CWE-426
High likelihoodUntrusted Search Path
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
639 vulnerabilities with CWE-426
CVE-2024-53407
LOW
Phiewer 4.1.0 - Untrusted Search Path Leading to Command Execution via Dylib Injection
CVSS 3.3
CVE-2024-48123
HIGH
HI-SCAN 6040i Hitrax HX-03-19-I - RCE
CVSS 8.4
CVE-2024-13158
HIGH
Ivanti Endpoint Manager < 2024 - Authenticated Remote Code Execution via Unbounded Resource Search Path
CVSS 7.2
CVE-2024-53866
CRITICAL
pnpm < 9.15.0 - Untrusted Search Path via Global Cache Override Leak
CVSS 9.8
CVE-2024-11454
HIGH
Autodesk Revit 2025-2025.4 - Untrusted Search Path DLL Loading
CVSS 7.8
CVE-2024-45207
HIGH
Veeam Agent for Windows - Code Injection
CVSS 7.0
CVE-2024-50986
HIGH
Clementine 1.3.1 - Untrusted Search Path
CVSS 7.3
CVE-2024-49515
HIGH
Substance3D - Painter <10.1.0 - Code Injection
CVSS 7.8
CVE-2024-36507
HIGH
Fortinet FortiClientWindows <7.4.0 - RCE
CVSS 7.3
CVE-2024-49043
HIGH
Microsoft SQL Server 2016-2022 Remote Code Execution via Untrusted Search Path
CVSS 7.8
CVE-2024-47906
HIGH
Ivanti Connect Secure <22.7R2.3 - Privilege Escalation
CVSS 7.8
CVE-2024-7995
HIGH
Autodesk VRED 2025-2025.2 - Privilege Escalation via Untrusted Search Path
CVSS 7.8
CVE-2024-47422
HIGH
Adobe Framemaker <2020.6, 2022.4 - RCE
CVSS 7.8
CVE-2024-43616
HIGH
Microsoft 365 Apps and Office - Remote Code Execution via Untrusted Search Path
CVSS 7.8
CVE-2024-43576
HIGH
Microsoft 365 Apps - Remote Code Execution via Untrusted Search Path
CVSS 7.8
CVE-2024-8733
HIGH
HP One Agent - Privilege Escalation
CVSS 8.0
CVE-2024-9325
HIGH
Intelbras InControl <2.21.56 - Unquoted Search Path
CVSS 7.8
CVE-2024-6769
MEDIUM
Microsoft Windows <2022 - Privilege Escalation
CVSS 6.7
CVE-2024-44103
HIGH
Ivanti Workspace Control < 10.18.99.0 - Authenticated DLL Hijacking
CVSS 8.8
CVE-2024-45281
MEDIUM
SAP BusinessObjects - Privilege Escalation
CVSS 5.8
CVE-2024-6473
HIGH
Yandex Browser <24.7.1.380 - DLL Hijacking
CVSS 7.8
CVE-2024-5623
HIGH
B&R APROL <= R 4.4-00P3 - Privilege Escalation
CVSS 7.8
CVE-2024-5622
HIGH
B&R APROL <4.2.07P3, <4.4-00P3 - Privilege Escalation
CVSS 7.8
CVE-2024-38305
HIGH
Dell SupportAssist <4.0.3 - Privilege Escalation
CVSS 7.3
CVE-2024-7886
HIGH
Scooter Software Beyond Compare <3.3.5.15075 - Path Traversal
CVSS 7.8
Details
Vulnerabilities
639
Exploit Likelihood
High