CWE-426

High likelihood

Untrusted Search Path

Parent: CWE-642 - External Control of Critical State Data

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

626 vulnerabilities with CWE-426
CVE-2023-27763 HIGH
Wondershare Mobiletrans - Untrusted Search Path
CVSS 7.8
CVE-2023-27762 HIGH
Wondershare Democreator - Untrusted Search Path
CVSS 7.8
CVE-2023-27761 HIGH
Wondershare Uniconverter - Untrusted Search Path
CVSS 7.8
CVE-2023-27760 HIGH
Wondershare Filmora - Untrusted Search Path
CVSS 7.8
CVE-2023-27759 HIGH
Wondershare Edrawmind - Untrusted Search Path
CVSS 7.8
CVE-2023-26358 HIGH
Creative Cloud <5.9.1 - RCE
CVSS 8.6
CVE-2023-26038 MEDIUM
ZoneMinder <1.36.33-1.37.33 - Local File Inclusion
CVSS 5.4
CVE-2023-26036 HIGH
ZoneMinder <1.36.33-1.37.33 - Local File Inclusion
CVSS 8.1
CVE-2023-23920 MEDIUM
Node.js <19.6.1-<14.21.3 - Privilege Escalation
CVSS 4.2
CVE-2023-22368 HIGH
ELECOM Camera Assistant <1.00-QuickFileDealer <1.2.1 - Privilege Es...
CVSS 7.8
CVE-2023-23618 HIGH
Git For Windows < 2.39.2 - Untrusted Search Path
CVSS 8.6
CVE-2023-22743 HIGH
Git For Windows < 2.39.2 - Untrusted Search Path
CVSS 7.2
CVE-2023-21764 HIGH
Microsoft Exchange Server - Privilege Escalation
CVSS 7.8
CVE-2023-21763 HIGH
Microsoft Exchange Server - Privilege Escalation
CVSS 7.8
CVE-2022-4987 HIGH
Hirschmann Industrial HiVision External Application Path Hijacking Leading to Arbitrary Code Execution
CVSS 7.3
CVE-2022-43456 MEDIUM
Intel(R) RST <16.8.5.1014.5-19.5.2.1049.5 - Privilege Escalation
CVSS 6.7
CVE-2022-35868 MEDIUM
TIA Multiuser Server/V15.1-Project-Server V17 - Privilege Escalation
CVSS 6.7
CVE-2022-4883 HIGH
LibXpm - Path Traversal
CVSS 8.8
CVE-2022-41953 HIGH
Git < 2.39.1 - Untrusted Search Path
CVSS 8.6
CVE-2022-38060 HIGH
OpenStack Kolla - Privilege Escalation
CVSS 8.8
CVE-2022-23748 HIGH KEV
mDNSResponder.exe - DLL Sideloading
CVSS 7.8
CVE-2022-31253 HIGH
openSUSE Factory openldap2 <2.6.3-404.1 - Privilege Escalation
CVSS 7.1
CVE-2022-3734 MEDIUM
Redis - Untrusted Search Path
CVSS 6.3
CVE-2022-0074 HIGH
Litespeedtech Openlitespeed < 1.7.16.1 - Untrusted Search Path
CVSS 8.8
CVE-2022-39245 HIGH
Mist <0.9.5 - Command Injection
CVSS 8.4
Details
Vulnerabilities 626
Exploit Likelihood High