← Back
CWE-427

1,220 CVEs • Abstraction: Base

Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

JSON object

Loading...

CVEs (1,220)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openclaw
1Openclaw
Jun 17, 2026
May 11, 2026
8.4 HIGH· v4
7.8 HIGH· v3
N/A· v2
OpenClaw before 2026.4.23 contains an arbitrary code execution vulnerability in the bundled plugin setup resolver that loads setup-api.js from process.cwd() during provider setup metadata resolution. Attackers can execut...Show more
OpenClaw before 2026.4.23 contains an arbitrary code execution vulnerability in the bundled plugin setup resolver that loads setup-api.js from process.cwd() during provider setup metadata resolution. Attackers can execute arbitrary JavaScript under the current user account by placing a malicious extensions/<plugin>/setup-api.js file in a repository and convincing a user to run OpenClaw commands from that directory.Show less
-
-
Jun 17, 2026
May 8, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control the value of the PATH environment variable. NOTE: this is disputed because ability of an attacker to control the environmen...Show more
RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control the value of the PATH environment variable. NOTE: this is disputed because ability of an attacker to control the environment is a site-specific misconfiguration.Show less
1Zte
1Zxcloud Irai
Jun 17, 2026
May 7, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and...Show more
ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.Show less
1Zte
1Zxcloud Irai
Jun 17, 2026
May 7, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execute arbitrary code locally and escalate privileges.
-
-
Aug 24, 2026
May 6, 2026
8.4 HIGH· v4
N/A· v3
N/A· v2
An Uncontrolled Search Path Element vulnerability in JohnsonControls AC2000 on Windows allows Leveraging/Manipulating Configuration File Search Paths. This issue affects AC2000: from 10.6 before release 10, from 11.0 be...Show more
An Uncontrolled Search Path Element vulnerability in JohnsonControls AC2000 on Windows allows Leveraging/Manipulating Configuration File Search Paths. This issue affects AC2000: from 10.6 before release 10, from 11.0 before release 9, from 12 before release 3.Show less
1Watchguard
1Agent
Aug 10, 2026
May 6, 2026
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
Uncontrolled Search Path Element vulnerability in WatchGuard Agent on Windows allows Using Malicious Files.
-
-
Jun 17, 2026
Apr 29, 2026
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.93212.
1Openclaw
1Openclaw
Jun 17, 2026
Apr 28, 2026
5.8 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
OpenClaw before 2026.3.31 contains an incomplete host-env-security-policy.json that fails to restrict compiler binary environment variables, allowing untrusted models to substitute CC, CXX, CARGO_BUILD_RUSTC, and CMAKE_C...Show more
OpenClaw before 2026.3.31 contains an incomplete host-env-security-policy.json that fails to restrict compiler binary environment variables, allowing untrusted models to substitute CC, CXX, CARGO_BUILD_RUSTC, and CMAKE_C_COMPILER via environment overrides. Attackers with approved host-exec requests can override compiler binaries to execute arbitrary code during build processes.Show less
-
-
Jun 17, 2026
Apr 28, 2026
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
AVACAST developed by eMPIA Technology, has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a malicious DLL in a specific directory, resulting in arbitrary code execution with system privile...Show more
AVACAST developed by eMPIA Technology, has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a malicious DLL in a specific directory, resulting in arbitrary code execution with system privileges when the system loads the DLL.Show less
1Nullsoft
1Nullsoft Scriptable Install System
Jun 17, 2026
Apr 24, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTempFileName to return...Show more
NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTempFileName to return 0, as shown in the references).Show less
1Microsoft
1Power Apps
Jun 17, 2026
Apr 23, 2026
N/A· v4
8.0 HIGH· v3
N/A· v2
Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network.
-
-
Jun 17, 2026
Apr 23, 2026
7.0 HIGH· v4
7.3 HIGH· v3
N/A· v2
IP Setting Software contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with administrative privileges.
-
-
Jun 17, 2026
Apr 23, 2026
N/A· v4
5.1 MEDIUM· v3
N/A· v2
EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the installation directory. A local attacker can place a specially crafted DLL in this directory and achie...Show more
EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the installation directory. A local attacker can place a specially crafted DLL in this directory and achieve arbitrary code execution with highest privileges, because the affected service runs as NT AUTHORITY\SYSTEM.Show less
1Liveon
4Canonnwcamplugin.exe
Canonnwcampluginforadmin.exeDownloader5installer.exe+1 more
Jun 17, 2026
Apr 23, 2026
8.4 HIGH· v4
7.8 HIGH· v3
N/A· v2
The installers of LiveOn Meet Client for Windows (Downloader5Installer.exe and Downloader5InstallerForAdmin.exe) and the installers of Canon Network Camera Plugin (CanonNWCamPlugin.exe and CanonNWCamPluginForAdmin.exe) i...Show more
The installers of LiveOn Meet Client for Windows (Downloader5Installer.exe and Downloader5InstallerForAdmin.exe) and the installers of Canon Network Camera Plugin (CanonNWCamPlugin.exe and CanonNWCamPluginForAdmin.exe) insecurely load Dynamic Link Libraries (DLLs). If a malicious DLL is placed at the same directory, the affected installer may load that DLL and execute its code with the privilege of the user invoking the installer.Show less
1Firebirdsql
1Firebird
Jun 17, 2026
Apr 17, 2026
N/A· v4
9.9 CRITICAL· v3
N/A· v2
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine name into a filesystem path without fi...Show more
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine name into a filesystem path without filtering path separators or .. components. An authenticated user with CREATE FUNCTION privileges can use a crafted ENGINE name to load an arbitrary shared library from anywhere on the filesystem via path traversal. The library's initialization code executes immediately during loading, before Firebird validates the module, achieving code execution as the server's OS account. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.Show less
-
-
Jun 17, 2026
Apr 17, 2026
6.4 MEDIUM· v4
7.0 HIGH· v3
6.0 MEDIUM· v2
A vulnerability has been found in Mobatek MobaXterm Home Edition up to 26.1. This affects an unknown part in the library msimg32.dll. The manipulation leads to uncontrolled search path. An attack has to be approached loc...Show more
A vulnerability has been found in Mobatek MobaXterm Home Edition up to 26.1. This affects an unknown part in the library msimg32.dll. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The attack is considered to have high complexity. It is indicated that the exploitability is difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 26.2 is able to mitigate this issue. It is suggested to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.Show less
1Eaton
1Intelligent Power Protector
Jun 17, 2026
Apr 16, 2026
N/A· v4
9.9 CRITICAL· v3
N/A· v2
Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to arbitrary code execution by an attacker with access to the software package. This security issue has...Show more
Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to arbitrary code execution by an attacker with access to the software package. This security issue has been fixed in the latest version of Eaton IPP software which is available on the Eaton download center.Show less
1Adobe
2Photoshop Installer
Photoshop Set Up.exe
Jul 29, 2026
Apr 15, 2026
N/A· v4
8.6 HIGH· v3
N/A· v2
Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could have exploited this v...Show more
Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could have exploited this vulnerability by placing a malicious library in a directory searched by the installer. Exploitation of this issue required user interaction in that a victim must have been running the installer. Scope is changed.Show less
1Lenovo
1Software Fix
Aug 24, 2026
Apr 15, 2026
7.0 HIGH· v4
7.3 HIGH· v3
N/A· v2
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to execute code with elevated privileges.
1Lenovo
1Service Bridge
Aug 24, 2026
Apr 15, 2026
5.4 MEDIUM· v4
6.7 MEDIUM· v3
N/A· v2
A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a local authenticated user to execute code with elevated privileges.