CWE-427
1,189 CVEs • Abstraction: Base
Uncontrolled Search Path Element
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
CVEs (1,189)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
SaferVPN for Windows Ver 5.0.3.3 through 5.0.4.15 could allow local privilege escalation from low privileged users to SYSTEM via a crafted openssl configuration file. This issue is similar to CVE-2019-12572. |
AnyDesk before 6.1.0 on Windows, when run in portable mode on a system where the attacker has write access to the application directory, allows this attacker to compromise a local user account via a read-only setting for...Show more |
1Epson 2Epsonnet Setupmanager Offirio Synergyware PrintdirectorJun 17, 2026 Dec 24, 2020 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Untrusted search path vulnerability in self-extracting files created by EpsonNet SetupManager versions 2.2.14 and earlier, and Offirio SynergyWare PrintDirector versions 1.6x/1.6y and earlier allows an attacker to gain p...Show more |
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It has a misconfigured FTP service that allows a malicious network user to access system folders and download sensitive file...Show more |
Western Digital Dashboard before 3.2.2.9 allows DLL Hijacking that leads to compromise of the SYSTEM account. |
Adobe Lightroom Classic version 10.0 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of th...Show more |
Adobe Prelude version 9.0.1 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user inte...Show more |
1Paloaltonetworks 1Cortex Xdr Agent Jun 17, 2026 Dec 9, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A local privilege escalation vulnerability exists in Palo Alto Networks Cortex XDR Agent on the Windows platform that allows an authenticated local Windows user to execute programs with SYSTEM privileges. This requires t...Show more |
1Kaspersky 1Anti Ransomware Tool Jun 17, 2026 Dec 4, 2020 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 The installer of Kaspersky Anti-Ransomware Tool (KART) prior to KART 4.0 Patch C was vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges during installation process. |
1Canonical 2Snapcraft Ubuntu LinuxJun 17, 2026 Dec 4, 2020 N/A· v4 6.8 MEDIUM· v3 4.4 MEDIUM· v2 In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a malicious snap to gain code execution within the context of another snap if both plug the home interface...Show more |
Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which the installation repair takes place. Since the MS Installer allows regular users to run the repair, a...Show more |
1Cyberark 1Endpoint Privilege Manager Jun 17, 2026 Nov 27, 2020 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 CyberArk Endpoint Privilege Manager (EPM) 11.1.0.173 allows attackers to bypass a Credential Theft protection mechanism by injecting a DLL into a process that normally has credential access, such as a Chrome process that...Show more |
1Epson 33Album Print Color Calibration UtilityColorbase+30 moreJun 17, 2026 Nov 24, 2020 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. |
Uncontrolled search path in the Intel(R) VTune(TM) Profiler before version 2020 Update 1 may allow an authenticated user to potentially enable escalation of privilege via local access. |
1Intel 1Scs Add On For Microsoft Sccm Jun 17, 2026 Nov 12, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Uncontrolled search path in Intel(R) SCS Add-on for Microsoft* SCCM before version 2.1.10 may allow an authenticated user to potentially enable escalation of privilege via local access. |
Various components in Ivanti Endpoint Manager through 2020.1.1 rely on Windows search order when loading a (nonexistent) library file, allowing (under certain conditions) one to gain code execution (and elevation of priv...Show more |
NVIDIA GeForce NOW application software on Windows, all versions prior to 2.0.25.119, contains a vulnerability in its open-source software dependency in which the OpenSSL library is vulnerable to binary planting attacks...Show more |
1Bbraun 1Onlinesuite Application Package Jun 17, 2026 Nov 6, 2020 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 A DLL hijacking vulnerability in the B. Braun OnlineSuite Version AP 3.0 and earlier allows local attackers to execute code on the system as a high privileged user. |
1Git Large File Storage Project 1Git Large File Storage Jun 17, 2026 Nov 5, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Git LFS 2.12.0 allows Remote Code Execution. |
A vulnerability exists in the Origin Client that could allow a non-Administrative user to elevate their access to either Administrator or System. Once the user has obtained elevated access, they may be able to take contr...Show more |