CWE-427

Uncontrolled Search Path Element

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

1,168 vulnerabilities with CWE-427
CVE-2025-14405 MEDIUM
PDFsam Enhanced - Privilege Escalation
CVSS 6.8
CVE-2025-53000 HIGH
jupyter/nbconvert <= 7.16.6 - Unauthenticated Remote Code Execution via SVG to PDF Conversion
CVSS 7.8
CVE-2025-13670 MEDIUM
Intel High Level Synthesis Compiler < 24.3 - DLL Planting via i++ Command
CVSS 6.7
CVE-2025-13669 MEDIUM
Intel High Level Synthesis Compiler 19.1-24.3 - Search Order Hijacking via Uncontrolled Search Path Element
CVSS 6.7
CVE-2025-13665 MEDIUM
Intel Quartus Prime < 24.1 - DLL Planting in System Console Utility
CVSS 6.7
CVE-2025-13668 MEDIUM
Intel Quartus Prime Pro Edition < 25.1 - Privilege Escalation via Uncontrolled Search Path
CVSS 6.7
CVE-2025-13664 MEDIUM
Intel Quartus Prime < 24.1 - Privilege Escalation via Uncontrolled Search Path Element
CVSS 6.7
CVE-2025-64995 MEDIUM
TeamViewer DEX < 3.4 - Privilege Escalation via 1E-Exchange-NomadClientHealth-ConfigureGeneralSetting Instruction
CVSS 6.5
CVE-2025-64994 MEDIUM
TeamViewer DEX < 17.1 - Privilege Escalation via Uncontrolled Search Path in 1E-Nomad-SetWorkRate
CVSS 6.5
CVE-2025-34424 HIGH
MailEnable < 10.54 - Uncontrolled Search Path Element via MEAIDP.DLL Loading
CVSS 7.8
CVE-2025-34423 HIGH
MailEnable < 10.54 - Uncontrolled Search Path Element via MEAIAU.DLL Loading
CVSS 7.8
CVE-2025-34422 HIGH
MailEnable < 10.54 - Uncontrolled Search Path Element via MEAIPC.DLL Loading
CVSS 7.8
CVE-2025-34421 HIGH
MailEnable < 10.54 - Uncontrolled Search Path Element via MEAISP.DLL Loading
CVSS 7.8
CVE-2025-34420 HIGH
MailEnable < 10.54 - Uncontrolled Search Path Element via MEAIAM.DLL Loading
CVSS 7.8
CVE-2025-34419 HIGH
MailEnable < 10.54 - Uncontrolled Search Path Element via MEAISM.DLL Loading
CVSS 7.8
CVE-2025-34418 HIGH
MailEnable < 10.54 - Uncontrolled Search Path Element via MEAIMF.DLL Loading
CVSS 7.8
CVE-2025-34417 HIGH
MailEnable < 10.54 - Uncontrolled Search Path Element via MEAISO.DLL Loading
CVSS 7.8
CVE-2025-34416 HIGH
MailEnable < 10.54 - Uncontrolled Search Path Element via MEAIPO.DLL Loading
CVSS 7.8
CVE-2025-13152 HIGH
Lenovo One Client - Privilege Escalation
CVSS 7.8
CVE-2025-12046 HIGH
Lenovo App Store/Browser - Privilege Escalation
CVSS 7.8
CVE-2025-65741 CRITICAL
Sublime Text 3 <3208 - Code Injection
CVSS 9.8
CVE-2025-34396 HIGH
MailEnable < 10.54 - Uncontrolled Search Path Element via MEAINFY.DLL Loading
CVSS 7.3
CVE-2025-5471 HIGH
Yandex Telemost <2.19.1 - Search Order Hijacking
CVSS 7.8
CVE-2025-5470 HIGH
Yandex Disk <3.2.45.3275 - Search Order Hijacking
CVE-2025-5469 HIGH
Yandex Messenger <2.245 - Search Order Hijacking
Details
Vulnerabilities 1,168