CWE-426
High likelihoodUntrusted Search Path
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
657 vulnerabilities with CWE-426
CVE-2024-6080
HIGH
Intelbras InControl <2.21.56 - Unquoted Search Path
CVSS 7.8
CVE-2024-38462
CRITICAL
iRODS < 4.3.2 - Untrusted Search Path via msiSendMail Function
CVSS 9.8
CVE-2024-30100
HIGH
Microsoft SharePoint Server - Remote Code Execution
CVSS 7.8
CVE-2024-28060
HIGH
Apiris Kafeo <6.4.4 - Code Injection
CVSS 7.3
CVE-2024-28133
HIGH
CHARX SEC-3000/3050/3100/3150 Firmware < 1.5.1 - Untrusted Search Path
CVSS 7.8
CVE-2024-32019
HIGH
netdata 1.44.0-60-1.45.0-169 and 1.45.0-1.45.3 - Local Privilege Escalation via PATH Environment Variable Manipulation
CVSS 8.8
CVE-2024-20693
HIGH
Windows Kernel - Privilege Escalation
CVSS 7.8
CVE-2024-20754
HIGH
Lightroom < 7.2 - Untrusted Search Path
CVSS 7.8
CVE-2024-26198
HIGH
Microsoft Exchange Server - Remote Code Execution via Untrusted Search Path
CVSS 8.8
CVE-2024-21435
HIGH
Windows 11 22H2 < 10.0.22621.3296 and 23H2 < 10.0.22631.3296 - Remote Code Execution via OLE
CVSS 8.8
CVE-2024-27303
HIGH
electron-builder <24.13.2 - Command Injection
CVSS 7.3
CVE-2024-25103
MEDIUM
AppSamvid Software <= 2.0.1 - DLL Hijacking via Untrusted Search Path
CVSS 6.3
CVE-2024-24697
HIGH
Zoom Meeting SDK < 5.17.0 - Authenticated Privilege Escalation via Untrusted Search Path
CVSS 7.2
CVE-2024-24810
HIGH
WiX toolset <4.0.4 - Privilege Escalation
CVSS 8.2
CVE-2024-23304
HIGH
Cybozu KUNAI for Android 3.0.20-3.0.21 - Unauthenticated Denial of Service
CVSS 7.5
CVE-2024-22410
LOW
Creditcoin - Untrusted Search Path via Windows DLL Loading
CVSS 3.3
CVE-2024-22190
HIGH
GitPython < 3.1.41 - Untrusted Search Path on Windows via Git or Bash Execution
CVSS 7.8
CVE-2024-21325
HIGH
Microsoft Printer Metadata Troubleshooter Tool < 1.0.0.1 - Remote Code Execution
CVSS 7.8
CVE-2023-1521
HIGH
sccache < 0.4.0 - LD_PRELOAD Local Privilege Escalation
CVSS 7.8
CVE-2023-32266
MEDIUM
OpenText ALM,QC <16.0 - Code Injection
CVE-2023-48670
HIGH
Dell SupportAssist <3.14.1 - Privilege Escalation
CVSS 7.3
CVE-2023-43586
HIGH
Zoom Desktop Client for Windows - Privilege Escalation
CVSS 7.3
CVE-2023-36003
MEDIUM
XAML Diagnostics - Privilege Escalation
CVSS 6.7
CVE-2023-26031
HIGH
Apache Hadoop <3.3.4 - Privilege Escalation
CVSS 7.5
CVE-2023-39202
LOW
Zoom Rooms Client for Windows & Zoom VDI Client - DoS
CVSS 3.1
Details
Vulnerabilities
657
Exploit Likelihood
High