CWE-426
Untrusted Search Path
Description
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-38
CVEs mapped to this weakness (672)
page 1 of 34| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-30330 | Cri | 0.67 | 9.8 | 0.06 | May 12, 2023 | SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42300/generic/gn_defaultframe/2.0/defaultframe_filter.php. | ||
| CVE-2025-26155 | Cri | 0.64 | 9.8 | 0.01 | Nov 26, 2025 | NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability. | ||
| CVE-2024-38462 | Cri | 0.64 | 9.8 | 0.01 | Jun 16, 2024 | iRODS before 4.3.2 provides an msiSendMail function with a problematic dependency on the mail binary, such as in the mailMS.cpp#L94-L106 reference. | ||
| CVE-2022-22047 | Hig | 0.64 | 7.8 | 0.17 | KEV | Jul 12, 2022 | Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability | |
| CVE-2022-24826 | Cri | 0.64 | 9.8 | 0.02 | Apr 20, 2022 | On Windows, if Git LFS operates on a malicious repository with a `..exe` file as well as a file named `git.exe`, and `git.exe` is not found in `PATH`, the `..exe` program will be executed, permitting the attacker to execute arbitrary code. This does not affect Unix systems.… | ||
| CVE-2011-4125 | Cri | 0.64 | 9.8 | 0.02 | Oct 27, 2021 | A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute any program as root. | ||
| CVE-2017-12414 | Cri | 0.64 | 9.8 | 0.02 | Aug 3, 2017 | Format Factory 4.1.0 has a DLL Hijacking Vulnerability because an untrusted search path is used for msimg32.dll, WindowsCodecs.dll, and dwmapi.dll. | ||
| CVE-2017-2225 | Cri | 0.64 | 9.8 | 0.01 | Jul 7, 2017 | Untrusted search path vulnerability in EbidSettingChecker.exe (version 1.0.0.0) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | ||
| CVE-2012-1854 | Hig | 0.64 | 7.8 | 0.21 | KEV | Jul 10, 2012 | Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications SDK allows local users to gain privileges via a Trojan horse… | |
| CVE-2022-23748 | Hig | 0.63 | 7.8 | 0.09 | KEV | Nov 17, 2022 | mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a malicious attacker could be using the valid and legitimate executable to load malicious files. | |
| CVE-2025-49457 | Cri | 0.62 | 9.6 | 0.01 | Aug 12, 2025 | Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access | ||
| CVE-2025-65078 | Cri | 0.60 | — | 0.01 | Feb 3, 2026 | An untrusted search path vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code. | ||
| CVE-2025-23266 | Cri | 0.59 | 9.0 | 0.03 | Jul 17, 2025 | NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data… | ||
| CVE-2025-4971 | Hig | 0.58 | — | 0.01 | May 20, 2025 | Broadcom Automic Automation Agent Unix versions < 24.3.0 HF4 and < 21.0.13 HF1 allow low privileged users who have execution rights on the agent executable to escalate their privileges. | ||
| CVE-2024-26198 | Hig | 0.58 | 8.8 | 0.07 | Mar 12, 2024 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2019-11351 | Hig | 0.58 | 8.8 | 0.04 | Apr 19, 2019 | TeamSpeak 3 Client before 3.2.5 allows remote code execution in the Qt framework. | ||
| CVE-2016-1417 | Hig | 0.58 | 8.8 | 0.04 | Jan 23, 2017 | Untrusted search path vulnerability in Snort 2.9.7.0-WIN32 allows remote attackers to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse tcapi.dll that is located in the same folder on a remote file share as a pcap file that is being processed. | ||
| CVE-2026-63093 | Hig | 0.57 | 8.8 | 0.01 | Jul 17, 2026 | Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by placing a malicious git.exe file in the repository root directory. When a developer clones and opens a crafted repository, Cursor… | ||
| CVE-2026-44477 | Cri | 0.57 | 9.9 | 0.00 | May 28, 2026 | CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and 1.28.3, the CloudNativePG metrics exporter opens its PostgreSQL connection as the postgres superuser via the pod-local Unix socket, then demotes the session… | ||
| CVE-2026-45772 | Cri | 0.57 | 9.8 | 0.00 | May 15, 2026 | Turborepo is a high-performance build system for JavaScript and TypeScript codebases. From 1.1.0 to before 2.9.14, Turborepo can be vulnerable to arbitrary code execution when run in untrusted repositories that contain malicious Yarn configuration. In affected versions, package… |
- risk 0.67cvss 9.8epss 0.06
SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42300/generic/gn_defaultframe/2.0/defaultframe_filter.php.
- risk 0.64cvss 9.8epss 0.01
NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability.
- risk 0.64cvss 9.8epss 0.01
iRODS before 4.3.2 provides an msiSendMail function with a problematic dependency on the mail binary, such as in the mailMS.cpp#L94-L106 reference.
- risk 0.64cvss 7.8epss 0.17
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
- risk 0.64cvss 9.8epss 0.02
On Windows, if Git LFS operates on a malicious repository with a `..exe` file as well as a file named `git.exe`, and `git.exe` is not found in `PATH`, the `..exe` program will be executed, permitting the attacker to execute arbitrary code. This does not affect Unix systems.…
- risk 0.64cvss 9.8epss 0.02
A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute any program as root.
- risk 0.64cvss 9.8epss 0.02
Format Factory 4.1.0 has a DLL Hijacking Vulnerability because an untrusted search path is used for msimg32.dll, WindowsCodecs.dll, and dwmapi.dll.
- risk 0.64cvss 9.8epss 0.01
Untrusted search path vulnerability in EbidSettingChecker.exe (version 1.0.0.0) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
- risk 0.64cvss 7.8epss 0.21
Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications SDK allows local users to gain privileges via a Trojan horse…
- risk 0.63cvss 7.8epss 0.09
mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a malicious attacker could be using the valid and legitimate executable to load malicious files.
- risk 0.62cvss 9.6epss 0.01
Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access
- risk 0.60cvss —epss 0.01
An untrusted search path vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code.
- risk 0.59cvss 9.0epss 0.03
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data…
- risk 0.58cvss —epss 0.01
Broadcom Automic Automation Agent Unix versions < 24.3.0 HF4 and < 21.0.13 HF1 allow low privileged users who have execution rights on the agent executable to escalate their privileges.
- risk 0.58cvss 8.8epss 0.07
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.58cvss 8.8epss 0.04
TeamSpeak 3 Client before 3.2.5 allows remote code execution in the Qt framework.
- risk 0.58cvss 8.8epss 0.04
Untrusted search path vulnerability in Snort 2.9.7.0-WIN32 allows remote attackers to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse tcapi.dll that is located in the same folder on a remote file share as a pcap file that is being processed.
- risk 0.57cvss 8.8epss 0.01
Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by placing a malicious git.exe file in the repository root directory. When a developer clones and opens a crafted repository, Cursor…
- risk 0.57cvss 9.9epss 0.00
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and 1.28.3, the CloudNativePG metrics exporter opens its PostgreSQL connection as the postgres superuser via the pod-local Unix socket, then demotes the session…
- risk 0.57cvss 9.8epss 0.00
Turborepo is a high-performance build system for JavaScript and TypeScript codebases. From 1.1.0 to before 2.9.14, Turborepo can be vulnerable to arbitrary code execution when run in untrusted repositories that contain malicious Yarn configuration. In affected versions, package…