CWE-427

Uncontrolled Search Path Element

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

1,133 vulnerabilities with CWE-427
CVE-2026-25852 MEDIUM
Acronis DeviceLock Dlp < 9.0.93212 - Privilege Escalation
CVSS 6.7
CVE-2026-41373 MEDIUM
OpenClaw < 2026.3.31 - Compiler Binary Substitution via Environment Variable Override in Host Execution Policy
CVSS 6.1
CVE-2026-7279 HIGH
eMPIA Technology|AVACAST - DLL Hijacking
CVSS 7.8
CVE-2026-42171 HIGH
Nullsoft Scriptable Install System <3.12 - Privilege Escalation
CVSS 7.8
CVE-2026-32172 HIGH
Microsoft Power Apps Remote Code Execution Vulnerability
CVSS 8.0
CVE-2026-34488 HIGH
i-PRO IP Setting Software <V5.20 - DLL Hijacking
CVSS 7.3
CVE-2026-32679 HIGH
Downloader5Installer.exe 1.0.0.0 - DLL Hijacking
CVSS 7.8
CVE-2026-40342 CRITICAL
Firebird: Path Traversal + Arbitrary File Write Leads to Remote Code Execution
CVSS 9.9
CVE-2026-6421 HIGH
Mobatek MobaXterm Home Edition msimg32.dll uncontrolled search path
CVSS 7.0
CVE-2026-22619 HIGH
Eaton IPP software <2.0 - Code Injection
CVSS 7.8
CVE-2026-34632 HIGH
Photoshop Installer | CWE-427: Uncontrolled Search Path Element
CVSS 8.2
CVE-2026-4134 HIGH
Lenovo Software Fix <7.5.5.19 - Privilege Escalation
CVSS 7.3
CVE-2026-1636 MEDIUM
Lenovo Service Bridge <5.0.2.20 - Privilege Escalation
CVSS 6.7
CVE-2026-5397 HIGH
Vulnerability Related to an Uncontrolled Search Path Element in a UPS Management Application
CVSS 7.8
CVE-2026-5055 HIGH
NoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
CVSS 7.8
CVE-2026-4158 HIGH
KeePassXC OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
CVSS 7.3
CVE-2026-28704 HIGH
Emocheck - DLL Hijacking
CVSS 7.8
CVE-2026-30478 HIGH
GatewayGeo MapServer for Windows 5 - Privilege Escalation via DLL Injection
CVSS 8.8
CVE-2026-40031 HIGH
MemProcFS < 5.17 DLL/Shared Library Hijacking
CVSS 7.8
CVE-2026-28728 MEDIUM
Acronis True Image < 42902 - Privilege Escalation
CVSS 6.7
CVE-2026-27774 MEDIUM
Acronis True Image < 42902 - Privilege Escalation
CVSS 6.7
CVE-2026-5271 HIGH
Possible to hijack modules in current working directory
CVSS 7.8
CVE-2026-3775 HIGH
Foxit PDF Editor/Reader Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
CVSS 7.8
CVE-2026-22561 HIGH
Anthropic Claude Desktop - Windows < 1.1.3363 - Privilege Escalation
CVSS 7.8
CVE-2026-34054 HIGH
openssl on Windows built with openssldir set from the build machine (Uncontrolled Search Path Element)
CVSS 7.8
Details
Vulnerabilities 1,133