CWE-427
1,189 CVEs • Abstraction: Base
Uncontrolled Search Path Element
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
CVEs (1,189)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Intel 1Rapid Storage Technology Jun 17, 2026 Jun 9, 2021 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 Uncontrolled search path element in the installer for the Intel(R) Rapid Storage Technology software, before versions 17.9.0.34, 18.0.0.640 and 18.1.0.24, may allow an authenticated user to potentially enable escalation...Show more |
1Intel 1Driver & Support Assistant Jun 17, 2026 Jun 9, 2021 N/A· v4 7.3 HIGH· v3 4.4 MEDIUM· v2 Uncontrolled search path element in Intel(R) DSA before version 20.11.50.9 may allow an authenticated user to potentially enable an escalation of privilege via local access. |
1Intel 2Lapbc510 Firmware Lapbc710 FirmwareJun 17, 2026 Jun 9, 2021 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 Uncontrolled search path in the Intel(R) NUC M15 Laptop Kit Driver Pack software before updated version 1.1 may allow an authenticated user to potentially enable escalation of privilege via local access. |
1Intel 1Processor Diagnostic Tool Jun 17, 2026 Jun 9, 2021 N/A· v4 7.3 HIGH· v3 4.4 MEDIUM· v2 Uncontrolled search path element in the Intel(R) Processor Diagnostic Tool before version 4.1.5.37 may allow an authenticated user to potentially enable escalation of privilege via local access. |
1Cisco 5Webex Meetings Desktop Webex Meetings OnlineWebex Meetings Server+2 moreJun 17, 2026 Jun 4, 2021 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 A vulnerability in Cisco Webex Meetings Desktop App for Windows, Cisco Webex Meetings Server, Cisco Webex Network Recording Player for Windows, and Cisco Webex Teams for Windows could allow an authenticated, local attack...Show more |
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to execute arbitrary code and conduct DLL hijacking attacks. |
Untrusted search path vulnerability in The Installer of Overwolf 2.168.0.n and earlier allows an attacker to gain privileges and execute arbitrary code with the privilege of the user invoking the installer via a Trojan h...Show more |
Untrusted search path vulnerability in the installers of ScanSnap Manager prior to versions V7.0L20 and the Software Download Installer prior to WinSSInst2JP.exe and WinSSInst2iX1500JP.exe allows an attacker to gain priv...Show more |
1Bitdefender 1Gravityzone Business Security Jun 17, 2026 May 18, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Uncontrolled Search Path Element vulnerability in the openssl component as used in Bitdefender GravityZone Business Security allows an attacker to load a third party DLL to elevate privileges. This issue affects Bitdefen...Show more |
In Ubiquiti UniFi Video v3.10.13, when the executable starts, its first library validation is in the current directory. This allows the impersonation and modification of the library to execute code on the system. This wa...Show more |
1Teradici 1Pcoip Graphics Agent Jun 17, 2026 May 13, 2021 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 Teradici PCoIP Graphics Agent for Windows prior to 21.03 does not validate NVENC.dll. An attacker could replace the .dll and redirect pixels elsewhere. |
1Cisco 1Anyconnect Secure Mobility Client Jun 17, 2026 May 6, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are use...Show more |
1Cisco 1Anyconnect Secure Mobility Client Jun 17, 2026 May 6, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are use...Show more |
1Cisco 1Anyconnect Secure Mobility Client Jun 17, 2026 May 6, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are use...Show more |
1Cisco 1Anyconnect Secure Mobility Client Jun 17, 2026 May 6, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are use...Show more |
1Cisco 1Anyconnect Secure Mobility Client Jun 17, 2026 May 6, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are use...Show more |
1Cisco 1Anyconnect Secure Mobility Client Jun 17, 2026 May 6, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are use...Show more |
A DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow privilege escalation. |
A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.4). The software insecurely loads libraries which makes it vulnerable to DLL hijacking. Successful exploitation by a local attacker could lead...Show more |
Adobe Robohelp version 2020.0.3 (and earlier) is affected by an uncontrolled search path element vulnerability that could lead to privilege escalation. An attacker with admin permissions to write to the file system could...Show more |