CWE-428

Unquoted Search Path or Element

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

451 vulnerabilities with CWE-428
CVE-2021-47862 HIGH
Hi-Rez Studios 5.1.6.3 - Code Injection
CVSS 7.8
CVE-2021-47861 HIGH
Event Log Explorer 4.9.3 - Privilege Escalation
CVSS 7.8
CVE-2021-47859 HIGH
ActivIdentity 8.2 - Local Privilege Escalation
CVSS 7.8
CVE-2021-47847 HIGH
Disk Sorter Server 13.6.12 - Code Injection
CVSS 7.8
CVE-2021-47845 HIGH
Spy Emergency 25.0.650 - Privilege Escalation
CVSS 7.8
CVE-2021-47833 HIGH
WifiHotSpot 1.0.0.0 - Code Injection
CVSS 7.8
CVE-2021-47829 HIGH
DHCP Broadband 4.1.0.1503 - Code Injection
CVSS 7.8
CVE-2021-47828 HIGH
BOOTP Turbo <2.0.0.1253 - Code Injection
CVSS 7.8
CVE-2021-47826 HIGH
Acer Backup Manager 3.0.0.99 - Code Injection
CVSS 7.8
CVE-2021-47825 HIGH
Acer Updater Service 1.2.3500.0 - Privilege Escalation
CVSS 7.8
CVE-2021-47823 HIGH
Acer ePowerSvc 6.0.3008.0 - Privilege Escalation
CVSS 7.8
CVE-2021-47822 HIGH
DiskBoss Service 12.2.18 - Privilege Escalation
CVSS 7.8
CVE-2021-47810 HIGH
WibuKey Runtime 6.51 - Code Injection
CVSS 7.8
CVE-2021-47809 HIGH
Disk Sorter Enterprise 13.6.12 - Code Injection
CVSS 7.8
CVE-2021-47807 HIGH
Sync Breeze 13.6.18 - Code Injection
CVSS 7.8
CVE-2021-47806 HIGH
Dup Scout 13.5.28 - Unquoted Service Path Privilege Escalation via Windows Service Configuration
CVSS 7.8
CVE-2021-47805 HIGH
Disk Savvy 13.6.14 - Code Injection
CVSS 7.8
CVE-2021-47804 HIGH
Wise Care 365 <5.6.7.568 - Code Injection
CVSS 7.8
CVE-2021-47803 HIGH
iFunbox 4.2 - Unquoted Search Path Privilege Escalation via Apple Mobile Device Service
CVSS 7.8
CVE-2021-47792 HIGH
Remote Mouse 4.002 - Privilege Escalation
CVSS 7.8
CVE-2021-47790 HIGH
Active WebCam 11.5 - Code Injection
CVSS 7.8
CVE-2021-47787 HIGH
TotalAV <5.15.69 - Privilege Escalation
CVSS 7.8
CVE-2021-47780 HIGH
Macro Expert 4.7 - Privilege Escalation
CVSS 7.8
CVE-2021-47773 HIGH
Dynojet Power Core 2.3.0 - Code Injection
CVSS 7.8
CVE-2021-47767 HIGH
10-Strike Network Inventory Explorer Pro 9.31 - Unquoted Service Path Privilege Escalation via srvInventoryWebServer
CVSS 7.8
Details
Vulnerabilities 451