← Back
CWE-427

1,189 CVEs • Abstraction: Base

Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

JSON object

Loading...

CVEs (1,189)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Deltaww
2Cncsoft B
Dopsoft
Jun 17, 2026
Feb 29, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Delta Electronics CNCSoft-B DOPSoft prior to v4.0.0.82 insecurely loads libraries, which may allow an attacker to use DLL hijacking and take over the system where the software is installed.
1Aveva
1Platform Common Services
Jun 17, 2026
Feb 29, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
The vulnerability, if exploited, could allow a malicious entity with access to the file system to achieve arbitrary code execution and privilege escalation by tricking AVEVA Edge to load an unsafe DLL.
1Hexagon
1Qognify Vms Client Viewer
Jun 17, 2026
Feb 26, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
A DLL hijacking vulnerability was identified in the Qognify VMS Client Viewer version 7.1 or higher, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DL...Show more
A DLL hijacking vulnerability was identified in the Qognify VMS Client Viewer version 7.1 or higher, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL, if some specific pre-conditions are met.Show less
1Intel
1Mpi Library
Jun 17, 2026
Feb 14, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Uncontrolled search path for some Intel(R) MPI Library Software before version 2021.11 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1System Support Utility
Jun 17, 2026
Feb 14, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Uncontrolled search path element in some Intel(R) SSU software before version 3.0.0.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1System Usage Report For Gameplay
Jun 17, 2026
Feb 14, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Uncontrolled search path in the Intel(R) SUR for Gameplay Software before version 2.0.1901 may allow a privillaged user to potentially enable escalation of privilege via local access.
1Intel
1Implicit Spmd Program Compiler
Jun 17, 2026
Feb 14, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Uncontrolled search path in some Intel(R) ISPC software before version 1.21.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Software Development Kit For Opencl
Jun 17, 2026
Feb 14, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Uncontrolled search path in some Intel(R) SDK for OpenCL(TM) Applications software may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Computing Improvement Program
Jun 17, 2026
Feb 14, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Uncontrolled search path in some Intel(R) CIP software before version 2.4.10577 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Battery Life Diagnostic Tool
Jun 17, 2026
Feb 14, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Uncontrolled search path in some Intel(R) Battery Life Diagnostic Tool software before version 2.3.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Virtual Raid On Cpu
Jun 17, 2026
Feb 14, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
Uncontrolled search path element in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Oneapi
Jun 17, 2026
Feb 14, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Qsfp+ Configuration Utility
Jun 17, 2026
Feb 14, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Uncontrolled search path in Intel(R) QSFP+ Configuration Utility software, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Extreme Tuning Utility
Jun 17, 2026
Feb 14, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Uncontrolled search path in some Intel(R) XTU software before version 7.12.0.29 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Thunderbolt Dch Driver
Jun 17, 2026
Feb 14, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Uncontrolled search path element in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Binary Configuration Tool
Jun 17, 2026
Feb 14, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Uncontrolled search path in some Intel(R) Binary Configuration Tool software before version 3.4.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Plone
1Plone Docker Official Image
Jul 9, 2026
Feb 5, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components not existing in the public package index (npm).
1Trendmicro
5Air Support
Antivirus + SecurityInternet Security+2 more
Jun 17, 2026
Jan 29, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Trend Micro uiAirSupport, included in the Trend Micro Security 2023 family of consumer products, version 6.0.2092 and below is vulnerable to a DLL hijacking/proxying vulnerability, which if exploited could allow an attac...Show more
Trend Micro uiAirSupport, included in the Trend Micro Security 2023 family of consumer products, version 6.0.2092 and below is vulnerable to a DLL hijacking/proxying vulnerability, which if exploited could allow an attacker to impersonate and modify a library to execute code on the system and ultimately escalate privileges on an affected system.Show less
1Regify
1Regipay
Jun 17, 2026
Jan 24, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue was discovered in Regify Regipay Client for Windows version 4.5.1.0 allows DLL hijacking: a user can trigger the execution of arbitrary code every time the product is executed.
1Ibm
1Db2
Jun 17, 2026
Jan 22, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
IBM Db2 10.1, 10.5, and 11.1 could allow a remote user to execute arbitrary code caused by installing like named jar files across multiple databases. A user could exploit this by installing a malicious jar file that ove...Show more
IBM Db2 10.1, 10.5, and 11.1 could allow a remote user to execute arbitrary code caused by installing like named jar files across multiple databases. A user could exploit this by installing a malicious jar file that overwrites the existing like named jar file in another database. IBM X-Force ID: 249205.Show less