CWE-428
450 CVEs • Abstraction: Base
Unquoted Search Path or Element
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.
CVEs (450)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An Unquoted Service Path vulnerability exists in bVPN 2.5.1 via a specially crafted file in the waselvpnserv service path. |
1Rumble Mail Server Project 1Rumble Mail Server Jun 17, 2026 Apr 4, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An Unquoted Service Path vulnerablility exists in Rumble Mail Server 0.51.3135 via via a specially crafted file in the RumbleService executable service path. |
An Unquoted Service Path vulnerability exists in FreeLAN 2.2 via a specially crafted file in the FreeLAN Service path. |
An Unquoted Service Path vulnerability exists in AnyTXT Searcher 1.2.394 via a specially crafted file in the ATService path. . |
Xshell v7.0.0099 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file. |
Xlpd v7.0.0094 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file. |
Xmanager v7.0.0096 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file. |
Xftp 7.0.0088p and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file. |
FreeFtpd version 1.0.13 and below contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges. |
BitComet Service for Windows before version 1.8.6 contains an unquoted service path vulnerability which allows attackers to escalate privileges to the system level. |
Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker can hijack the flow of execution due to an unquoted argument to the runas.exe command used by the i...Show more |
1Rdpsoft 1Remote Desktop Commander Suite Agent Jun 17, 2026 Mar 3, 2022 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 Remote Desktop Commander Suite Agent before v4.8 contains an unquoted service path which allows attackers to escalate privileges to the system level. |
Wordline HIDCCEMonitorSVC before v5.2.4.3 contains an unquoted service path which allows attackers to escalate privileges to the system level. |
1Trigonesoft 1Remote System Monitor Jun 17, 2026 Feb 17, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 TRIGONE Remote System Monitor 3.61 is vulnerable to an unquoted path service allowing local users to launch processes with elevated privileges. |
1Mitsubishielectric 46C Controller Interface Module Utility C Controller Module Setting And Monitoring ToolCc Link Ie Control Network Data Collector+43 moreJun 17, 2026 Feb 11, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, an...Show more |
1Hpe 2Agentless Management Proliant Agentless ManagementJun 17, 2026 Feb 4, 2022 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 A local unquoted search path security vulnerability has been identified in HPE Agentless Management Service for Windows version(s): Prior to 1.44.0.0, 10.96.0.0. This vulnerability could be exploited locally by a user wi...Show more |
1Siemens 1Sicam Pq Analyzer Firmware Jun 17, 2026 Jan 11, 2022 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 A vulnerability has been identified in SICAM PQ Analyzer (All versions < V3.18). A service is started by an unquoted registry entry. As there are spaces in this path, attackers with write privilege to those directories m...Show more |
1Sophos 3Exploit Prevention Intercept X EndpointIntercept X For ServerJun 17, 2026 Nov 26, 2021 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 A local administrator could prevent the HMPA service from starting despite tamper protection using an unquoted service path vulnerability in the HMPA component of Sophos Intercept X Advanced and Sophos Intercept X Advanc...Show more |
Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrary code as the account that runs the Controller Service. This issue affects: Gallagher Command Centre...Show more |
1Intel 1Nuc M15 Laptop Kit Keyboard Led Service Driver Pack Jun 17, 2026 Nov 17, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Unquoted search path in the installer for the Intel(R) NUC M15 Laptop Kit Keyboard LED Service driver pack before version 1.0.0.4 may allow an authenticated user to potentially enable escalation of privilege via local ac...Show more |