CWE-427
1,189 CVEs • Abstraction: Base
Uncontrolled Search Path Element
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
CVEs (1,189)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability was found in XAMPP 7.1.1-0-VC14. It has been classified as problematic. Affected is an unknown function of the component Installer. The manipulation leads to privilege escalation. It is possible to launch...Show more |
DLL hijacking vulnerability in KiesWrapper in Samsung Kies prior to version 2.6.4.22043_1 allows attacker to execute arbitrary code. |
An uncontrolled search path element vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to craft a special configuration file to load an untrusted library with escalated privilege...Show more |
EOL Product CVE - Installer of Trend Micro Password Manager (Consumer) versions 3.7.0.1223 and below provided by Trend Micro Incorporated contains an issue with the DLL search path, which may lead to insecurely loading D...Show more |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 May 24, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the 'working' folder through the 'Upload Files / Binaries' functionality. |
A DLL hijacking vulnerability in the installed for Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, leading to execution of arbitrary code, via the installer not restr...Show more |
Multiple DLL hijacking vulnerabilities via the components instup.exe and wsc_proxy.exe in Avast Premium Security before v21.11.2500 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via a craf...Show more |
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 3640 |
Local privilege escalation due to a DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 3640 |
1Intel 1Extreme Tuning Utility Jun 17, 2026 May 12, 2022 N/A· v4 7.3 HIGH· v3 4.4 MEDIUM· v2 Uncontrolled search path in the Intel(R) XTU software before version 7.3.0.33 may allow an authenticated user to potentially enable escalation of privilege via local access. |
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreJun 17, 2026 May 11, 2022 N/A· v4 7.3 HIGH· v3 4.4 MEDIUM· v2 Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an uncontrolled search path vulnerability that could lead to local privilege escalation. Exp...Show more |
1Paloaltonetworks 1Cortex Xdr Agent Jun 17, 2026 May 11, 2022 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local user with file creation privilege in the Windows root directory (such...Show more |
1Xinje 1Xd/e Series Plc Program Tool Jun 17, 2026 May 11, 2022 N/A· v4 7.3 HIGH· v3 6.9 MEDIUM· v2 A vulnerability exists in XINJE XD/E Series PLC Program Tool in versions up to v3.5.1 that can allow an authenticated, local attacker to load a malicious DLL. Local access is required to successfully exploit this vulnera...Show more |
A misconfiguration in the node default path allows for local privilege escalation from a lower privileged user to the Splunk user in Splunk Enterprise versions before 8.1.1 on Windows. |
1F5 2Big Ip Access Policy Manager Big Ip Access Policy Manager ClientJun 17, 2026 May 5, 2022 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, as well as F5 BIG-IP APM C...Show more |
SonicWall Global VPN Client 4.10.7.1117 installer (32-bit and 64-bit) and earlier versions have a DLL Search Order Hijacking vulnerability in one of the installer components. Successful exploitation via a local attacker...Show more |
1Samsung 1Gear Iconx Pc Manager Jun 17, 2026 May 3, 2022 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 DLL hijacking vulnerability in Gear IconX PC Manager prior to version 2.1.220405.51 allows attacker to execute arbitrary code. The patch adds proper absolute path to prevent dll hijacking. |
A DLL search path vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow privilege escalation. |
2Git For Windows Project Microsoft4Git For Windows Visual Studio 2017Visual Studio 2019+1 moreJun 17, 2026 Apr 12, 2022 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 GitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user account. |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraGit+1 moreJun 17, 2026 Apr 12, 2022 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted part...Show more |