The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
1,191 vulnerabilities with CWE-427
CVE-2026-48388
HIGH
Photoshop Installer | CWE-427: Uncontrolled Search Path Element
CVSS 8.6
CVE-2026-8164
HIGH
Search Order Hijacking in ArkSigner's ArkSigner Desktop Client
CVSS 7.3
CVE-2026-16519
HIGH
GeoVision GV-IP Device Utility DLL Search Order Hijacking Vulnerability
CVSS 7.3
CVE-2026-21770
MEDIUM
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to DLL hijacking
CVSS 6.5
CVE-2026-5674
HIGH
Pipewire: pipewire: sandbox escape and arbitrary code execution via malicious library loading
CVSS 8.8
CVE-2026-42936
HIGH
SBI Securities Co.,ltd. Hyper Sbi 2 < ver.3.20.0 - Uncontrolled Search Path Element
CVSS 7.8
CVE-2026-48272
HIGH
Creative Cloud Desktop | Uncontrolled Search Path Element (CWE-427)
CVSS 7.8
CVE-2026-0487
HIGH
SAProuter on Windows - Unauthenticated DLL Hijacking Code Execution
CVSS 8.4
CVE-2026-48364
HIGH
ColdFusion | Uncontrolled Search Path Element (CWE-427)
CVSS 8.2
CVE-2026-48363
HIGH
ColdFusion | Uncontrolled Search Path Element (CWE-427)
CVSS 8.2
CVE-2026-15515
HIGH
Tencent PC Manager QMUDisk Driver qmudisk64.sys uncontrolled search path
CVSS 7.0
CVE-2026-57239
HIGH
Foxit PDF Editor/Reader Local Privilege Escalation
CVSS 8.2
CVE-2026-56437
HIGH
Fuji Electric Co.,ltd. Pupsman - Uncontrolled Search Path Element
CVSS 7.8
CVE-2026-38972
HIGH
Notepad3 <= 6.25.822.1 - DLL Search-Order Hijacking via MSFTEDIT.DLL Load in About Dialog
CVSS 7.8
CVE-2026-54672
HIGH
electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`
CVSS 7.8
CVE-2026-54232
HIGH
vLLM < 0.22.1 Dockerfile - Dependency Confusion Code Execution
CVSS 8.8
CVE-2026-49241
HIGH
Angular: Multiple Remote Code Execution Vulnerabilities in Angular Language Service VS Code Extension
CVSS 8.8
CVE-2026-6645
HIGH
PaperCut Print Deploy Client for Windows 1.10.4178 - SYSTEM Privilege Escalation
CVE-2026-11958
HIGH
Local privilege escalation in ANSSI’s DFIR-ORC
CVE-2026-12003
MEDIUM
CPython >3.11 Insecure Input Validation resulting in privilege escalation
CVE-2026-5064
HIGH
HP One Agent Software – Security Update
CVE-2026-50100
HIGH
Ricoh Company, Ltd. Multiple Printer Drivers - Uncontrolled Search Path Element
CVSS 7.8
CVE-2026-11967
HIGH
Arbitrary code execution in MobaXterm Personal Edition (Portable)
CVE-2026-11879
HIGH
Arbitrary code execution in MobaXterm Personal Edition (Portable)
CVE-2026-53813
HIGH
OpenClaw < 2026.4.25 - Arbitrary Artifact Loading via Fake Package Root Resolution
CVSS 7.8
Details
Vulnerabilities
1,191