allow a privileged user to potentially enable escalation of privilege via local access.Show less
-
-
Jun 17, 2026
Feb 12, 2025
5.4 MEDIUM· v4
6.7 MEDIUM· v3
N/A· v2
Uncontrolled search path for some Intel(R) Quartus(R) Prime Software before version 23.1.1 Patch 1.01std may allow an authenticated user to potentially enable escalation of privilege via local access.
-
-
Jun 17, 2026
Feb 12, 2025
5.4 MEDIUM· v4
6.7 MEDIUM· v3
N/A· v2
Uncontrolled search path for some EPCT software before version 1.42.8.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
-
-
Jun 17, 2026
Feb 12, 2025
5.4 MEDIUM· v4
6.7 MEDIUM· v3
N/A· v2
Uncontrolled search path for the Intel(R) XTU software for Windows before version 7.14.2.14 may allow an authenticated user to potentially enable escalation of privilege via local access.
-
-
Jun 17, 2026
Feb 12, 2025
5.4 MEDIUM· v4
6.7 MEDIUM· v3
N/A· v2
Uncontrolled search path for the FPGA Support Package for the Intel(R) oneAPI DPC++/C++ Compiler software for Windows before version 2024.2 may allow an authenticated user to potentially enable escalation of privilege vi...Show more
Uncontrolled search path for the FPGA Support Package for the Intel(R) oneAPI DPC++/C++ Compiler software for Windows before version 2024.2 may allow an authenticated user to potentially enable escalation of privilege via local access.Show less
1Intel
2Advisor
Oneapi Base Toolkit
Jun 17, 2026
Feb 12, 2025
5.4 MEDIUM· v4
6.7 MEDIUM· v3
N/A· v2
Uncontrolled search path for some Intel(R) Advisor software before version 2024.2 may allow an authenticated user to potentially enable escalation of privilege via local access.