CWE-427

Uncontrolled Search Path Element

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

1,191 vulnerabilities with CWE-427
CVE-2023-3662 HIGH
CODESYS Development System 3.5.17.0-3.5.19.19 - Uncontrolled Search Path Element
CVSS 7.3
CVE-2023-36853 HIGH
Keysight Geolocation Server <v2.4.2 - Code Injection
CVSS 7.8
CVE-2023-37849 MEDIUM
Panda Security VPN < 15.14.8 - DLL Hijacking via Crafted DLL in Executable Directory
CVSS 6.5
CVE-2023-31543 CRITICAL
pipreqs 0.3.0-0.4.11 - Dependency Confusion via PyPI Package Upload
CVSS 9.8
CVE-2023-28929 HIGH
Trend Micro Security <2023 - DLL Hijacking
CVSS 7.8
CVE-2023-2005 MEDIUM
Tenable Nessus, SecurityCenter, Tenable.io - Uncontrolled Search Path Element
CVSS 6.3
CVE-2023-27908 HIGH
Autodesk Installer 1.29.0.90-1.39.0.216 - Privilege Escalation via DLL Parsing
CVSS 7.8
CVE-2023-0142 MEDIUM
Synology DSM <7.1 - Privilege Escalation
CVSS 6.5
CVE-2023-0976 MEDIUM
Trellix Agent < 5.7.9 - Uncontrolled Search Path Element via TA Deployment Feature
CVSS 6.3
CVE-2023-3091 HIGH
Captura <8.0.0 - Uncontrolled Search Path
CVSS 7.0
CVE-2023-28080 MEDIUM
Dell PowerPath 7.0-7.2 - DLL Hijacking and Privilege Escalation
CVSS 6.7
CVE-2023-25005 HIGH
Autodesk InfraWorks 2021.0-2021.2 and 2023 - Resource Injection via Malicious DLL File
CVSS 7.8
CVE-2023-25428 HIGH
Soft-o Free Password Manager 1.1.20 - DLL Hijacking
CVSS 7.8
CVE-2023-31197 MEDIUM
Intel(R) Trace Analyzer and Collector <2020-3 - Privilege Escalation
CVSS 6.7
CVE-2023-27386 MEDIUM
Intel Pathfinder for RISC-V - Uncontrolled Search Path Privilege Escalation via Local Access
CVSS 6.7
CVE-2023-27298 HIGH
Intel(R) WULT <1.0.0 - Privilege Escalation
CVSS 8.8
CVE-2023-22355 MEDIUM
Intel oneAPI Toolkit <4.3.0.251 - Privilege Escalation
CVSS 6.7
CVE-2023-30237 HIGH
CyberGhost < 8.3.10.10015 - DLL Injection via Dashboard.exe
CVSS 7.8
CVE-2023-2355 HIGH
Acronis Snap Deploy <3900 - Privilege Escalation
CVSS 7.8
CVE-2023-29012 HIGH
Git for Windows <2.40.1 - Code Injection
CVSS 7.2
CVE-2023-29011 HIGH
Git for Windows < 2.40.1 - Uncontrolled Search Path Element via connect.exe Config File
CVSS 7.5
CVE-2023-28140 MEDIUM
Qualys Cloud Agent < 4.5.3.1 - Uncontrolled Search Path Element via DLL Hijacking
CVSS 6.7
CVE-2023-29187 MEDIUM
SapSetup <9.0 - Privilege Escalation
CVSS 6.7
CVE-2023-1745 MEDIUM
KMPlayer 4.2.2.73 - Uncontrolled Search Path Element in SHFOLDER.dll
CVSS 5.3
CVE-2023-0213 HIGH
M-Files Installer <22.6 - Privilege Escalation
CVSS 8.8
Details
Vulnerabilities 1,191