← Back
CWE-428

450 CVEs • Abstraction: Base

Unquoted Search Path or Element

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

JSON object

Loading...

CVEs (450)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sierrawireless
3Sierra Wireless Em7345 Software
Sierra Wireless Em7455 SoftwareSierra Wireless Location Sensor Driver
May 13, 2026
Aug 2, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Multiple unquoted service path vulnerabilities in Sierra Wireless Windows Mobile Broadband Driver Package (MBDP) with build ID < 4657 allows local users to launch processes with elevated privileges.
1Eduiq
1Net Monitor For Employees
May 13, 2026
Jun 8, 2017
N/A· v4
7.3 HIGH· v3
6.9 MEDIUM· v2
Net Monitor for Employees Pro through 5.3.4 has an unquoted service path, which allows a Security Feature Bypass of its documented "Block applications" design goal. The local attacker must have privileges to write to pro...Show more
Net Monitor for Employees Pro through 5.3.4 has an unquoted service path, which allows a Security Feature Bypass of its documented "Block applications" design goal. The local attacker must have privileges to write to program.exe in a protected directory, such as the %SYSTEMDRIVE% directory, and thus the issue is not interpreted as a direct privilege escalation. However, the local attacker might have the goal of executing program.exe even though program.exe is a blocked application.Show less
1Adobe
1Photoshop Cc
May 13, 2026
Apr 12, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Adobe Photoshop versions CC 2017 (18.0.1) and earlier, CC 2015.5.1 (17.0.1) and earlier have an unquoted search path vulnerability.
1Unisys
1Secure Partitioning
May 13, 2026
Apr 11, 2017
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Unquoted Windows search path vulnerability in the guest service in Unisys s-Par before 4.4.20 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by pr...Show more
Unquoted Windows search path vulnerability in the guest service in Unisys s-Par before 4.4.20 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by program.exe.Show less
1Lenovo
2Edge Keyboard Driver
Slim Usb Keyboard Driver
May 13, 2026
Jan 26, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Unquoted service path vulnerability in Lenovo Edge and Lenovo Slim USB Keyboard Driver versions earlier than 1.21 allows local users to execute code with elevated privileges.
1Adobe
1Creative Cloud
May 6, 2026
Oct 13, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Unquoted Windows search path vulnerability in Adobe Creative Cloud Desktop Application before 3.8.0.310 on Windows allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory.
1Moxa
1Active Opc Server
May 6, 2026
Sep 24, 2016
N/A· v4
8.8 HIGH· v3
7.2 HIGH· v2
Unquoted Windows search path vulnerability in Moxa Active OPC Server before 2.4.19 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory.
1Sonicwall
1Netextender
May 6, 2026
Aug 26, 2015
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Unquoted Windows search path vulnerability in the autorun value in Dell SonicWall NetExtender before 7.5.227 and 8.0.x before 8.0.238, as used in the SRA firmware before 7.5.1.2-40sv and 8.x before 8.0.0.3-23sv, allows l...Show more
Unquoted Windows search path vulnerability in the autorun value in Dell SonicWall NetExtender before 7.5.227 and 8.0.x before 8.0.238, as used in the SRA firmware before 7.5.1.2-40sv and 8.x before 8.0.0.3-23sv, allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder.Show less
2Openvpn
Privatetunnel
2Openvpn
Privatetunnel
May 28, 2026
Aug 25, 2014
N/A· v4
5.3 MEDIUM· v3
6.9 MEDIUM· v2
Unquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and OpenVPN Connect version 3.1 (Windows) allows local users to gain privileges via a crafted program.exe f...Show more
Unquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and OpenVPN Connect version 3.1 (Windows) allows local users to gain privileges via a crafted program.exe file in the %SYSTEMDRIVE% folder.Show less
1Schneider Electric
1Floating License Manager
May 28, 2026
Feb 28, 2014
N/A· v4
5.9 MEDIUM· v3
6.9 MEDIUM· v2
Unquoted Windows search path vulnerability in Schneider Electric Floating License Manager 1.0.0 through 1.4.0 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substr...Show more
Unquoted Windows search path vulnerability in Schneider Electric Floating License Manager 1.0.0 through 1.4.0 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character.Show less