The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.
451 vulnerabilities with CWE-428
CVE-2022-37197
HIGH
IOBit IOTransfer V4 - Unquoted Service Path
CVSS 7.8
CVE-2022-36384
MEDIUM
Intel NUC Kit Wireless Adapter <22.40 - Privilege Escalation
CVSS 6.7
CVE-2022-33920
HIGH
Dell GeoDrive <2.2 - Code Injection
CVSS 7.8
CVE-2022-39959
HIGH
Panini Everest Engine 2.0.4 - Unquoted Search Path Privilege Escalation via Everest.exe
CVSS 7.8
CVE-2022-35292
HIGH
SAP Business One - Privilege Escalation
CVSS 7.8
CVE-2022-1697
LOW
Okta Active Directory Agent <3.12.0 - Path Traversal
CVSS 3.9
CVE-2022-36344
CRITICAL
JustSystems JUST Online Update for J-License - Path Traversal
CVSS 9.8
CVE-2022-35899
HIGH
ASUSTeK Aura Ready Game SDK <1.0.0.4 - Privilege Escalation
CVSS 7.8
CVE-2022-31591
HIGH
SAP BusinessObjects BW Publisher Service <430 - Privilege Escalation
CVSS 7.8
CVE-2022-2147
MEDIUM
Cloudflare Warp <2022.3.186.0 - Privilege Escalation
CVSS 6.5
CVE-2022-31590
HIGH
SAP PowerDesigner Proxy 16.7 - Privilege Escalation
CVSS 7.8
CVE-2022-29320
HIGH
MiniTool Partition Wizard v12.0 - Privilege Escalation
CVSS 7.8
CVE-2022-27095
HIGH
BattlEye v0.9 - Privilege Escalation
CVSS 7.8
CVE-2022-27094
MEDIUM
Sony PlayMemories Home v6.0 - Privilege Escalation
CVSS 6.7
CVE-2022-26634
HIGH
HMA VPN <5.3.5913.0 - Privilege Escalation
CVSS 7.8
CVE-2022-0883
HIGH
Snow License Manager 9.0.0-9.20.0 - Unquoted Service Path
CVSS 7.3
CVE-2022-27905
HIGH
ControlUp Real-Time Agent < 8.6 - Privilege Escalation via Unquoted Path
CVSS 7.2
CVE-2022-27089
HIGH
Fujitsu PlugFree Network <= 7.3.0.3 - Privilege Escalation
CVSS 7.8
CVE-2022-27088
HIGH
Ivanti DSM Remote <6.3.1.1862 - Privilege Escalation
CVSS 7.8
CVE-2022-23909
HIGH
Sherpa Connector Service <2020.2.20328.2050 - Privilege Escalation
CVSS 7.8
CVE-2022-27966
MEDIUM
Xshell < 7.0.0099 - Unquoted Search Path or Element
CVSS 6.5
CVE-2022-27965
MEDIUM
Xlpd < 7.0.0094 - Unquoted Search Path or Element
CVSS 6.5
CVE-2022-27964
MEDIUM
Xmanager < 7.0.0096 - Unquoted Search Path or Element
CVSS 6.5
CVE-2022-27963
MEDIUM
Xftp < 7.0.0088p - Unquoted Search Path or Element
CVSS 6.5
CVE-2022-27052
HIGH
FreeFtpd <1.0.13 - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities
451