CWE-428

Unquoted Search Path or Element

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

451 vulnerabilities with CWE-428
CVE-2026-9128 HIGH
Rockwell Studio 5000 Logix Designer - Unquoted Search Path Code Execution
CVE-2026-8864 HIGH
HP Fan Control App – Potential Escalation of Privilege
CVE-2026-25865 HIGH
Punto Switcher 4.5.0.583 Unquoted Search Path via WinExec
CVSS 7.8
CVE-2026-7280 MEDIUM
eMPIA Technology|AVACAST - Unquoted Service Path
CVSS 6.7
CVE-2026-5789 HIGH
Search path without quotes in CivetWeb
CVSS 7.8
CVE-2026-34768 LOW
Electron: Unquoted executable path in app.setLoginItemSettings on Windows
CVSS 3.9
CVE-2026-33253 MEDIUM
SANYO DENKI SANUPS SOFTWARE 1.0.1-1.1.4 - Privilege Escalation
CVSS 6.7
CVE-2026-25866 HIGH
MobaXterm <26.1 - Uncontrolled Search Path
CVSS 7.8
CVE-2026-26034 HIGH
UPS MUMC 01.06.0001 - Privilege Escalation
CVSS 7.8
CVE-2026-26033 MEDIUM
UPS MUMC 01.06.0001 - Privilege Escalation
CVSS 6.7
CVE-2026-1585 MEDIUM
IJ Scan Utility 1.1.2-1.5.0 - Privilege Escalation
CVSS 6.7
CVE-2026-2542 HIGH
Total VPN 0.5.29.0 - Privilege Escalation
CVSS 7.0
CVE-2026-24466 MEDIUM
Oki Electric Industry Co., Ltd. - Privilege Escalation
CVSS 6.7
CVE-2025-71326 HIGH
AVAST Antivirus 25.11 Unquoted Service Path Privilege Escalation
CVSS 7.8
CVE-2025-41359 HIGH
Small HTTP Server 3.06.36 - Unquoted Service Path Code Execution
CVSS 7.8
CVE-2025-36384 HIGH
IBM Db2 for Windows <12.1.3 - Privilege Escalation
CVSS 8.4
CVE-2025-59888 MEDIUM
Eaton UPS Companion - Code Injection
CVSS 6.7
CVE-2025-14018 HIGH
NetBT Consulting Services Inc. E-Fatura <1.2.15 - Path Traversal
CVSS 7.3
CVE-2025-34499 MEDIUM
AnyDesk 7.0.15,9.0.1 - Code Injection
CVE-2025-66271 MEDIUM
ELECOM Clone for Windows < 2.36 - Unquoted Service Path Privilege Escalation
CVSS 6.7
CVE-2025-66461 MEDIUM
FULLBACK Manager Pro - Code Injection
CVSS 6.7
CVE-2025-66575 HIGH
VeeVPN 1.6.1 - Unquoted Service Path Remote Code Execution via VeePNService
CVSS 7.8
CVE-2025-66269 HIGH
UPSilon 2000 - Privilege Escalation
CVE-2025-66264 HIGH
CMService.exe - Privilege Escalation
CVE-2025-13433 HIGH
Muse Group MuseHub 2.1.0.1567 - Path Traversal
CVSS 7.0
Details
Vulnerabilities 451