CWE-428

Unquoted Search Path or Element

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

418 vulnerabilities with CWE-428
CVE-2022-36344 CRITICAL
JustSystems JUST Online Update for J-License - Path Traversal
CVSS 9.8
CVE-2022-35899 HIGH
ASUSTeK Aura Ready Game SDK <1.0.0.4 - Privilege Escalation
CVSS 7.8
CVE-2022-31591 HIGH
SAP BusinessObjects BW Publisher Service <430 - Privilege Escalation
CVSS 7.8
CVE-2022-2147 MEDIUM
Cloudflare Warp <2022.3.186.0 - Privilege Escalation
CVSS 6.5
CVE-2022-31590 HIGH
SAP PowerDesigner Proxy 16.7 - Privilege Escalation
CVSS 7.8
CVE-2022-29320 HIGH
MiniTool Partition Wizard v12.0 - Privilege Escalation
CVSS 7.8
CVE-2022-27095 HIGH
BattlEye v0.9 - Privilege Escalation
CVSS 7.8
CVE-2022-27094 MEDIUM
Sony PlayMemories Home v6.0 - Privilege Escalation
CVSS 6.7
CVE-2022-26634 HIGH
HMA VPN <5.3.5913.0 - Privilege Escalation
CVSS 7.8
CVE-2022-0883 HIGH
SLM <9.20.1 - Info Disclosure
CVSS 7.3
CVE-2022-27905 HIGH
Controlup < 8.6 - Privilege Escalation
CVSS 7.2
CVE-2022-27089 HIGH
Fujitsu PlugFree Network <= 7.3.0.3 - Privilege Escalation
CVSS 7.8
CVE-2022-27088 HIGH
Ivanti DSM Remote <6.3.1.1862 - Privilege Escalation
CVSS 7.8
CVE-2022-23909 HIGH
Sherpa Connector Service <2020.2.20328.2050 - Privilege Escalation
CVSS 7.8
CVE-2022-27966 MEDIUM
Xshell <7.0.0099 - RCE
CVSS 6.5
CVE-2022-27965 MEDIUM
Xlpd <7.0.0094 - RCE
CVSS 6.5
CVE-2022-27964 MEDIUM
Xmanager <7.0.0096 - RCE
CVSS 6.5
CVE-2022-27963 MEDIUM
Xftp <7.0.0088p - RCE
CVSS 6.5
CVE-2022-27052 HIGH
FreeFtpd <1.0.13 - Privilege Escalation
CVSS 7.8
CVE-2022-27050 HIGH
BitComet Service <1.8.6 - Privilege Escalation
CVSS 7.8
CVE-2022-0237 MEDIUM
Rapid7 Insight Agent <3.1.2.38 - Privilege Escalation
CVSS 4.0
CVE-2022-25031 HIGH
Remote Desktop Commander Suite Agent <4.8 - Privilege Escalation
CVSS 7.8
CVE-2021-47898 HIGH
Epson USB Display <1.6.0.0 - Privilege Escalation
CVSS 7.8
CVE-2021-47896 HIGH
PDF Complete Corporate Edition 4.1.45 - Code Injection
CVSS 7.8
CVE-2021-47890 HIGH
LogonExpert 8.1 - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities 418