CWE-427

Uncontrolled Search Path Element

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

1,191 vulnerabilities with CWE-427
CVE-2024-45710 HIGH
SolarWinds Platform < 2024.4 - Local Privilege Escalation via Uncontrolled Search Path Element
CVSS 7.8
CVE-2024-30117 LOW
HCL BigFix Platform 9.5-9.5.25 - Uncontrolled Search Path Element
CVSS 2.5
CVE-2024-9046 HIGH
Lenovo stARstudio < 2020.3.12.34806 - DLL Hijacking
CVSS 7.8
CVE-2024-4132 HIGH
Lenovo Lock Screen < 9.0.18 - DLL Hijacking
CVSS 7.8
CVE-2024-4131 HIGH
Lenovo Emulator < 9.1.6 - DLL Hijacking
CVSS 7.8
CVE-2024-4130 HIGH
Lenovo App Store < 9.0.17 - DLL Hijacking
CVSS 7.8
CVE-2024-4089 HIGH
Lenovo Super File - Privilege Escalation
CVSS 7.8
CVE-2024-33582 HIGH
Lenovo Service Framework - Privilege Escalation
CVSS 7.8
CVE-2024-33581 HIGH
Lenovo PC Manager AI - Privilege Escalation
CVSS 7.8
CVE-2024-33580 HIGH
Lenovo Personal Cloud - Privilege Escalation
CVSS 7.8
CVE-2024-33579 HIGH
Lenovo Baiying - Privilege Escalation
CVSS 7.8
CVE-2024-33578 HIGH
Lenovo Leyun - Privilege Escalation
CVSS 7.8
CVE-2024-47196 MEDIUM
ModelSim Questa < V2025.2 - Code Injection
CVSS 6.7
CVE-2024-47195 MEDIUM
ModelSim Questa < V2024.3 - Code Injection
CVSS 6.7
CVE-2024-47194 MEDIUM
ModelSim Questa < V2024.3 - Code Injection
CVSS 6.7
CVE-2024-45246 HIGH
Vynamic View < 5.9.5 - Uncontrolled Search Path Element
CVSS 7.3
CVE-2024-6769 MEDIUM
Microsoft Windows <2022 - Privilege Escalation
CVSS 6.7
CVE-2024-44168 MEDIUM
macOS < 13.7, < 14.7, < 15 - Unauthorized File System Modification via Library Injection
CVSS 5.5
CVE-2024-8766 MEDIUM
Acronis Cyber Protect <38235-39169 - Privilege Escalation
CVSS 6.7
CVE-2024-34016 MEDIUM
Acronis Cyber Protect Cloud Agent <38235 - Privilege Escalation
CVSS 6.5
CVE-2024-34153 MEDIUM
Intel(R) RAID Web Console - Privilege Escalation
CVSS 6.7
CVE-2024-39613 MEDIUM
Mattermost Desktop App <=5.8.0 - Uncontrolled Search Path Element via cmd.exe
CVSS 5.3
CVE-2024-20430 HIGH
Cisco Meraki Systems Manager - Code Injection
CVSS 7.3
CVE-2024-6510 HIGH
AVG Internet Security <24 - Privilege Escalation
CVSS 7.8
CVE-2024-8441 MEDIUM
Ivanti EPM <2022 SU6-2024 September - Privilege Escalation
CVSS 6.7
Details
Vulnerabilities 1,191