CWE-428

Unquoted Search Path or Element

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

418 vulnerabilities with CWE-428
CVE-2023-54338 HIGH
Tftpd32 SE 4.60 - Code Injection
CVSS 8.4
CVE-2023-54336 HIGH
Mediconta 3.7.27 - Privilege Escalation
CVSS 8.4
CVE-2023-54331 HIGH
Outline 1.6.0 - Privilege Escalation
CVSS 7.8
CVE-2023-53984 HIGH
Clevo HotKey Clipboard 2.1.0.6 - Code Injection
CVSS 8.4
CVE-2023-53965 HIGH
SOUND4 Server Service 4.1.102 - Privilege Escalation
CVSS 8.4
CVE-2023-53954 MEDIUM
ActFax 10.10 - Privilege Escalation
CVSS 6.2
CVE-2023-53947 HIGH
OCS Inventory NG <2.3.0.0 - Privilege Escalation
CVSS 8.4
CVE-2023-53946 HIGH
Arcsoft PhotoStudio 6.0.0.172 - Privilege Escalation
CVSS 8.4
CVE-2023-53912 MEDIUM
USB Flash Drives Control 4.1.0.0 - Code Injection
CVSS 6.2
CVE-2023-39464 HIGH
Trianglemicroworks Scada Data Gateway - Remote Code Execution
CVSS 7.2
CVE-2023-24542 MEDIUM
Intel(R) Thunderbolt(TM) DCH <88 - Privilege Escalation
CVSS 6.7
CVE-2023-7043 LOW
ESET - Code Injection
CVSS 3.3
CVE-2023-6631 HIGH
PowerSYSTEM Center <2020 Update 16 - Privilege Escalation
CVSS 7.8
CVE-2023-32658 MEDIUM
Intel(R) NUC Kits <1.79.1.1 - Privilege Escalation
CVSS 6.7
CVE-2023-29165 MEDIUM
Intel(R) Arc(TM) Control <1.73.5335.2 - Privilege Escalation
CVSS 6.7
CVE-2023-25075 MEDIUM
Intel Server Configuration Utility <16.0.9 - Privilege Escalation
CVSS 6.7
CVE-2023-0392 MEDIUM
LDAP Agent Update <5.18 - RCE
CVSS 6.7
CVE-2023-37537 HIGH
HCL AppScan Presence - Privilege Escalation
CVSS 7.8
CVE-2023-42486 MEDIUM
Fortect - Privilege Escalation
CVSS 6.3
CVE-2023-5012 MEDIUM
Topaz OFD <2.11.0.201 - Unquoted Search Path
CVSS 5.3
CVE-2023-4991 HIGH
NextBX QWAlerter 4.50 - Unquoted Search Path
CVSS 7.8
CVE-2023-36658 HIGH
OPSWAT MetaDefender KIOSK <4.6.1.9996 - Local Privilege Escalation
CVSS 7.8
CVE-2023-22841 MEDIUM
Intel Server Firmware Update Utility - Uncontrolled Search Path
CVSS 6.7
CVE-2023-2685 HIGH
AO-OPC Server - SSRF
CVSS 7.2
CVE-2023-26911 HIGH
ASUS SetupAsusServices <1.0.5.1 - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities 418