CWE-426

High likelihood

Untrusted Search Path

Parent: CWE-642 - External Control of Critical State Data

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

602 vulnerabilities with CWE-426
CVE-2026-3787 HIGH
UltraVNC 1.6.4.0 - Path Traversal
CVSS 7.0
CVE-2026-29089 HIGH
TimescaleDB 2.23.0-2.25.1 - Code Injection
CVSS 8.8
CVE-2026-2998 HIGH
eAI Technologies ERP - DLL Hijacking
CVSS 7.8
CVE-2026-25926 HIGH
Notepad++ <8.9.2 - Unsafe Search Path
CVSS 7.3
CVE-2026-2542 HIGH
Total VPN 0.5.29.0 - Privilege Escalation
CVSS 7.0
CVE-2026-2538 HIGH
Notepad2 4.2.22-4.2.25 - Path Traversal
CVSS 7.0
CVE-2026-2516 HIGH
Unidocs ezPDF DRM Reader/ezPDF Reader 2.0/3.0.0.4 - Path Traversal
CVSS 7.0
CVE-2026-21508 HIGH
Microsoft Windows 10 1607 < 10.0.14393.8868 - Authentication Bypass
CVSS 7.0
CVE-2025-15569 HIGH
Artifex MuPDF <1.26.1 - Path Traversal
CVSS 7.0
CVE-2026-25880 HIGH
SumatraPDF <3.5.2 - RCE
CVSS 7.8
CVE-2025-15321 LOW
Tanium Tanos < 1.8.3.0196 - Incorrect Authorization
CVSS 2.7
CVE-2025-13491 MEDIUM
IBM App Connect Enterprise <12.19.0-12.0 - Info Disclosure
CVSS 5.1
CVE-2026-0662 HIGH
Autodesk 3ds Max < 2026.3.2 - Untrusted Search Path
CVSS 7.8
CVE-2025-65078
Lexmark - Code Injection
CVE-2026-24051 HIGH
OpenTelemetry-Go <1.40.0 - Path Hijacking
CVSS 7.0
CVE-2026-24070 HIGH
Native Access - Privilege Escalation
CVSS 8.8
CVE-2026-23888 MEDIUM
pnpm <10.28.1 - Path Traversal
CVSS 6.5
CVE-2026-23512 HIGH
SumatraPDF <3.5.2 - RCE
CVSS 8.6
CVE-2026-21280 HIGH
Adobe Illustrator < 29.8.4 - Untrusted Search Path
CVSS 8.6
CVE-2026-20943 HIGH
Microsoft Office - Code Injection
CVSS 7.0
CVE-2025-12793 HIGH
AsusSoftwareManagerAgent - RCE
CVSS 7.8
CVE-2019-25257 MEDIUM
LogicalDOC Enterprise 7.7.4 - Command Injection
CVSS 6.5
CVE-2025-67722 HIGH
Sangoma Freepbx < 16.0.45 - Untrusted Search Path
CVSS 7.8
CVE-2025-64785 HIGH
Adobe Acrobat < 20.005.30838 - Untrusted Search Path
CVSS 7.8
CVE-2025-12819 HIGH
PgBouncer <1.25.1 - SQL Injection
CVSS 7.5
Details
Vulnerabilities 602
Exploit Likelihood High