CWE-427

Uncontrolled Search Path Element

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

1,133 vulnerabilities with CWE-427
CVE-2025-10089 HIGH
MILCO.S Setting App - Code Injection
CVSS 7.7
CVE-2025-64726 HIGH
Socket Firewall <0.15.5 - RCE
CVE-2025-40827 HIGH
Siemens Software Center, Solid Edge SE2025 <V3.5-V225.0 Update 10 -...
CVSS 7.8
CVE-2025-40763 HIGH
Altair Grid Engine < V2026.0.0 - Code Injection
CVSS 7.8
CVE-2025-35972 MEDIUM
Intel MPI Library <2021.16 - Privilege Escalation
CVSS 6.7
CVE-2025-32038 MEDIUM
Intel oneAPI DPC++C++ Compiler <2025.0.1 - Privilege Escalation
CVSS 6.7
CVE-2025-32001 MEDIUM
Intel(R) Processor Identification Utility <8.0.43 - Privilege Escal...
CVSS 6.7
CVE-2025-31931 MEDIUM
ITT API <3.25.4 - Privilege Escalation
CVSS 6.7
CVE-2025-31647 MEDIUM
Intel(R) Graphics Software <25.22.1502.2 - Privilege Escalation
CVSS 6.7
CVE-2025-31645 MEDIUM
System Event Log Viewer Utility - Privilege Escalation
CVSS 6.7
CVE-2025-30506 MEDIUM
Intel Driver and Support Assistant <25.2 - Privilege Escalation
CVSS 6.7
CVE-2025-30182 MEDIUM
Intel(R) Distribution for Python <2025.2.0 - Privilege Escalation
CVSS 6.7
CVE-2025-25059 MEDIUM
Intel(R) OFU <14.1.31 - Privilege Escalation
CVSS 6.7
CVE-2025-24842 MEDIUM
Intel(R) System Support Utility <4.1.0 - Privilege Escalation
CVSS 6.7
CVE-2025-24491 MEDIUM
Intel(R) Killer(TM) Performance Suite <killer 4.0 40.25.509.1465 - ...
CVSS 6.7
CVE-2025-20065 MEDIUM
Display Virtualization for Windows OS <1797 - Privilege Escalation
CVSS 6.7
CVE-2025-20050 MEDIUM
Intel(R) CIP <WIN_DCA_2.4.0.11001 - Privilege Escalation
CVSS 6.7
CVE-2025-23358 HIGH
NVIDIA NVApp - Code Injection
CVSS 8.2
CVE-2025-11761 HIGH
HP Client Management Script Library < 1.8.5 - Uncontrolled Search Path
CVSS 7.8
CVE-2025-60749 HIGH
Trimble SketchUp desktop 2025 - Code Injection
CVSS 7.8
CVE-2025-61161 HIGH
Evope Collector <1.1.6.9.0 - Code Injection
CVSS 8.4
CVE-2025-62776 HIGH
WTW EAGLE <3.0.8.0 - Code Injection
CVSS 7.8
CVE-2025-10939 LOW
Org.keycloak Keycloak-quarkus-server - Uncontrolled Search Path
CVSS 3.7
CVE-2025-9164 HIGH
Docker Desktop <4.48.0 - Privilege Escalation
CVE-2025-11940 HIGH
LibreWolf <143.0.4-1 - Path Traversal
CVSS 7.0
Details
Vulnerabilities 1,133