CWE-426
Untrusted Search Path
Description
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-38
CVEs mapped to this weakness (695)
page 1 of 35| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-30330 | Cri | 0.67 | 9.8 | 0.06 | May 12, 2023 | SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42300/generic/gn_defaultframe/2.0/defaultframe_filter.php. | ||
| CVE-2026-78155 | Cri | 0.64 | 9.9 | 0.01 | Aug 23, 2026 | privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges | ||
| CVE-2026-74872 | Cri | 0.64 | 9.8 | 0.01 | Aug 17, 2026 | openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files matching the whirlpool*py313*.so… | ||
| CVE-2025-26155 | Cri | 0.64 | 9.8 | 0.01 | Nov 26, 2025 | NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability. | ||
| CVE-2024-38462 | Cri | 0.64 | 9.8 | 0.01 | Jun 16, 2024 | iRODS before 4.3.2 provides an msiSendMail function with a problematic dependency on the mail binary, such as in the mailMS.cpp#L94-L106 reference. | ||
| CVE-2022-22047 | Hig | 0.64 | 7.8 | 0.19 | KEV | Jul 12, 2022 | Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability | |
| CVE-2022-24826 | Cri | 0.64 | 9.8 | 0.02 | Apr 20, 2022 | On Windows, if Git LFS operates on a malicious repository with a `..exe` file as well as a file named `git.exe`, and `git.exe` is not found in `PATH`, the `..exe` program will be executed, permitting the attacker to execute arbitrary code. This does not affect Unix systems.… | ||
| CVE-2011-4125 | Cri | 0.64 | 9.8 | 0.02 | Oct 27, 2021 | A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute any program as root. | ||
| CVE-2020-15801 | Cri | 0.64 | 9.8 | 0.03 | Jul 17, 2020 | In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from arbitrary locations. The ._pth file (e.g., the python._pth file) is not affected. | ||
| CVE-2018-19486 | Cri | 0.64 | 9.8 | 0.04 | Nov 23, 2018 | Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cases involving the run_command() API and run-command.c, because there was a dangerous change from execvp to execv during 2017. | ||
| CVE-2017-12414 | Cri | 0.64 | 9.8 | 0.02 | Aug 3, 2017 | Format Factory 4.1.0 has a DLL Hijacking Vulnerability because an untrusted search path is used for msimg32.dll, WindowsCodecs.dll, and dwmapi.dll. | ||
| CVE-2017-2225 | Cri | 0.64 | 9.8 | 0.01 | Jul 7, 2017 | Untrusted search path vulnerability in EbidSettingChecker.exe (version 1.0.0.0) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | ||
| CVE-2012-1854 | Hig | 0.64 | 7.8 | 0.21 | KEV | Jul 10, 2012 | Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications SDK allows local users to gain privileges via a Trojan horse… | |
| CVE-2022-23748 | Hig | 0.63 | 7.8 | 0.09 | KEV | Nov 17, 2022 | mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a malicious attacker could be using the valid and legitimate executable to load malicious files. | |
| CVE-2025-49457 | Cri | 0.62 | 9.6 | 0.01 | Aug 12, 2025 | Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access | ||
| CVE-2025-65078 | Cri | 0.60 | — | 0.01 | Feb 3, 2026 | An untrusted search path vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code. | ||
| CVE-2025-23266 | Cri | 0.59 | 9.0 | 0.03 | Jul 17, 2025 | NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data… | ||
| CVE-2025-4971 | Hig | 0.58 | — | 0.01 | May 20, 2025 | Broadcom Automic Automation Agent Unix versions < 24.3.0 HF4 and < 21.0.13 HF1 allow low privileged users who have execution rights on the agent executable to escalate their privileges. | ||
| CVE-2024-26198 | Hig | 0.58 | 8.8 | 0.07 | Mar 12, 2024 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2019-11351 | Hig | 0.58 | 8.8 | 0.04 | Apr 19, 2019 | TeamSpeak 3 Client before 3.2.5 allows remote code execution in the Qt framework. |
- risk 0.67cvss 9.8epss 0.06
SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42300/generic/gn_defaultframe/2.0/defaultframe_filter.php.
- risk 0.64cvss 9.9epss 0.01
privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges
- risk 0.64cvss 9.8epss 0.01
openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files matching the whirlpool*py313*.so…
- risk 0.64cvss 9.8epss 0.01
NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability.
- risk 0.64cvss 9.8epss 0.01
iRODS before 4.3.2 provides an msiSendMail function with a problematic dependency on the mail binary, such as in the mailMS.cpp#L94-L106 reference.
- risk 0.64cvss 7.8epss 0.19
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
- risk 0.64cvss 9.8epss 0.02
On Windows, if Git LFS operates on a malicious repository with a `..exe` file as well as a file named `git.exe`, and `git.exe` is not found in `PATH`, the `..exe` program will be executed, permitting the attacker to execute arbitrary code. This does not affect Unix systems.…
- risk 0.64cvss 9.8epss 0.02
A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute any program as root.
- risk 0.64cvss 9.8epss 0.03
In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from arbitrary locations. The ._pth file (e.g., the python._pth file) is not affected.
- risk 0.64cvss 9.8epss 0.04
Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cases involving the run_command() API and run-command.c, because there was a dangerous change from execvp to execv during 2017.
- risk 0.64cvss 9.8epss 0.02
Format Factory 4.1.0 has a DLL Hijacking Vulnerability because an untrusted search path is used for msimg32.dll, WindowsCodecs.dll, and dwmapi.dll.
- risk 0.64cvss 9.8epss 0.01
Untrusted search path vulnerability in EbidSettingChecker.exe (version 1.0.0.0) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
- risk 0.64cvss 7.8epss 0.21
Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications SDK allows local users to gain privileges via a Trojan horse…
- risk 0.63cvss 7.8epss 0.09
mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a malicious attacker could be using the valid and legitimate executable to load malicious files.
- risk 0.62cvss 9.6epss 0.01
Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access
- risk 0.60cvss —epss 0.01
An untrusted search path vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code.
- risk 0.59cvss 9.0epss 0.03
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data…
- risk 0.58cvss —epss 0.01
Broadcom Automic Automation Agent Unix versions < 24.3.0 HF4 and < 21.0.13 HF1 allow low privileged users who have execution rights on the agent executable to escalate their privileges.
- risk 0.58cvss 8.8epss 0.07
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.58cvss 8.8epss 0.04
TeamSpeak 3 Client before 3.2.5 allows remote code execution in the Qt framework.