The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.
418 vulnerabilities with CWE-428
CVE-2023-54338
HIGH
Tftpd32 SE 4.60 - Code Injection
CVSS 8.4
CVE-2023-54336
HIGH
Mediconta 3.7.27 - Privilege Escalation
CVSS 8.4
CVE-2023-54331
HIGH
Outline 1.6.0 - Privilege Escalation
CVSS 7.8
CVE-2023-53984
HIGH
Clevo HotKey Clipboard 2.1.0.6 - Code Injection
CVSS 8.4
CVE-2023-53965
HIGH
SOUND4 Server Service 4.1.102 - Privilege Escalation
CVSS 8.4
CVE-2023-53954
MEDIUM
ActFax 10.10 - Privilege Escalation
CVSS 6.2
CVE-2023-53947
HIGH
OCS Inventory NG <2.3.0.0 - Privilege Escalation
CVSS 8.4
CVE-2023-53946
HIGH
Arcsoft PhotoStudio 6.0.0.172 - Privilege Escalation
CVSS 8.4
CVE-2023-53912
MEDIUM
USB Flash Drives Control 4.1.0.0 - Code Injection
CVSS 6.2
CVE-2023-39464
HIGH
Trianglemicroworks Scada Data Gateway - Remote Code Execution
CVSS 7.2
CVE-2023-24542
MEDIUM
Intel(R) Thunderbolt(TM) DCH <88 - Privilege Escalation
CVSS 6.7
CVE-2023-7043
LOW
ESET - Code Injection
CVSS 3.3
CVE-2023-6631
HIGH
PowerSYSTEM Center <2020 Update 16 - Privilege Escalation
CVSS 7.8
CVE-2023-32658
MEDIUM
Intel(R) NUC Kits <1.79.1.1 - Privilege Escalation
CVSS 6.7
CVE-2023-29165
MEDIUM
Intel(R) Arc(TM) Control <1.73.5335.2 - Privilege Escalation
CVSS 6.7
CVE-2023-25075
MEDIUM
Intel Server Configuration Utility <16.0.9 - Privilege Escalation
CVSS 6.7
CVE-2023-0392
MEDIUM
LDAP Agent Update <5.18 - RCE
CVSS 6.7
CVE-2023-37537
HIGH
HCL AppScan Presence - Privilege Escalation
CVSS 7.8
CVE-2023-42486
MEDIUM
Fortect - Privilege Escalation
CVSS 6.3
CVE-2023-5012
MEDIUM
Topaz OFD <2.11.0.201 - Unquoted Search Path
CVSS 5.3
CVE-2023-4991
HIGH
NextBX QWAlerter 4.50 - Unquoted Search Path
CVSS 7.8
CVE-2023-36658
HIGH
OPSWAT MetaDefender KIOSK <4.6.1.9996 - Local Privilege Escalation
CVSS 7.8
CVE-2023-22841
MEDIUM
Intel Server Firmware Update Utility - Uncontrolled Search Path
CVSS 6.7
CVE-2023-2685
HIGH
AO-OPC Server - SSRF
CVSS 7.2
CVE-2023-26911
HIGH
ASUS SetupAsusServices <1.0.5.1 - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities
418