CWE-427

Uncontrolled Search Path Element

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

1,191 vulnerabilities with CWE-427
CVE-2024-21818 MEDIUM
Intel(R) PCM <202311 - Privilege Escalation
CVSS 6.7
CVE-2024-21814 MEDIUM
Intel Chipset Device Software < 10.1.19444.8378 - Authenticated Privilege Escalation via Uncontrolled Search Path
CVSS 6.7
CVE-2024-21788 MEDIUM
Intel Graphics Performance Analyzers < 2023.4 - Authenticated Privilege Escalation via Uncontrolled Search Path
CVSS 6.7
CVE-2024-21777 MEDIUM
Intel Quartus Prime < 23.4 - Authenticated Privilege Escalation via Uncontrolled Search Path
CVSS 6.7
CVE-2024-21774 MEDIUM
Intel(R) Processor Identification Utility <6.10.34.1129, 7.1.6 - Pr...
CVSS 6.7
CVE-2024-21772 MEDIUM
Intel Advisor < 2024.0 - Authenticated Privilege Escalation via Uncontrolled Search Path
CVSS 6.7
CVE-2024-20366 HIGH
Cisco Crosswork NSO - Privilege Escalation
CVSS 7.8
CVE-2024-2637 HIGH
B&R Industrial Automation - Buffer Overflow
CVSS 7.2
CVE-2024-25050 HIGH
IBM Rational Developer for i and IBM i - Uncontrolled Search Path Element
CVSS 8.4
CVE-2024-33672 HIGH
Veritas NetBackup < 10.4 - Arbitrary File Deletion via Multi-Threaded Agent
CVSS 7.7
CVE-2024-28099 HIGH
VT STUDIO < 8.32 - Uncontrolled Search Path Element
CVSS 7.8
CVE-2024-22450 HIGH
Dell Alienware Command Center <6.2.7.0 - Code Injection
CVSS 7.4
CVE-2024-29734 HIGH
SonicDICOM Media Viewer <2.3.2 - Code Injection
CVSS 7.8
CVE-2024-0980 HIGH
Okta Verify for Windows < 4.10.7 - Arbitrary Code Execution via Auto-Update Service
CVSS 7.1
CVE-2024-28131 HIGH
EasyRange Ver 1.41 - Code Injection
CVSS 7.8
CVE-2024-22346 HIGH
Db2 for IBM i <7.6 - Privilege Escalation
CVSS 8.4
CVE-2024-22167 HIGH
SanDisk PrivateAccess Windows App < 6.4.10 - DLL Hijacking
CVSS 7.9
CVE-2024-0670 HIGH
Checkmk <2.2.0p23-2.0.0 - Privilege Escalation
CVSS 8.8
CVE-2024-27303 HIGH
electron-builder <24.13.2 - Command Injection
CVSS 7.3
CVE-2024-20338 HIGH
Cisco Secure Client for Linux - Privilege Escalation
CVSS 7.3
CVE-2024-1595 HIGH
Delta Electronics CNCSoft-B and DOPSoft < 4.0.0.82 - DLL Hijacking via Insecure Library Loading
CVSS 7.8
CVE-2024-23054 CRITICAL
Plone Docker Official Image 5.2.13 - Remote Code Execution via Missing npm Package in Static Components
CVSS 9.8
CVE-2024-23940 HIGH
Trend Micro Security 2023 < 6.0.2103 - DLL Hijacking via uiAirSupport
CVSS 7.8
CVE-2023-52945 HIGH
Synology BeeDrive For Desktop < 1.3.2-13814 - Uncontrolled Search Path Element
CVSS 7.8
CVE-2023-53959 CRITICAL
FileZilla Client 3.63.1 - Code Injection
CVSS 9.8
Details
Vulnerabilities 1,191