CWE-426

High likelihood

Untrusted Search Path

Parent: CWE-642 - External Control of Critical State Data

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

626 vulnerabilities with CWE-426
CVE-2022-36403 HIGH
Device Software Manager <2.20.3.0 - Privilege Escalation
CVSS 7.8
CVE-2022-36070 HIGH
Poetry - Code Injection
CVSS 7.3
CVE-2022-22047 HIGH KEV
Windows Client Server Run-time Subsystem - Privilege Escalation
CVSS 7.8
CVE-2022-31012 HIGH
Git for Windows <2.37.1 - Code Injection
CVSS 8.2
CVE-2022-28964 HIGH
Avast Premium Security <v21.11.2500 - DoS
CVSS 7.1
CVE-2022-29583 HIGH
Service - Untrusted Search Path
CVSS 7.8
CVE-2022-24826 CRITICAL
Git Large File Storage < 3.1.3 - Untrusted Search Path
CVSS 9.8
CVE-2022-26184 CRITICAL
Poetry <1.1.9 - Memory Corruption
CVSS 9.8
CVE-2022-26183 HIGH
PNPM <6.15.1 - Memory Corruption
CVSS 8.8
CVE-2022-26488 HIGH
Python <3.10.3 (Windows) - Privilege Escalation
CVSS 7.0
CVE-2022-25366 HIGH
Cryptomator < 1.6.5 - Untrusted Search Path
CVSS 7.8
CVE-2022-0014 MEDIUM
Paloaltonetworks Cortex Xdr Agent < 5.0.12 - Untrusted Search Path
CVSS 6.7
CVE-2021-4435 HIGH
Yarn < 1.22.13 - Untrusted Search Path
CVSS 7.7
CVE-2021-26738 HIGH
Zscaler Client Connector < 3.7 - Untrusted Search Path
CVSS 7.8
CVE-2021-3305 HIGH
Feishu < 3.41.3 - Untrusted Search Path
CVSS 7.8
CVE-2021-36666 HIGH
Druva Insync Client < 7.0.0 - Untrusted Search Path
CVSS 7.8
CVE-2021-45975 HIGH
Acer Care Center <4.00.3038 - DLL Hijacking
CVSS 7.8
CVE-2021-33063 HIGH
Intel(R) RealSense(TM) D400 Series UWP - Privilege Escalation
CVSS 7.8
CVE-2021-26557 HIGH
Octopus Tentacle < 6.0.489 - Untrusted Search Path
CVSS 7.8
CVE-2021-26556 HIGH
Octopus Deploy < 2020.4.229 - Untrusted Search Path
CVSS 7.8
CVE-2021-36297 HIGH
SupportAssist Client <3.8-3.9 - Code Injection
CVSS 7.8
CVE-2021-31841 HIGH
Mcafee Agent < 5.7.4 - Untrusted Search Path
CVSS 8.2
CVE-2021-41387 HIGH
Seatd < 0.6.2 - Untrusted Search Path
CVSS 8.8
CVE-2021-37617 HIGH
Nextcloud Desktop < 3.3.0 - Uncontrolled Search Path
CVSS 7.3
CVE-2021-21562 MEDIUM
Dell Emc Powerscale Onefs - Untrusted Search Path
CVSS 4.4
Details
Vulnerabilities 626
Exploit Likelihood High