CWE-427

Uncontrolled Search Path Element

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

1,191 vulnerabilities with CWE-427
CVE-2026-48388 HIGH
Photoshop Installer | CWE-427: Uncontrolled Search Path Element
CVSS 8.6
CVE-2026-8164 HIGH
Search Order Hijacking in ArkSigner's ArkSigner Desktop Client
CVSS 7.3
CVE-2026-16519 HIGH
GeoVision GV-IP Device Utility DLL Search Order Hijacking Vulnerability
CVSS 7.3
CVE-2026-21770 MEDIUM
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to DLL hijacking
CVSS 6.5
CVE-2026-5674 HIGH
Pipewire: pipewire: sandbox escape and arbitrary code execution via malicious library loading
CVSS 8.8
CVE-2026-42936 HIGH
SBI Securities Co.,ltd. Hyper Sbi 2 < ver.3.20.0 - Uncontrolled Search Path Element
CVSS 7.8
CVE-2026-48272 HIGH
Creative Cloud Desktop | Uncontrolled Search Path Element (CWE-427)
CVSS 7.8
CVE-2026-0487 HIGH
SAProuter on Windows - Unauthenticated DLL Hijacking Code Execution
CVSS 8.4
CVE-2026-48364 HIGH
ColdFusion | Uncontrolled Search Path Element (CWE-427)
CVSS 8.2
CVE-2026-48363 HIGH
ColdFusion | Uncontrolled Search Path Element (CWE-427)
CVSS 8.2
CVE-2026-15515 HIGH
Tencent PC Manager QMUDisk Driver qmudisk64.sys uncontrolled search path
CVSS 7.0
CVE-2026-57239 HIGH
Foxit PDF Editor/Reader Local Privilege Escalation
CVSS 8.2
CVE-2026-56437 HIGH
Fuji Electric Co.,ltd. Pupsman - Uncontrolled Search Path Element
CVSS 7.8
CVE-2026-38972 HIGH
Notepad3 <= 6.25.822.1 - DLL Search-Order Hijacking via MSFTEDIT.DLL Load in About Dialog
CVSS 7.8
CVE-2026-54672 HIGH
electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`
CVSS 7.8
CVE-2026-54232 HIGH
vLLM < 0.22.1 Dockerfile - Dependency Confusion Code Execution
CVSS 8.8
CVE-2026-49241 HIGH
Angular: Multiple Remote Code Execution Vulnerabilities in Angular Language Service VS Code Extension
CVSS 8.8
CVE-2026-6645 HIGH
PaperCut Print Deploy Client for Windows 1.10.4178 - SYSTEM Privilege Escalation
CVE-2026-11958 HIGH
Local privilege escalation in ANSSI’s DFIR-ORC
CVE-2026-12003 MEDIUM
CPython >3.11 Insecure Input Validation resulting in privilege escalation
CVE-2026-5064 HIGH
HP One Agent Software – Security Update
CVE-2026-50100 HIGH
Ricoh Company, Ltd. Multiple Printer Drivers - Uncontrolled Search Path Element
CVSS 7.8
CVE-2026-11967 HIGH
Arbitrary code execution in MobaXterm Personal Edition (Portable)
CVE-2026-11879 HIGH
Arbitrary code execution in MobaXterm Personal Edition (Portable)
CVE-2026-53813 HIGH
OpenClaw < 2026.4.25 - Arbitrary Artifact Loading via Fake Package Root Resolution
CVSS 7.8
Details
Vulnerabilities 1,191