CWE-427
1,189 CVEs • Abstraction: Base
Uncontrolled Search Path Element
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
CVEs (1,189)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Mite for Perl before 0.013000 generates code with the current working directory ('.') added to the @INC path similar to CVE-2016-1238. If an attacker can place a malicious file in current working directory, it may be l...Show more |
Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally. |
1Microsoft 2Visual Studio 2019 Visual Studio 2022Jun 17, 2026 Mar 11, 2025 N/A· v4 7.3 HIGH· v3 N/A· v2 Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. |
1Microsoft 3Visual Studio 2017 Visual Studio 2019Visual Studio 2022Jun 17, 2026 Mar 11, 2025 N/A· v4 7.3 HIGH· v3 N/A· v2 Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. |
Wondershare filmora 9.2.11 is affected by Trojan Dll hijacking leading to privilege escalation. |
An Uncontrolled Search Path Element vulnerability exists which could allow a malicious actor to perform DLL hijacking and execute arbitrary code with escalated privileges. |
A vulnerability was found in Blizzard Battle.Net up to 2.39.0.15212 on Windows and classified as critical. Affected by this issue is some unknown functionality in the library profapi.dll. The manipulation leads to uncont...Show more |
IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user with the capability to compile or restore a program to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to ru...Show more |
1Trendmicro 1Housecall For Home Networks Jun 17, 2026 Feb 22, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Trend Micro HouseCall for Home Networks version 5.3.1302 and below contains an uncontrolled search patch element vulnerability that could allow an attacker with low user privileges to create a malicious DLL that could le...Show more |
1Citrix 1Secure Access Client Jun 17, 2026 Feb 20, 2025 5.9 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac |
Rufus is a utility that helps format and create bootable USB flash drives. A DLL hijacking vulnerability in Rufus 4.6.2208 and earlier versions allows an attacker loading and executing a malicious DLL with escalated priv...Show more |
Insecure Loading of Dynamic Link Libraries have been discovered in HVAC Energy Saving Program, which could allow local attackers to potentially disclose information or execute arbitray code on affected systems. This issu...Show more |
Insecure Loading of Dynamic Link Libraries have been discovered in USB-CONVERTERCABLE DRIVER, which could allow local attackers to potentially disclose information or execute arbitray code on affected systems. This issue...Show more |
Uncontrolled search path for the Intel(R) RealSense D400 Series Universal Windows Platform (UWP) Driver for Windows(R) 10 all versions may allow an authenticated user to potentially enable escalation of privilege via loc...Show more |
Uncontrolled search path element in some BIOS and System Firmware Update Package for Intel(R) Server M50FCP family before version R01.02.0002 may allow a privileged user to potentially enable escalation of privilege via...Show more |
Uncontrolled search path for some Intel(R) Quartus(R) Prime Software before version 23.1.1 Patch 1.01std may allow an authenticated user to potentially enable escalation of privilege via local access. |
Uncontrolled search path for some EPCT software before version 1.42.8.0 may allow an authenticated user to potentially enable escalation of privilege via local access. |
Uncontrolled search path for the Intel(R) XTU software for Windows before version 7.14.2.14 may allow an authenticated user to potentially enable escalation of privilege via local access. |
Uncontrolled search path for the FPGA Support Package for the Intel(R) oneAPI DPC++/C++ Compiler software for Windows before version 2024.2 may allow an authenticated user to potentially enable escalation of privilege vi...Show more |
1Intel 2Advisor Oneapi Base ToolkitJun 17, 2026 Feb 12, 2025 5.4 MEDIUM· v4 6.7 MEDIUM· v3 N/A· v2 Uncontrolled search path for some Intel(R) Advisor software before version 2024.2 may allow an authenticated user to potentially enable escalation of privilege via local access. |