CWE-427

Uncontrolled Search Path Element

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

1,133 vulnerabilities with CWE-427
CVE-2025-20041 MEDIUM
Intel(R) Graphics <32.0.101.6325/32.0.101.6252 - Privilege Escalation
CVSS 6.7
CVE-2025-20015 MEDIUM
Intel(R) Ethernet Connection <29.4 - Privilege Escalation
CVSS 6.7
CVE-2025-32917 HIGH
Checkmk - Uncontrolled Search Path
CVSS 8.8
CVE-2025-35471 HIGH
Conda-forge Miniforge < 24.5.0 - Uncontrolled Search Path
CVSS 7.3
CVE-2025-4539 HIGH
Todesk - Uncontrolled Search Path
CVSS 7.0
CVE-2025-4532 HIGH
Shanghai Bairui Information Technology SunloginClient 15.8.3.19819 ...
CVSS 7.0
CVE-2025-4525 HIGH
Discord - Uncontrolled Search Path
CVSS 7.0
CVE-2025-4455 HIGH
Patch My PC Home Updater <5.1.3.0 - Uncontrolled Search Path
CVSS 7.0
CVE-2025-4272 HIGH
Mechrevo Control Console 1.0.2.70 - Uncontrolled Search Path
CVSS 7.0
CVE-2025-23177 HIGH
CWE-427 - Uncontrolled Search Path
CVSS 7.6
CVE-2025-2769 HIGH
Bdrive Netdrive - Uncontrolled Search Path
CVSS 7.8
CVE-2025-2768 HIGH
Bdrive Netdrive - Uncontrolled Search Path
CVSS 7.8
CVE-2025-43950 HIGH
DPMAdirektPro 4.1.5 - Privilege Escalation
CVSS 7.8
CVE-2025-32780 HIGH
BleachBit <4.6.2 - DLL Hijacking
CVSS 7.3
CVE-2025-29817 MEDIUM
Microsoft Power Automate For Desktop - Uncontrolled Search Path
CVSS 5.7
CVE-2025-29803 HIGH
Microsoft Sql Server Management Studio - Uncontrolled Search Path
CVSS 7.3
CVE-2025-2630 HIGH
NI LabVIEW <2025 Q1 - RCE
CVSS 7.3
CVE-2025-2629 HIGH
NI LabVIEW <2025 Q1 - RCE
CVSS 7.3
CVE-2025-29802 HIGH
Microsoft Visual Studio 2022 < 17.8.20 - Uncontrolled Search Path
CVSS 7.3
CVE-2025-22458 HIGH
Ivanti Endpoint Manager < 2022 - Uncontrolled Search Path
CVSS 7.8
CVE-2025-3051 MEDIUM
Linux::Statm::Tiny <0.0701 - RCE
CVSS 6.5
CVE-2025-30673 MEDIUM
Perl <0.050002 - RCE
CVSS 6.5
CVE-2025-30672 MEDIUM
Mite for Perl <0.013000 - Code Injection
CVSS 6.5
CVE-2025-26631 HIGH
Microsoft Visual Studio Code < 1.98.0 - Uncontrolled Search Path
CVSS 7.3
CVE-2025-25003 HIGH
Visual Studio - Privilege Escalation
CVSS 7.3
Details
Vulnerabilities 1,133