CWE-428

Unquoted Search Path or Element

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

451 vulnerabilities with CWE-428
CVE-2020-36976 HIGH
Acer Global Registration Service 1.0.0.3 - Code Injection
CVSS 7.8
CVE-2020-36975 HIGH
EPSON Status Monitor 3 8.0 - Unquoted Service Path Privilege Escalation via E_S60RPB.EXE
CVSS 7.8
CVE-2020-36974 HIGH
Realtek Andrea RT Filters 1.0.64.7 - Code Injection
CVSS 7.8
CVE-2020-36959 HIGH
IDT PC Audio 1.0.6499.0 - Privilege Escalation
CVSS 7.8
CVE-2020-36958 HIGH
Kite 1.2020.1119.0 - Code Injection
CVSS 7.8
CVE-2020-36957 HIGH
PDF Complete <3.5.310.2002 - Code Injection
CVSS 7.8
CVE-2020-36953 HIGH
MiniTool ShadowMaker 3.2 - Local Privilege Escalation
CVSS 7.8
CVE-2020-36952 HIGH
IObit Uninstaller 10 Pro - Privilege Escalation
CVSS 7.8
CVE-2020-36937 HIGH
Microvirt MEMU Play 3.7.0 - Code Injection
CVSS 7.8
CVE-2020-36936 HIGH
Magic Mouse 2 Utilities <2.20 - Privilege Escalation
CVSS 7.8
CVE-2020-36935 HIGH
KMSpico 17.1.0.0 - Unquoted Service Path Privilege Escalation via Service KMSELDI Configuration
CVSS 7.8
CVE-2020-36934 HIGH
Deep Instinct Windows Agent 1.2.24.0 - Privilege Escalation
CVSS 7.8
CVE-2020-36933 HIGH
HTC IPTInstaller 4.0.9 - Code Injection
CVSS 7.8
CVE-2020-36930 HIGH
SysGauge Server 7.9.18 - Code Injection
CVSS 7.8
CVE-2020-36929 HIGH
Brother BRPrint Auditor 3.0.7 - Code Injection
CVSS 7.8
CVE-2020-36928 HIGH
Brother BRAgent 1.38 - Code Injection
CVSS 7.8
CVE-2020-36927 HIGH
DiskPulse Enterprise 13.6.14 - Code Injection
CVSS 7.8
CVE-2020-36903 HIGH
Selea CarPlateServer 4.0.1.6 - Privilege Escalation
CVSS 8.4
CVE-2020-36879 HIGH
Flexsense DiskBoss 11.7.28 - Privilege Escalation
CVE-2020-24682 HIGH
B&R Industrial Automation <4.9.4 - Privilege Escalation
CVSS 7.2
CVE-2020-14521 HIGH
Mitsubishi Electric Factory Automation - Code Injection
CVSS 8.3
CVE-2020-11632 HIGH
Zscaler Client Connector <2.1.2.150 - Code Injection
CVSS 7.8
CVE-2020-22809 HIGH
Windscribe <v1.83 Build 20 - Privilege Escalation
CVSS 7.8
CVE-2020-35152 MEDIUM
Cloudflare WARP for Windows <1.2.2695.1 - Privilege Escalation
CVSS 4.5
CVE-2020-5147 MEDIUM
SonicWall NetExtender <10.2.300 - Privilege Escalation
CVSS 5.3
Details
Vulnerabilities 451