CWE-427

Uncontrolled Search Path Element

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

1,133 vulnerabilities with CWE-427
CVE-2025-1700 HIGH
Motorola Software Fix - Privilege Escalation
CVSS 7.0
CVE-2025-7472 HIGH
Intercept X for Windows <1.22 - Privilege Escalation
CVSS 7.5
CVE-2025-34109 HIGH
Panda Security Products <16.1.2 - Code Injection
CVE-2025-48496 MEDIUM
Emerson ValveLink - SSRF
CVSS 5.1
CVE-2025-36004 HIGH
I - Uncontrolled Search Path
CVSS 8.8
CVE-2025-49144 HIGH
Notepad++ <8.8.1 - Privilege Escalation
CVSS 7.3
CVE-2025-4981 CRITICAL
Mattermost Server < 9.11.16 - Uncontrolled Search Path
CVSS 9.9
CVE-2025-5981 MEDIUM
Google Osv-scalibr < 0.1.8 - Path Traversal
CVSS 6.5
CVE-2025-49487 MEDIUM
Trendmicro Worry-free Business Securi... - Uncontrolled Search Path
CVSS 6.8
CVE-2025-49158 MEDIUM
Trendmicro Apex One < 14.0.14492 - Uncontrolled Search Path
CVSS 6.7
CVE-2025-49155 HIGH
Trendmicro Apex One < 14.0.14492 - Uncontrolled Search Path
CVSS 8.8
CVE-2025-33122 HIGH
IBM i <7.7 - Privilege Escalation
CVSS 7.5
CVE-2025-49148 HIGH
ClipShare <3.8.5 - RCE
CVSS 7.3
CVE-2025-5480 HIGH
Action1 - Privilege Escalation
CVSS 7.8
CVE-2025-30167 HIGH
Jupyter Core <5.8.0 - Info Disclosure
CVSS 7.3
CVE-2025-5180 HIGH
Wondershare Filmora - Uncontrolled Search Path
CVSS 7.0
CVE-2025-5129 HIGH
Sangfor Atrust - Uncontrolled Search Path
CVSS 7.0
CVE-2025-2272 HIGH
Forcepoint FIE Endpoint <25.05 - Privilege Escalation
CVSS 7.0
CVE-2025-27997 HIGH
Blizzard Battle.net - Uncontrolled Search Path
CVSS 8.4
CVE-2025-4769 HIGH
CBEWIN Anytxt Searcher 1.3.1128.0 - Uncontrolled Search Path
CVSS 7.0
CVE-2025-43553 HIGH
Adobe Substance 3D Modeler < 1.22.0 - Uncontrolled Search Path
CVSS 7.8
CVE-2025-21099 MEDIUM
Intel(R) Graphics - Privilege Escalation
CVSS 6.7
CVE-2025-20108 MEDIUM
Intel(R) Network Adapter Driver <29.4 - Privilege Escalation
CVSS 6.7
CVE-2025-20079 MEDIUM
Intel(R) Advisor - Privilege Escalation
CVSS 6.7
CVE-2025-20043 MEDIUM
Intel RealSense SDK <2.56.2 - Privilege Escalation
CVSS 6.7
Details
Vulnerabilities 1,133