CWE-428

Unquoted Search Path or Element

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

451 vulnerabilities with CWE-428
CVE-2021-47762 HIGH
HTTPDebuggerPro 9.11 - Code Injection
CVSS 7.8
CVE-2021-47739 HIGH
Epic Games Easy Anti-Cheat 4.0 - Code Injection
CVSS 8.4
CVE-2021-26735 MEDIUM
Zscaler Client Connector < 3.6 - Unquoted Search Path Privilege Escalation
CVSS 6.7
CVE-2021-43463 HIGH
Ext2Fsd v0.68 - Unquoted Service Path
CVSS 7.8
CVE-2021-43460 HIGH
System Explorer 7.0.0 - Privilege Escalation
CVSS 7.8
CVE-2021-43458 HIGH
Vembu BDR 4.2.0.1 - Unquoted Service Path
CVSS 7.8
CVE-2021-43457 HIGH
bVPN 2.5.1 - Unquoted Service Path in waselvpnserv
CVSS 7.8
CVE-2021-43456 HIGH
Rumble Mail Server 0.51.3135 - Buffer Overflow
CVSS 7.8
CVE-2021-43455 HIGH
freelan 2.2 - Unquoted Service Path
CVSS 7.8
CVE-2021-43454 HIGH
AnyTXT Searcher <1.2.394 - Buffer Overflow
CVSS 7.8
CVE-2021-45819 MEDIUM
Wordline HIDCCEMonitorSVC <5.2.4.3 - Privilege Escalation
CVSS 6.4
CVE-2021-46368 HIGH
TRIGONE Remote System Monitor <3.61 - Privilege Escalation
CVSS 7.8
CVE-2021-29218 MEDIUM
HPE Agentless Mgmt Svcs <1.44.0.0 - Privilege Escalation
CVSS 6.7
CVE-2021-45460 HIGH
SICAM PQ Analyzer Firmware < 3.18 - Unquoted Service Path Hijacking
CVSS 8.1
CVE-2021-25269 MEDIUM
Sophos Intercept X Advanced <2.0.23 - Privilege Escalation
CVSS 4.4
CVE-2021-23197 MEDIUM
Gallagher Command Centre <8.50.2048 - RCE
CVSS 5.2
CVE-2021-33095 HIGH
Intel(R) NUC M15 Laptop Kit Keyboard LED Service <1.0.0.4 - Privile...
CVSS 7.8
CVE-2021-42563 HIGH
NI Service Locator <18.0 - Privilege Escalation
CVSS 7.8
CVE-2021-35231 MEDIUM
Kiwi Syslog Server - Privilege Escalation
CVSS 6.7
CVE-2021-40683 HIGH
Akamai EAA Client <2.3.1-2.5.3 - Path Traversal
CVSS 7.8
CVE-2021-35056 MEDIUM
Unisys Stealth <5.1.025.0, <6.0.055.0 - Info Disclosure
CVSS 6.7
CVE-2021-35469 HIGH
Lexmark Printer Software - Privilege Escalation
CVSS 7.8
CVE-2021-0112 HIGH
Intel Unite(R) Client <4.2.25031 - Privilege Escalation
CVSS 7.3
CVE-2021-31776 HIGH
Aviatrix VPN Client < 2.14.14 - Local Privilege Escalation via Unquoted Search Path
CVSS 7.8
CVE-2021-31553 MEDIUM
MediaWiki < 1.35.2 - Denial of Service via CheckUser Extension Username Handling
CVSS 6.5
Details
Vulnerabilities 451