VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,233)

page 12 of 62
  • CVE-2025-2769HigApr 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Bdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Bdrive NetDrive. An attacker must first obtain the ability to execute low-privileged code on…

  • CVE-2025-2768HigApr 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Bdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Bdrive NetDrive. An attacker must first obtain the ability to execute low-privileged code on…

  • CVE-2025-43950HigApr 22, 2025
    risk 0.51cvss 7.8epss 0.00

    DPMAdirektPro 4.1.5 is vulnerable to DLL Hijacking. It happens by placing a malicious DLL in a directory (in the absence of a legitimate DLL), which is then loaded by the application instead of the legitimate DLL. This causes the malicious DLL to load with the same privileges as…

  • CVE-2025-22458HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    DLL hijacking in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an authenticated attacker to escalate to System.

  • CVE-2020-23438HigMar 4, 2025
    risk 0.51cvss 7.8epss 0.00

    Wondershare filmora 9.2.11 is affected by Trojan Dll hijacking leading to privilege escalation.

  • CVE-2024-10930HigMar 4, 2025
    risk 0.51cvss 7.8epss 0.00

    An Uncontrolled Search Path Element vulnerability exists which could allow a malicious actor to perform DLL hijacking and execute arbitrary code with escalated privileges.

  • CVE-2024-48091HigFeb 7, 2025
    risk 0.51cvss 7.8epss 0.00

    Tally Prime Edit Log v2.1 was discovered to contain a DLL hijacking vulnerability via the component TextShaping.dll. This vulnerability allows attackers to execute arbitrary code via a crafted DLL.

  • CVE-2024-53588HigJan 23, 2025
    risk 0.51cvss 7.8epss 0.00

    A DLL hijacking vulnerability in iTop VPN v16.0 allows attackers to execute arbitrary code via placing a crafted DLL file into the path \ProgramData\iTop VPN\Downloader\vpn6.

  • CVE-2025-21127HigJan 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could lead to arbitrary code execution. An attacker could manipulate the search path environment variable to point to a malicious library, resulting in the…

  • CVE-2025-0069HigJan 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Due to DLL injection vulnerability in SAPSetup, an attacker with either local user privileges or with access to a compromised corporate user�s Windows account could gain higher privileges. With this, he could move laterally within the network and further compromise the active…

  • CVE-2024-55543HigJan 2, 2025
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.

  • CVE-2024-55540HigJan 2, 2025
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.

  • CVE-2022-27595HigDec 19, 2024
    risk 0.51cvss 7.8epss 0.00

    An insecure library loading vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local attackers who have gained user access to execute unauthorized code or commands. We have already fixed the vulnerability in the following…

  • CVE-2024-9852HigNov 28, 2024
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian versions 10.97.3 and prior, Mitsubishi Electric GENESIS32 all versions,…

  • CVE-2024-8299HigNov 28, 2024
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian versions 10.97.3 and prior, Mitsubishi Electric GENESIS32 all versions,…

  • CVE-2024-7253HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    NoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute low-privileged code on the target…

  • CVE-2024-7244HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    Panda Security Dome VPN DLL Hijacking Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the…

  • CVE-2024-48605HigOct 22, 2024
    risk 0.51cvss 7.8epss 0.01

    An issue in Helakuru Desktop Application v1.1 allows a local attacker to execute arbitrary code via the lack of proper validation of the wow64log.dll file.

  • CVE-2024-10093HigOct 17, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability, which was classified as critical, was found in VSO ConvertXtoDvd 7.0.0.83. Affected is an unknown function in the library avcodec.dll of the file ConvertXtoDvd.exe. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The…

  • CVE-2024-10068HigOct 17, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in OpenSight Software FlashFXP 5.4.0.3970. It has been classified as critical. Affected is an unknown function in the library libcrypto-1_1.dll of the file FlashFXP.exe. The manipulation leads to uncontrolled search path. An attack has to be approached…