CWE-427

Uncontrolled Search Path Element

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

1,191 vulnerabilities with CWE-427
CVE-2026-2360 HIGH
PostgreSQL Anonymizer - Privilege Escalation
CVSS 8.0
CVE-2026-25656 HIGH
SINEC NMS < V4.0 SP3 and UMC < V2.15.2.1 - Uncontrolled Search Path Element
CVSS 7.8
CVE-2026-25655 HIGH
SINEC NMS < V4.0 SP2 - Uncontrolled Search Path Element via Configuration File Modification
CVSS 7.8
CVE-2026-23741 NONE
Asterisk <20.7-cert9, 20.18.2, 21.12.1, 22.8.2, 23.2.2 - Privilege ...
CVE-2026-23740 NONE
Sangoma Certified Asterisk - Uncontrolled Search Path Element via World-Writable Directory
CVE-2026-24694 HIGH
Roland Cloud Manager <3.1.19 - Code Injection
CVSS 7.8
CVE-2026-25129 MEDIUM
PsySH 0.11.0-0.11.22 and 0.12.0-0.12.18 - Unauthenticated Arbitrary Code Execution via Malicious .psysh.php File
CVSS 6.7
CVE-2026-21408 HIGH
beat-access <3.0.3 - Code Injection
CVSS 7.3
CVE-2026-0776 HIGH
Discord Client - Privilege Escalation
CVSS 7.3
CVE-2026-23755 HIGH
D-Link D-View 8 <2.0.1.107 - Code Injection
CVSS 7.3
CVE-2026-24016 HIGH
ServerView Agents for Windows - Uncontrolled Search Path Element
CVSS 7.8
CVE-2026-21427 HIGH
Pioneer Corporation - DLL Hijacking
CVSS 7.8
CVE-2025-13162 MEDIUM
ABB Control Builder A - Advant Master Online Builder DLL Vulnerability
CVSS 4.4
CVE-2025-41670 HIGH
Phoenix Contact AXC F 1152 - Untrusted Search Path
CVSS 7.8
CVE-2025-14575 LOW
Uncontrolled Search Path Element in Qt Network OpenSSL TLS backend allows rogue CA certificate loading
CVE-2025-62628 HIGH
AMD AIM-T Manageability Service - Uncontrolled Search Path Element via OpenSSL Initialization
CVE-2025-36515 MEDIUM
AI Playground software < 3.0.0 alpha - Uncontrolled Search Path Element
CVE-2025-35969 MEDIUM
Intel(R) Server Firmware Update Utility Software - Uncontrolled Search Path Element
CVE-2025-69599 CRITICAL
RayVentory Scan Engine through 12.6 Update 8 - Privilege Escalation
CVSS 9.8
CVE-2025-10549 MEDIUM
DLL Hijacking in EfficientLab Controlio Leads to Local Privilege Escalation
CVSS 5.1
CVE-2025-14821 HIGH
Libssh: libssh: insecure default configuration leads to local man-in-the-middle attacks on windows
CVSS 7.8
CVE-2025-69784 HIGH
OpenEDR 2.5.1.0 - Privilege Escalation
CVSS 8.8
CVE-2025-11792 HIGH
Acronis Cyber Protect Cloud Agent <41124 - Privilege Escalation
CVSS 7.3
CVE-2025-15558 HIGH
Docker CLI <=29.1.5 - Privilege Escalation
CVSS 8.0
CVE-2025-54519 HIGH
AMD Vivado Documentation Navigator Installation (Windows) - DLL Hijacking
CVSS 7.3
Details
Vulnerabilities 1,191