VYPR

CWE-426

Untrusted Search Path

BaseStableLikelihood: High

Description

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-38

CVEs mapped to this weakness (672)

page 4 of 34
  • CVE-2023-36536HigJul 11, 2023
    risk 0.53cvss 8.2epss 0.00

    Untrusted search path in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.

  • CVE-2023-34119HigJul 11, 2023
    risk 0.53cvss 8.2epss 0.00

    Insecure temporary file in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.

  • CVE-2023-26036HigFeb 25, 2023
    risk 0.53cvss 8.1epss 0.01

    ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain a Local File Inclusion (Untrusted Search Path) vulnerability via /web/index.php. By controlling…

  • CVE-2022-31012HigJul 12, 2022
    risk 0.53cvss 8.2epss 0.00

    Git for Windows is a fork of Git that contains Windows-specific patches. This vulnerability in versions prior to 2.37.1 lets Git for Windows' installer execute a binary into `C:\mingw64\bin\git.exe` by mistake. This only happens upon a fresh install, not when upgrading Git for…

  • CVE-2021-31841HigSep 22, 2021
    risk 0.53cvss 8.2epss 0.00

    A DLL sideloading vulnerability in McAfee Agent for Windows prior to 5.7.4 could allow a local user to perform a DLL sideloading attack with an unsigned DLL with a specific name and in a specific location. This would result in the user gaining elevated permissions and the…

  • CVE-2026-45721CriMay 26, 2026
    risk 0.52cvss 9.0epss 0.00

    Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for any URL path that resolves to a directory without an index file, DirPage walks upward through parent directories — past the configured server root — looking for a file named…

  • CVE-2025-31480CriApr 4, 2025
    risk 0.52cvss 9.1epss 0.00

    aiven-extras is a PostgreSQL extension. This is a privilege escalation vulnerability, allowing elevation to superuser inside PostgreSQL databases that use the aiven-extras package. The vulnerability leverages the format function not being schema-prefixed. Affected users should…

  • CVE-2024-8733HigOct 2, 2024
    risk 0.52cvss 8.0epss 0.00

    A potential security vulnerability has been identified in the HP One Agent for certain HP PC products, which might allow for escalation of privilege. HP is releasing software updates to mitigate this potential vulnerability.

  • CVE-2024-35260HigJun 27, 2024
    risk 0.52cvss 8.0epss 0.01

    An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.

  • CVE-2023-36778HigOct 10, 2023
    risk 0.52cvss 8.0epss 0.04

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2020-1458HigJul 14, 2020
    risk 0.52cvss 7.8epss 0.11

    A remote code execution vulnerability exists when Microsoft Office improperly validates input before loading dynamic link library (DLL) files, aka 'Microsoft Office Remote Code Execution Vulnerability'.

  • CVE-2019-12569HigJun 3, 2019
    risk 0.52cvss 7.8epss 0.15

    A vulnerability in Viber before 10.7.0 for Desktop (Windows) could allow an attacker to execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search paths used by the application URI. An attacker could exploit this vulnerability by convincing a…

  • CVE-2019-0809HigApr 9, 2019
    risk 0.52cvss 7.8epss 0.11

    A remote code execution vulnerability exists when the Visual Studio C++ Redistributable Installer improperly validates input before loading dynamic link library (DLL) files, aka 'Visual Studio Remote Code Execution Vulnerability'.

  • CVE-2026-56174HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

  • CVE-2026-55522HigAug 5, 2026
    risk 0.51cvss 7.8epss 0.00

    PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerable to code execution. Workflow._execute_include() implicitly imports and runs an included recipe's…

  • CVE-2026-41447HigAug 3, 2026
    risk 0.51cvss 7.8epss 0.00

    FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafted openssl.cnf file in the unvalidated C:\Program Files (x86)\Common Files\SSL\ directory path. Attackers can write a malicious…

  • CVE-2026-48565HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

  • CVE-2026-24064HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability. A trusted XPC client component included with the product is signed with hardened runtime entitlements that permit dynamic library injection. A local attacker can set the…

  • CVE-2026-30906HigMay 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Untrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access.

  • CVE-2026-0251HigMay 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands…