← Back
CWE-427

1,189 CVEs • Abstraction: Base

Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

JSON object

Loading...

CVEs (1,189)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tenable
2Nessus
Plugin Feed
Jun 17, 2026
Mar 15, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability was reported where through modifying the scan variables, an authenticated user in Tenable products, that has Scan Policy Configuration roles, could manipulate audit policy variables to execute arbitrary c...Show more
A vulnerability was reported where through modifying the scan variables, an authenticated user in Tenable products, that has Scan Policy Configuration roles, could manipulate audit policy variables to execute arbitrary commands on credentialed scan targets.Show less
1Mcafee
1Total Protection
Jun 17, 2026
Mar 13, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
McAfee Total Protection prior to 16.0.49 allows attackers to elevate user privileges due to DLL sideloading. This could enable a user with lower privileges to execute unauthorized tasks.
1Trendmicro
1Apex One
Jun 17, 2026
Mar 10, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
An issue in the Trend Micro Apex One agent could allow an attacker who has previously acquired administrative rights via other means to bypass the protection by using a specifically crafted DLL during a specific update p...Show more
An issue in the Trend Micro Apex One agent could allow an attacker who has previously acquired administrative rights via other means to bypass the protection by using a specifically crafted DLL during a specific update process. Please note: an attacker must first obtain administrative access on the target system via another method in order to exploit this.Show less
1Trendmicro
1Apex One
Jun 17, 2026
Mar 10, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker to achieve a remote code execution state on affected products.
1Sraoss
1Pg Ivm
Jun 17, 2026
Mar 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Uncontrolled search path element vulnerability exists in pg_ivm versions prior to 1.5.1. When refreshing an IMMV, pg_ivm executes functions without specifying schema names. Under certain conditions, pg_ivm may be tricked...Show more
Uncontrolled search path element vulnerability exists in pg_ivm versions prior to 1.5.1. When refreshing an IMMV, pg_ivm executes functions without specifying schema names. Under certain conditions, pg_ivm may be tricked to execute unexpected functions from other schemas with the IMMV owner's privilege. If this vulnerability is exploited, an unexpected function provided by an attacker may be executed with the privilege of the materialized view owner.Show less
1Afl++ Project
1Afl++
Jun 17, 2026
Feb 21, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
In AFL++ 4.05c, the CmpLog component uses the current working directory to resolve and execute unprefixed fuzzing targets, allowing code execution.
1Infoblox
1Bloxone Endpoint
Jun 17, 2026
Feb 17, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Infoblox BloxOne Endpoint for Windows through 2.2.7 allows DLL injection that can result in local privilege escalation.
1Intel
2Administrative Tools For Intel Network Adapters
Non Volatile Memory Update Utility
Jun 17, 2026
Feb 16, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Uncontrolled search path in some Intel(R) Network Adapter installer software may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Quickassist Technology
Jun 17, 2026
Feb 16, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
Uncontrolled search path in some Intel(R) QAT drivers for Windows before version 1.6 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
2Fpga Software Development Kit
Quartus Prime
Jun 17, 2026
Feb 16, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
Uncontrolled search path in some Intel(R) Quartus(R) Prime Pro and Standard Edition software may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Battery Life Diagnostic Tool
Jun 17, 2026
Feb 16, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Uncontrolled search path in the Intel(R) Battery Life Diagnostic Tool software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Fpga Add On
Jun 17, 2026
Feb 16, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
Uncontrolled search path element in the Intel(R) FPGA Add-on for Intel(R) oneAPI Base Toolkit before version 2022.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Oneapi Collective Communications Library
Jun 17, 2026
Feb 16, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
Uncontrolled search path element in the Intel(R) oneAPI Collective Communications Library (oneCCL) before version 2021.6 for Intel(R) oneAPI Base Toolkit may allow an authenticated user to potentially enable escalation o...Show more
Uncontrolled search path element in the Intel(R) oneAPI Collective Communications Library (oneCCL) before version 2021.6 for Intel(R) oneAPI Base Toolkit may allow an authenticated user to potentially enable escalation of privilege via local access.Show less
1Intel
1Oneapi Dpc++/c++ Compiler Runtime
Jun 17, 2026
Feb 16, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
Uncontrolled search path element in the Intel(R) oneAPI DPC++/C++ Compiler Runtime before version 2022.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Openmp
Jun 17, 2026
Feb 16, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
Uncontrolled search path element in the Intel(R) oneAPI Toolkit OpenMP before version 2022.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Oneapi Deep Neural Network
Jun 17, 2026
Feb 16, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
Uncontrolled search path element in the Intel(R) oneAPI Deep Neural Network (oneDNN) before version 2022.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Trace Analyzer And Collector
Jun 17, 2026
Feb 16, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
Uncontrolled search path element in the Intel(R) Trace Analyzer and Collector before version 2021.6 for Intel(R) oneAPI HPC Toolkit may allow an authenticated user to potentially enable escalation of privilege via local...Show more
Uncontrolled search path element in the Intel(R) Trace Analyzer and Collector before version 2021.6 for Intel(R) oneAPI HPC Toolkit may allow an authenticated user to potentially enable escalation of privilege via local access.Show less
1Intel
1Mpi Library
Jun 17, 2026
Feb 16, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
Uncontrolled search path element in the Intel(R) MPI Library before version 2021.6 for Intel(R) oneAPI HPC Toolkit may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Distribution For Python
Jun 17, 2026
Feb 16, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
Uncontrolled search path element in the Intel(R) Distribution for Python programming language before version 2022.1 for Intel(R) oneAPI Toolkits may allow an authenticated user to potentially enable escalation of privile...Show more
Uncontrolled search path element in the Intel(R) Distribution for Python programming language before version 2022.1 for Intel(R) oneAPI Toolkits may allow an authenticated user to potentially enable escalation of privilege via local access.Show less
1Intel
1Oneapi Data Analytics Library
Jun 17, 2026
Feb 16, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
Uncontrolled search path element in the Intel(R) oneAPI Data Analytics Library (oneDAL) before version 2021.5 for Intel(R) oneAPI Base Toolkit may allow an authenticated user to potentially enable escalation of privilege...Show more
Uncontrolled search path element in the Intel(R) oneAPI Data Analytics Library (oneDAL) before version 2021.5 for Intel(R) oneAPI Base Toolkit may allow an authenticated user to potentially enable escalation of privilege via local access.Show less