CWE-428

Unquoted Search Path or Element

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

451 vulnerabilities with CWE-428
CVE-2023-4991 HIGH
NextBX QWAlerter 4.50 - Unquoted Search Path
CVSS 7.8
CVE-2023-36658 HIGH
OPSWAT MetaDefender KIOSK <4.6.1.9996 - Local Privilege Escalation
CVSS 7.8
CVE-2023-22841 MEDIUM
Intel Server Firmware Update Utility < 16.0.7 - Authenticated Privilege Escalation via Unquoted Search Path
CVSS 6.7
CVE-2023-2685 HIGH
ABB AO-OPC 1.0.0-3.2.0 - Privilege Escalation via Unquoted Service Path
CVSS 7.2
CVE-2023-26911 HIGH
ASUS SetupAsusServices <1.0.5.1 - Privilege Escalation
CVSS 7.8
CVE-2023-3842 HIGH
Pointware EasyInventory <1.0.12.0 - Unquoted Search Path
CVSS 7.8
CVE-2023-38408 CRITICAL
OpenSSH < 9.3p2 - Remote Code Execution via PKCS#11 Untrusted Search Path
CVSS 9.8
CVE-2023-3438 MEDIUM
Trellix MOVE < 4.10.0 - Unquoted Windows Search Path Privilege Escalation via mvagtsce.exe
CVSS 4.4
CVE-2023-31747 HIGH
Wondershare Filmora <12.2.1.2088 - Privilege Escalation
CVSS 7.8
CVE-2023-2644 MEDIUM
DigitalPersona FPSensor 1.0.0.1 - Unquoted Search Path
CVSS 5.3
CVE-2023-27386 MEDIUM
Intel Pathfinder for RISC-V - Uncontrolled Search Path Privilege Escalation via Local Access
CVSS 6.7
CVE-2023-27298 HIGH
Intel(R) WULT <1.0.0 - Privilege Escalation
CVSS 8.8
CVE-2023-2417 MEDIUM
ks-soft Advanced Host Monitor <12.56 - Unquoted Search Path
CVSS 5.3
CVE-2023-2331 HIGH
42Gears Surelock <2.40.0 - Code Injection
CVSS 7.8
CVE-2023-22282 HIGH
WAB-MAT Ver.5.0.0.8 - Code Injection
CVSS 7.3
CVE-2023-24671 HIGH
VX Search v13.8 and v14.7 - Unquoted Service Path Privilege Escalation
CVSS 7.8
CVE-2023-24575 HIGH
Dell Multifunction Printer E525w <1.047.2022 - Privilege Escalation
CVSS 7.8
CVE-2023-0887 HIGH
phjounin TFTPD64-SE 4.64 - Unquoted Search Path
CVSS 7.0
CVE-2022-50971 HIGH
Malwarebytes 4.5 Unquoted Service Path Privilege Escalation
CVSS 7.8
CVE-2022-50938 HIGH
CONTPAQi AdminPAQ 14.0.0 - Code Injection
CVSS 8.4
CVE-2022-50935 CRITICAL
Flame II HSPA USB Modem - Privilege Escalation
CVSS 9.8
CVE-2022-50933 HIGH
Cain & Abel 4.9.56 - Code Injection
CVSS 7.8
CVE-2022-50930 HIGH
Emerson PAC Machine Edition 9.80 - Privilege Escalation
CVSS 8.4
CVE-2022-50929 HIGH
Connectify Hotspot 2018 - Code Injection
CVSS 8.4
CVE-2022-50928 HIGH
BlueSoleilCS 5.4.277 - Code Injection
CVSS 7.8
Details
Vulnerabilities 451