CWE-427

Uncontrolled Search Path Element

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

1,191 vulnerabilities with CWE-427
CVE-2026-4545 HIGH
Flos Freeware Notepad2 PROPSYS.dll uncontrolled search path
CVSS 7.0
CVE-2026-33156 HIGH
DLL Sideloading in ScreenToGif
CVSS 7.8
CVE-2026-2713 HIGH
IBM Trusteer Rapport 3.5.2309.290 - DLL Hijacking
CVSS 7.4
CVE-2026-24317 MEDIUM
SAP GUI for Windows - DLL Hijacking
CVSS 5.0
CVE-2026-30896 HIGH
Qsee Client <=1.0.1 - DLL Hijacking
CVSS 7.8
CVE-2026-3787 HIGH
UltraVNC 1.6.4.0 - Untrusted Search Path in Windows Service
CVSS 7.0
CVE-2026-28712 MEDIUM
Acronis Cyber Protect 17 <41186 - Privilege Escalation
CVSS 6.3
CVE-2026-28711 MEDIUM
Acronis Cyber Protect 17 - Privilege Escalation
CVSS 6.3
CVE-2026-29610 HIGH
OpenClaw <2026.2.14 - Command Injection
CVSS 8.8
CVE-2026-28456 HIGH
OpenClaw 2026.1.5-2026.2.14 - Code Injection
CVSS 7.2
CVE-2026-22270 MEDIUM
Dell PowerScale OneFS <9.10.1.6/9.11.0.0-9.12.0.1 - Privilege Escal...
CVSS 6.7
CVE-2026-24502 HIGH
Dell Command | Intel vPro <4.7.0 - Privilege Escalation
CVSS 8.8
CVE-2026-25191 HIGH
FinalCode Ver.5 series < 5.43R01 and Ver.6 series < 6.51R01 - Uncontrolled Search Path Element via Installer DLL Loading
CVSS 7.8
CVE-2026-3091 MEDIUM
Synology Presto Client <2.1.3-0672 - DLL Hijacking
CVSS 6.7
CVE-2026-21420 HIGH
Dell Repository Manager <3.4.8 - Privilege Escalation
CVSS 7.3
CVE-2026-2492 HIGH
TensorFlow HDF5 Library - Privilege Escalation
CVSS 7.8
CVE-2026-2040 HIGH
PDF-XChange Editor - Privilege Escalation
CVSS 7.3
CVE-2026-26099 MEDIUM
Owl opds 2.2.0.4 - Uncontrolled Search Path Element via Crafted Network Request
CVSS 5.5
CVE-2026-26098 MEDIUM
Owl opds 2.2.0.4 - Uncontrolled Search Path Element via Crafted Network Request
CVSS 5.5
CVE-2026-26097 MEDIUM
Owl opds 2.2.0.4 - Uncontrolled Search Path Element via Crafted Network Request
CVSS 5.5
CVE-2026-26050 HIGH
RICOH Job Log Tool <1.3.7 - DLL Hijacking
CVSS 7.8
CVE-2026-2538 HIGH
Notepad2 4.2.22-4.2.25 - Path Traversal
CVSS 7.0
CVE-2026-2516 HIGH
Unidocs ezPDF DRM Reader/ezPDF Reader 2.0/3.0.0.4 - Path Traversal
CVSS 7.0
CVE-2026-25676 HIGH
M-Track Duo HD <1.0.0 - Code Injection
CVSS 7.8
CVE-2026-2361 HIGH
PostgreSQL Anonymizer < 3.0.1 - Privilege Escalation via Malicious Function in Temporary View
CVSS 8.0
Details
Vulnerabilities 1,191