CWE-426

High likelihood

Untrusted Search Path

Parent: CWE-642 - External Control of Critical State Data

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

626 vulnerabilities with CWE-426
CVE-2024-20693 HIGH
Windows Kernel - Privilege Escalation
CVSS 7.8
CVE-2024-20754 HIGH
Lightroom Desktop <7.1.2 - RCE
CVSS 7.8
CVE-2024-26198 HIGH
Microsoft Exchange Server - Untrusted Search Path
CVSS 8.8
CVE-2024-21435 HIGH
Microsoft Windows 11 22h2 < 10.0.22621.3296 - Untrusted Search Path
CVSS 8.8
CVE-2024-27303 HIGH
electron-builder <24.13.2 - Command Injection
CVSS 7.3
CVE-2024-25103 MEDIUM
AppSamvid - Code Injection
CVSS 6.3
CVE-2024-24697 HIGH
Zoom < - Privilege Escalation
CVSS 7.2
CVE-2024-24810 HIGH
WiX toolset <4.0.4 - Privilege Escalation
CVSS 8.2
CVE-2024-23304 HIGH
Cybozu Kunai - Untrusted Search Path
CVSS 7.5
CVE-2024-22410 LOW
Creditcoin - Code Injection
CVSS 3.3
CVE-2024-22190 HIGH
GitPython <3.1.41 - Code Injection
CVSS 7.8
CVE-2024-21325 HIGH
Microsoft Printer Metadata Troubleshooter Tool - Untrusted Search Path
CVSS 7.8
CVE-2023-1521 HIGH
sccache - RCE
CVSS 7.8
CVE-2023-32266 MEDIUM
OpenText ALM,QC <16.0 - Code Injection
CVE-2023-48670 HIGH
Dell SupportAssist <3.14.1 - Privilege Escalation
CVSS 7.3
CVE-2023-43586 HIGH
Zoom Desktop Client for Windows - Privilege Escalation
CVSS 7.3
CVE-2023-36003 MEDIUM
XAML Diagnostics - Privilege Escalation
CVSS 6.7
CVE-2023-26031 HIGH
Apache Hadoop <3.3.4 - Privilege Escalation
CVSS 7.5
CVE-2023-39202 LOW
Zoom Rooms Client for Windows & Zoom VDI Client - DoS
CVSS 3.1
CVE-2023-41840 HIGH
Fortinet Forticlient - Untrusted Search Path
CVSS 7.8
CVE-2023-36422 HIGH
Microsoft Windows Defender - Privilege Escalation
CVSS 7.8
CVE-2023-36393 HIGH
Windows UI App Core - RCE
CVSS 7.8
CVE-2023-41766 HIGH
Microsoft Windows 10 1507 < 10.0.10240.20232 - Untrusted Search Path
CVSS 7.8
CVE-2023-36780 HIGH
Skype for Business - RCE
CVSS 7.2
CVE-2023-36778 HIGH
Microsoft Exchange Server - RCE
CVSS 8.0
Details
Vulnerabilities 626
Exploit Likelihood High