VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,213)

page 1 of 61
  • CVE-2020-27955CriNov 5, 2020
    risk 0.73cvss 9.8epss 0.83

    Git LFS 2.12.0 allows Remote Code Execution.

  • CVE-2020-3433HigKEVAug 17, 2020
    risk 0.73cvss 7.8epss 0.10

    A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials…

  • CVE-2017-6517CriMar 23, 2017
    risk 0.67cvss 9.8epss 0.46

    Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded by Skype. It allows an attacker to load a .dll of the…

  • CVE-2020-3153MedKEVFeb 19, 2020
    risk 0.65cvss 6.5epss 0.27

    A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling…

  • CVE-2026-16860CriAug 12, 2026
    risk 0.64cvss 9.9epss 0.01

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.

  • CVE-2025-69599CriMay 8, 2026
    risk 0.64cvss 9.8epss 0.00

    RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control the value of the PATH environment variable. NOTE: this is disputed because ability of an attacker to control the environment is a site-specific misconfiguration.

  • CVE-2019-25268CriJan 8, 2026
    risk 0.64cvss 9.8epss 0.00

    NREL BEopt 2.8.0.0 contains a DLL hijacking vulnerability that allows attackers to load arbitrary libraries by tricking users into opening application files from remote shares. Attackers can exploit insecure library loading of sdl2.dll and libegl.dll by placing malicious…

  • CVE-2023-53959CriDec 19, 2025
    risk 0.64cvss 9.8epss 0.01

    FileZilla Client 3.63.1 contains a DLL hijacking vulnerability that allows attackers to execute malicious code by placing a crafted TextShaping.dll in the application directory. Attackers can generate a reverse shell payload using msfvenom and replace the missing DLL to achieve…

  • CVE-2025-65741CriDec 9, 2025
    risk 0.64cvss 9.8epss 0.01

    Sublime Text 3 Build 3208 or prior for MacOS is vulnerable to Dylib Injection. An attacker could compile a .dylib file and force the execution of this library in the context of the Sublime Text application.

  • CVE-2024-23054CriFeb 5, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components not existing in the public package index (npm).

  • CVE-2023-25143CriMar 10, 2023
    risk 0.64cvss 9.8epss 0.02

    An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker to achieve a remote code execution state on affected products.

  • CVE-2022-34825CriNov 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier allows a remote unauthenticated…

  • CVE-2022-24955CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.01

    Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files.

  • CVE-2019-20780CriApr 17, 2020
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. Certain security settings, related to whether packages are verified and accepted only from known sources, are mishandled. The LG ID is LVE-SMP-190002 (April 2019).

  • CVE-2020-10515CriApr 2, 2020
    risk 0.64cvss 9.8epss 0.03

    STARFACE UCC Client before 6.7.1.204 on WIndows allows binary planting to execute code with System rights, aka usd-2020-0006.

  • CVE-2019-9546CriMar 1, 2019
    risk 0.64cvss 9.8epss 0.03

    SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.

  • CVE-2019-7653CriFeb 9, 2019
    risk 0.64cvss 9.8epss 0.02

    The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the current working directory, allowing code injection, because "python -m" looks in this directory, as demonstrated by rdf2dot. This issue is specific to use of the…

  • CVE-2018-12805CriJul 20, 2018
    risk 0.64cvss 9.8epss 0.04

    Adobe Connect versions 9.7.5 and earlier have an Insecure Library Loading vulnerability. Successful exploitation could lead to privilege escalation.

  • CVE-2017-3097CriJun 20, 2017
    risk 0.64cvss 9.8epss 0.07

    Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability. The vulnerability is due to unsafe library loading functions in the installer plugin. A successful exploitation could lead to arbitrary code execution.

  • CVE-2017-3092CriJun 20, 2017
    risk 0.64cvss 9.8epss 0.09

    Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability. The vulnerability is due to unsafe library loading of editor control library functions in the installer plugin. A successful exploitation could lead to arbitrary code execution.