The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
1,191 vulnerabilities with CWE-427
CVE-2026-2360
HIGH
PostgreSQL Anonymizer - Privilege Escalation
CVSS 8.0
CVE-2026-25656
HIGH
SINEC NMS < V4.0 SP3 and UMC < V2.15.2.1 - Uncontrolled Search Path Element
CVSS 7.8
CVE-2026-25655
HIGH
SINEC NMS < V4.0 SP2 - Uncontrolled Search Path Element via Configuration File Modification
CVSS 7.8
CVE-2026-23741
NONE
Asterisk <20.7-cert9, 20.18.2, 21.12.1, 22.8.2, 23.2.2 - Privilege ...
CVE-2026-23740
NONE
Sangoma Certified Asterisk - Uncontrolled Search Path Element via World-Writable Directory
CVE-2026-24694
HIGH
Roland Cloud Manager <3.1.19 - Code Injection
CVSS 7.8
CVE-2026-25129
MEDIUM
PsySH 0.11.0-0.11.22 and 0.12.0-0.12.18 - Unauthenticated Arbitrary Code Execution via Malicious .psysh.php File
CVSS 6.7
CVE-2026-21408
HIGH
beat-access <3.0.3 - Code Injection
CVSS 7.3
CVE-2026-0776
HIGH
Discord Client - Privilege Escalation
CVSS 7.3
CVE-2026-23755
HIGH
D-Link D-View 8 <2.0.1.107 - Code Injection
CVSS 7.3
CVE-2026-24016
HIGH
ServerView Agents for Windows - Uncontrolled Search Path Element
CVSS 7.8
CVE-2026-21427
HIGH
Pioneer Corporation - DLL Hijacking
CVSS 7.8
CVE-2025-13162
MEDIUM
ABB Control Builder A - Advant Master Online Builder DLL Vulnerability
CVSS 4.4
CVE-2025-41670
HIGH
Phoenix Contact AXC F 1152 - Untrusted Search Path
CVSS 7.8
CVE-2025-14575
LOW
Uncontrolled Search Path Element in Qt Network OpenSSL TLS backend allows rogue CA certificate loading
CVE-2025-62628
HIGH
AMD AIM-T Manageability Service - Uncontrolled Search Path Element via OpenSSL Initialization
CVE-2025-36515
MEDIUM
AI Playground software < 3.0.0 alpha - Uncontrolled Search Path Element
CVE-2025-35969
MEDIUM
Intel(R) Server Firmware Update Utility Software - Uncontrolled Search Path Element
CVE-2025-69599
CRITICAL
RayVentory Scan Engine through 12.6 Update 8 - Privilege Escalation
CVSS 9.8
CVE-2025-10549
MEDIUM
DLL Hijacking in EfficientLab Controlio Leads to Local Privilege Escalation
CVSS 5.1
CVE-2025-14821
HIGH
Libssh: libssh: insecure default configuration leads to local man-in-the-middle attacks on windows
CVSS 7.8
CVE-2025-69784
HIGH
OpenEDR 2.5.1.0 - Privilege Escalation
CVSS 8.8
CVE-2025-11792
HIGH
Acronis Cyber Protect Cloud Agent <41124 - Privilege Escalation
CVSS 7.3
CVE-2025-15558
HIGH
Docker CLI <=29.1.5 - Privilege Escalation
CVSS 8.0
CVE-2025-54519
HIGH
AMD Vivado Documentation Navigator Installation (Windows) - DLL Hijacking
CVSS 7.3
Details
Vulnerabilities
1,191