CWE-426

High likelihood

Untrusted Search Path

Parent: CWE-642 - External Control of Critical State Data

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

657 vulnerabilities with CWE-426
CVE-2023-27769 HIGH
Wondershare PDF Reader 1.0.1 - Remote Code Execution via Untrusted Search Path
CVSS 7.8
CVE-2023-27768 HIGH
Wondershare PDFelement 9.1.1 - Remote Code Execution via Untrusted Search Path
CVSS 7.8
CVE-2023-27767 HIGH
Wondershare Dr.Fone 12.4.9 - Remote Code Execution via drfone_setup_full3360.exe
CVSS 7.8
CVE-2023-27766 HIGH
Wondershare Anireel 1.5.4 - Remote Code Execution via Untrusted Search Path
CVSS 7.8
CVE-2023-27765 HIGH
Wondershare Recoverit 10.6.3 - Remote Code Execution via recoverit_setup_full4134.exe
CVSS 7.8
CVE-2023-27764 HIGH
Wondershare Repairit 3.5.4 - Remote Code Execution via repairit_setup_full5913.exe
CVSS 7.8
CVE-2023-27763 HIGH
Wondershare MobileTrans 4.0.2 - Remote Code Execution via Untrusted Search Path
CVSS 7.8
CVE-2023-27762 HIGH
Wondershare DemoCreator 6.0.0 - Remote Code Execution via Untrusted Search Path
CVSS 7.8
CVE-2023-27761 HIGH
Wondershare UniConverter 14.0.0 - Remote Code Execution via Untrusted Search Path
CVSS 7.8
CVE-2023-27760 HIGH
Wondershare Filmora 12.0.9 - Remote Code Execution via Untrusted Search Path
CVSS 7.8
CVE-2023-27759 HIGH
Wondershare EdrawMind 10.0.6 - Remote Code Execution via WindowsCodescs.dll
CVSS 7.8
CVE-2023-26358 HIGH
Adobe Creative Cloud < 5.10 - Untrusted Search Path
CVSS 8.6
CVE-2023-26038 MEDIUM
ZoneMinder <1.36.33-1.37.33 - Local File Inclusion
CVSS 5.4
CVE-2023-26036 HIGH
ZoneMinder <1.36.33-1.37.33 - Local File Inclusion
CVSS 8.1
CVE-2023-23920 MEDIUM
Node.js <19.6.1-<14.21.3 - Privilege Escalation
CVSS 4.2
CVE-2023-22368 HIGH
ELECOM Camera Assistant <1.00-QuickFileDealer <1.2.1 - Privilege Es...
CVSS 7.8
CVE-2023-23618 HIGH
Git for Windows < 2.39.2 - Untrusted Search Path via gitk Execution
CVSS 8.6
CVE-2023-22743 HIGH
Git for Windows < 2.39.2 - Untrusted Search Path via DLL Side-Loading
CVSS 7.2
CVE-2023-21764 HIGH
Microsoft Exchange Server - Privilege Escalation
CVSS 7.8
CVE-2023-21763 HIGH
Microsoft Exchange Server - Privilege Escalation
CVSS 7.8
CVE-2022-4987 HIGH
Hirschmann Industrial HiVision External Application Path Hijacking Leading to Arbitrary Code Execution
CVSS 7.3
CVE-2022-43456 MEDIUM
Intel(R) RST <16.8.5.1014.5-19.5.2.1049.5 - Privilege Escalation
CVSS 6.7
CVE-2022-35868 MEDIUM
TIA Multiuser Server/V15.1-Project-Server V17 - Privilege Escalation
CVSS 6.7
CVE-2022-4883 HIGH
libXpm < 3.5.15 - Untrusted Search Path via PATH Environment Variable Manipulation
CVSS 8.8
CVE-2022-41953 HIGH
Git < 2.39.1 - Untrusted Search Path via Git GUI Clone Post-Processing
CVSS 8.6
Details
Vulnerabilities 657
Exploit Likelihood High