CWE-426

High likelihood

Untrusted Search Path

Parent: CWE-642 - External Control of Critical State Data

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

626 vulnerabilities with CWE-426
CVE-2024-43616 HIGH
Microsoft 365 Apps - Untrusted Search Path
CVSS 7.8
CVE-2024-43576 HIGH
Microsoft 365 Apps - Untrusted Search Path
CVSS 7.8
CVE-2024-8733 HIGH
HP One Agent - Privilege Escalation
CVSS 8.0
CVE-2024-9325 HIGH
Intelbras InControl <2.21.56 - Unquoted Search Path
CVSS 7.8
CVE-2024-6769 MEDIUM
Microsoft Windows <2022 - Privilege Escalation
CVSS 6.7
CVE-2024-44103 HIGH
Ivanti Workspace Control < 10.18.99.0 - Untrusted Search Path
CVSS 8.8
CVE-2024-45281 MEDIUM
SAP BusinessObjects - Privilege Escalation
CVSS 5.8
CVE-2024-6473 HIGH
Yandex Browser <24.7.1.380 - DLL Hijacking
CVSS 7.8
CVE-2024-5623 HIGH
B&R APROL <= R 4.4-00P3 - Privilege Escalation
CVSS 7.8
CVE-2024-5622 HIGH
B&R APROL <4.2.07P3, <4.4-00P3 - Privilege Escalation
CVSS 7.8
CVE-2024-38305 HIGH
Dell SupportAssist <4.0.3 - Privilege Escalation
CVSS 7.3
CVE-2024-7886 HIGH
Scooter Software Beyond Compare <3.3.5.15075 - Path Traversal
CVSS 7.8
CVE-2024-42439 MEDIUM
Zoom Workplace Desktop App <6.1.0 - Privilege Escalation
CVSS 6.5
CVE-2024-41865 HIGH
Adobe Dimension < 3.4.11 - Untrusted Search Path
CVSS 7.8
CVE-2024-6975 HIGH
Catonetworks Cato Client < 5.10.34 - Untrusted Search Path
CVSS 8.8
CVE-2024-6974 HIGH
Catonetworks Cato Client < 5.10.34 - Incorrect Default Permissions
CVSS 8.8
CVE-2024-34123 HIGH
Premiere Pro <24.4.1 - RCE
CVSS 7.0
CVE-2024-35260 HIGH
Microsoft Power Platform - Untrusted Search Path
CVSS 8.0
CVE-2024-36071 MEDIUM
Samsung Magician 8.0.0 - Privilege Escalation
CVSS 6.3
CVE-2024-6080 HIGH
Intelbras InControl <2.21.56 - Unquoted Search Path
CVSS 7.8
CVE-2024-38462 CRITICAL
iRODS <4.3.2 - Buffer Overflow
CVSS 9.8
CVE-2024-30100 HIGH
Microsoft SharePoint Server - RCE
CVSS 7.8
CVE-2024-28060 HIGH
Apiris Kafeo <6.4.4 - Code Injection
CVSS 7.3
CVE-2024-28133 HIGH
Phoenixcontact Charx Sec-3000 Firmware < 1.5.1 - Untrusted Search Path
CVSS 7.8
CVE-2024-32019 HIGH
Netdata Agent - RCE
CVSS 8.8
Details
Vulnerabilities 626
Exploit Likelihood High