VYPR

CWE-426

Untrusted Search Path

BaseStableLikelihood: High

Description

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-38

CVEs mapped to this weakness (695)

page 1 of 35
  • CVE-2023-30330CriMay 12, 2023
    risk 0.67cvss 9.8epss 0.06

    SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42300/generic/gn_defaultframe/2.0/defaultframe_filter.php.

  • CVE-2026-78155CriAug 23, 2026
    risk 0.64cvss 9.9epss 0.01

    privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges

  • CVE-2026-74872CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files matching the whirlpool*py313*.so…

  • CVE-2025-26155CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.01

    NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability.

  • CVE-2024-38462CriJun 16, 2024
    risk 0.64cvss 9.8epss 0.01

    iRODS before 4.3.2 provides an msiSendMail function with a problematic dependency on the mail binary, such as in the mailMS.cpp#L94-L106 reference.

  • CVE-2022-22047HigKEVJul 12, 2022
    risk 0.64cvss 7.8epss 0.19

    Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

  • CVE-2022-24826CriApr 20, 2022
    risk 0.64cvss 9.8epss 0.02

    On Windows, if Git LFS operates on a malicious repository with a `..exe` file as well as a file named `git.exe`, and `git.exe` is not found in `PATH`, the `..exe` program will be executed, permitting the attacker to execute arbitrary code. This does not affect Unix systems.…

  • CVE-2011-4125CriOct 27, 2021
    risk 0.64cvss 9.8epss 0.02

    A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute any program as root.

  • CVE-2020-15801CriJul 17, 2020
    risk 0.64cvss 9.8epss 0.03

    In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from arbitrary locations. The ._pth file (e.g., the python._pth file) is not affected.

  • CVE-2018-19486CriNov 23, 2018
    risk 0.64cvss 9.8epss 0.04

    Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cases involving the run_command() API and run-command.c, because there was a dangerous change from execvp to execv during 2017.

  • CVE-2017-12414CriAug 3, 2017
    risk 0.64cvss 9.8epss 0.02

    Format Factory 4.1.0 has a DLL Hijacking Vulnerability because an untrusted search path is used for msimg32.dll, WindowsCodecs.dll, and dwmapi.dll.

  • CVE-2017-2225CriJul 7, 2017
    risk 0.64cvss 9.8epss 0.01

    Untrusted search path vulnerability in EbidSettingChecker.exe (version 1.0.0.0) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2012-1854HigKEVJul 10, 2012
    risk 0.64cvss 7.8epss 0.21

    Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications SDK allows local users to gain privileges via a Trojan horse…

  • CVE-2022-23748HigKEVNov 17, 2022
    risk 0.63cvss 7.8epss 0.09

    mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a malicious attacker could be using the valid and legitimate executable to load malicious files.

  • CVE-2025-49457CriAug 12, 2025
    risk 0.62cvss 9.6epss 0.01

    Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access

  • CVE-2025-65078CriFeb 3, 2026
    risk 0.60cvss —epss 0.01

    An untrusted search path vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code.

  • CVE-2025-23266CriJul 17, 2025
    risk 0.59cvss 9.0epss 0.03

    NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data…

  • CVE-2025-4971HigMay 20, 2025
    risk 0.58cvss —epss 0.01

    Broadcom Automic Automation Agent Unix versions < 24.3.0 HF4 and < 21.0.13 HF1 allow low privileged users who have execution rights on the agent executable to escalate their privileges.

  • CVE-2024-26198HigMar 12, 2024
    risk 0.58cvss 8.8epss 0.07

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2019-11351HigApr 19, 2019
    risk 0.58cvss 8.8epss 0.04

    TeamSpeak 3 Client before 3.2.5 allows remote code execution in the Qt framework.