CWE-427

Uncontrolled Search Path Element

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

1,191 vulnerabilities with CWE-427
CVE-2025-30672 MEDIUM
Mite for Perl <0.013000 - Code Injection
CVSS 6.5
CVE-2025-26631 HIGH
Visual Studio Code < 1.98.0 - Authenticated Privilege Escalation via Uncontrolled Search Path Element
CVSS 7.3
CVE-2025-25003 HIGH
Visual Studio - Privilege Escalation
CVSS 7.3
CVE-2025-24998 HIGH
Visual Studio - Privilege Escalation
CVSS 7.3
CVE-2025-1804 HIGH
Blizzard Battle.Net <2.39.0.15212 - Path Traversal
CVSS 7.0
CVE-2025-1223 MEDIUM
Citrix Secure Access Client for Mac - Privilege Escalation
CVSS 6.1
CVE-2025-26624 MEDIUM
Rufus <4.6.2208 - Privilege Escalation
CVE-2025-24039 HIGH
Visual Studio Code < 1.97.1 - Elevation of Privilege via Uncontrolled Search Path Element
CVSS 7.3
CVE-2025-21206 HIGH
Visual Studio 2017, 2019, 2022 - Elevation of Privilege via Uncontrolled Search Path
CVSS 7.3
CVE-2025-21127 HIGH
Adobe Photoshop 25.0-25.12, 26.0-26.1 - Uncontrolled Search Path Element via Environment Variable Manipulation
CVSS 7.8
CVE-2025-0069 HIGH
SAPSetup - Uncontrolled Search Path Element
CVSS 7.8
CVE-2024-22451 MEDIUM
Dell Peripheral Manager < 1.7.3 or later - Uncontrolled Search Path Element
CVSS 6.7
CVE-2024-22447 MEDIUM
Dell Peripheral Manager < 1.7.3 or later - Uncontrolled Search Path Element
CVSS 6.7
CVE-2024-36333 HIGH
AMD Cleanup Utility - DLL Hijacking
CVSS 7.8
CVE-2024-47091 HIGH
Privilege escalation via mk_mysql agent plugin on Windows
CVSS 7.8
CVE-2024-13976 HIGH
Commvault for Windows <11.20.0-11.36.0 - Code Injection
CVE-2024-24916 MEDIUM
Check Point SmartConsole - Uncontrolled Search Path Element
CVSS 6.5
CVE-2024-42191 MEDIUM
HCL Traveler for Microsoft Outlook < 3.0.12 - COM Hijacking via Uncontrolled Search Path Element
CVSS 6.5
CVE-2024-42190 MEDIUM
HCL Traveler for Microsoft Outlook < 3.0.12 - DLL Hijacking
CVSS 6.5
CVE-2024-13946 MEDIUM
ASPECT-Enterprise <3.* - Binary Planting
CVSS 6.8
CVE-2024-47800 MEDIUM
Intel(R) Graphics Driver - Privilege Escalation
CVSS 6.7
CVE-2024-47795 MEDIUM
Intel(R) oneAPI DPC++/C++ Compiler <2025.0.0 - Privilege Escalation
CVSS 6.7
CVE-2024-46895 MEDIUM
Intel Arc & Iris Xe Graphics <32.0.101.6083 - Privilege Escalation
CVSS 6.7
CVE-2024-39833 MEDIUM
Intel(R) QAT <2.3.0 - Privilege Escalation
CVSS 6.7
CVE-2024-31073 MEDIUM
Intel(R) oneAPI Level Zero - Privilege Escalation
CVSS 6.7
Details
Vulnerabilities 1,191