CWE-427

Uncontrolled Search Path Element

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

1,191 vulnerabilities with CWE-427
CVE-2025-20108 MEDIUM
Intel(R) Network Adapter Driver <29.4 - Privilege Escalation
CVSS 6.7
CVE-2025-20079 MEDIUM
Intel(R) Advisor - Privilege Escalation
CVSS 6.7
CVE-2025-20043 MEDIUM
Intel RealSense SDK <2.56.2 - Privilege Escalation
CVSS 6.7
CVE-2025-20041 MEDIUM
Intel(R) Graphics <32.0.101.6325/32.0.101.6252 - Privilege Escalation
CVSS 6.7
CVE-2025-20015 MEDIUM
Intel(R) Ethernet Connection <29.4 - Privilege Escalation
CVSS 6.7
CVE-2025-32917 HIGH
Checkmk < 2.4.0b7, < 2.3.0p32, < 2.2.0p42, 2.1.0p49 - Privilege Escalation via jar_signature Agent Plugin
CVSS 8.8
CVE-2025-35471 HIGH
conda-forge miniforge < 24.5.0 and openssl-feedstock < 2024-05-20 - Uncontrolled Search Path Element in OPENSSLDIR
CVSS 7.3
CVE-2025-4539 HIGH
ToDesk 4.7.6.3 - Uncontrolled Search Path Element in profapi.dll
CVSS 7.0
CVE-2025-4532 HIGH
Shanghai Bairui Information Technology SunloginClient 15.8.3.19819 ...
CVSS 7.0
CVE-2025-4525 HIGH
Discord 1.0.9188 - Uncontrolled Search Path Element in WINSTA.dll
CVSS 7.0
CVE-2025-4455 HIGH
Patch My PC Home Updater <5.1.3.0 - Uncontrolled Search Path
CVSS 7.0
CVE-2025-4272 HIGH
Mechrevo Control Console 1.0.2.70 - Uncontrolled Search Path
CVSS 7.0
CVE-2025-23177 HIGH
Ribbon Communications Apollo 9608 - Uncontrolled Search Path Element
CVSS 7.6
CVE-2025-2769 HIGH
Bdrive NetDrive - Local Privilege Escalation via OpenSSL Configuration File
CVSS 7.8
CVE-2025-2768 HIGH
Bdrive NetDrive - Local Privilege Escalation via OpenSSL Configuration File
CVSS 7.8
CVE-2025-43950 HIGH
DPMAdirektPro 4.1.5 - Privilege Escalation
CVSS 7.8
CVE-2025-32780 HIGH
BleachBit < 4.9.0 - Unauthenticated DLL Hijacking via uuid.dll in WindowsApps Directory
CVSS 7.3
CVE-2025-29817 MEDIUM
Power Automate for Desktop < 2.51.349.24355 - Authenticated Information Disclosure via Uncontrolled Search Path Element
CVSS 5.7
CVE-2025-29803 HIGH
SQL Server Management Studio < 20.2.1 - Privilege Escalation via Uncontrolled Search Path
CVSS 7.3
CVE-2025-2630 HIGH
NI LabVIEW < 2025 Q1 - Uncontrolled Search Path Element
CVSS 7.3
CVE-2025-2629 HIGH
NI LabVIEW < 2025 Q1 - DLL Hijacking via Uncontrolled Search Path
CVSS 7.3
CVE-2025-29802 HIGH
Visual Studio 2022 17.8.0-17.8.19 - Authenticated Privilege Escalation via Uncontrolled Search Path Element
CVSS 7.3
CVE-2025-22458 HIGH
Ivanti Endpoint Manager < 2024 SU1 and < 2022 SU7 - Authenticated DLL Hijacking
CVSS 7.8
CVE-2025-3051 MEDIUM
Linux::Statm::Tiny < 0.0701 - Untrusted Code Execution via Current Working Directory
CVSS 6.5
CVE-2025-30673 MEDIUM
Sub::HandlesVia < 0.050002 - Untrusted Code Loading via Current Working Directory
CVSS 6.5
Details
Vulnerabilities 1,191