CWE-426

High likelihood

Untrusted Search Path

Parent: CWE-642 - External Control of Critical State Data

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

657 vulnerabilities with CWE-426
CVE-2024-49515 HIGH
Substance3D - Painter <10.1.0 - Code Injection
CVSS 7.8
CVE-2024-36507 HIGH
Fortinet FortiClientWindows <7.4.0 - RCE
CVSS 7.3
CVE-2024-49043 HIGH
Microsoft SQL Server 2016-2022 Remote Code Execution via Untrusted Search Path
CVSS 7.8
CVE-2024-47906 HIGH
Ivanti Connect Secure <22.7R2.3 - Privilege Escalation
CVSS 7.8
CVE-2024-7995 HIGH
Autodesk VRED 2025-2025.2 - Privilege Escalation via Untrusted Search Path
CVSS 7.8
CVE-2024-47422 HIGH
Adobe Framemaker <2020.6, 2022.4 - RCE
CVSS 7.8
CVE-2024-43616 HIGH
Microsoft 365 Apps and Office - Remote Code Execution via Untrusted Search Path
CVSS 7.8
CVE-2024-43576 HIGH
Microsoft 365 Apps - Remote Code Execution via Untrusted Search Path
CVSS 7.8
CVE-2024-8733 HIGH
HP One Agent - Privilege Escalation
CVSS 8.0
CVE-2024-9325 HIGH
Intelbras InControl <2.21.56 - Unquoted Search Path
CVSS 7.8
CVE-2024-6769 MEDIUM
Microsoft Windows <2022 - Privilege Escalation
CVSS 6.7
CVE-2024-44103 HIGH
Ivanti Workspace Control < 10.18.99.0 - Authenticated DLL Hijacking
CVSS 8.8
CVE-2024-45281 MEDIUM
SAP BusinessObjects - Privilege Escalation
CVSS 5.8
CVE-2024-6473 HIGH
Yandex Browser <24.7.1.380 - DLL Hijacking
CVSS 7.8
CVE-2024-5623 HIGH
B&R APROL <= R 4.4-00P3 - Privilege Escalation
CVSS 7.8
CVE-2024-5622 HIGH
B&R APROL <4.2.07P3, <4.4-00P3 - Privilege Escalation
CVSS 7.8
CVE-2024-38305 HIGH
Dell SupportAssist <4.0.3 - Privilege Escalation
CVSS 7.3
CVE-2024-7886 HIGH
Scooter Software Beyond Compare <3.3.5.15075 - Path Traversal
CVSS 7.8
CVE-2024-42439 MEDIUM
Zoom Workplace Desktop App <6.1.0 - Privilege Escalation
CVSS 6.5
CVE-2024-41865 HIGH
Adobe Dimension < 3.4.11 - Untrusted Search Path
CVSS 7.8
CVE-2024-6975 HIGH
Cato Networks SDP Client < 5.10.34 - Local Privilege Escalation via OpenSSL Configuration File
CVSS 8.8
CVE-2024-6974 HIGH
Cato Networks SDP Client < 5.10.34 - Local Privilege Escalation via Self-Upgrade
CVSS 8.8
CVE-2024-34123 HIGH
Premiere Pro < 23.6.7 - Untrusted Search Path Arbitrary Code Execution
CVSS 7.0
CVE-2024-35260 HIGH
Microsoft Power Platform - Authenticated Remote Code Execution via Untrusted Search Path
CVSS 8.0
CVE-2024-36071 MEDIUM
Samsung Magician 8.0.0 - Privilege Escalation
CVSS 6.3
Details
Vulnerabilities 657
Exploit Likelihood High