VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,213)

page 3 of 61
  • CVE-2025-9059HigSep 11, 2025
    risk 0.57cvss epss 0.00

    The Altiris Core Agent Updater package (AeXNSC.exe) is prone to an elevation of privileges vulnerability through DLL hijacking.

  • CVE-2025-36004HigJun 25, 2025
    risk 0.57cvss 8.8epss 0.01

    IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user to gain elevated privileges due to an unqualified library call in IBM Facsimile Support for i. A malicious actor could cause user-controlled code to run with administrator privilege.

  • CVE-2025-4981CriJun 20, 2025
    risk 0.57cvss 9.9epss 0.01

    Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sanitize filenames in the archive extractor which allows authenticated users to write files to arbitrary locations on the filesystem via uploading archives with…

  • CVE-2025-49155HigJun 17, 2025
    risk 0.57cvss 8.8epss 0.01

    An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacker to inject malicious code leading to arbitrary code execution on affected installations.

  • CVE-2025-32917HigMay 13, 2025
    risk 0.57cvss 8.8epss 0.00

    Privilege escalation in jar_signature agent plugin in Checkmk versions <2.4.0b7 (beta), <2.3.0p32, <2.2.0p42, and 2.1.0p49 (EOL) allow user with write access to JAVA_HOME/bin directory to escalate privileges.

  • CVE-2024-41739HigJan 24, 2025
    risk 0.57cvss 8.8epss 0.00

    IBM Cognos Dashboards 4.0.7 and 5.0.0 on Cloud Pak for Data could allow a remote attacker to perform unauthorized actions due to dependency confusion.

  • CVE-2024-2208HigNov 12, 2024
    risk 0.57cvss 8.8epss 0.00

    Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. Sound Research has released driver updates to mitigate the potential vulnerabilities.

  • CVE-2024-44107HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.00

    DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges and achieve arbitrary code execution.

  • CVE-2024-5290HigAug 7, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged attacker to escalate privileges to the user that wpa_supplicant runs as (usually root). Membership in the netdev group or access to the…

  • CVE-2023-44440HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    Ashlar-Vellum Lithium Uncontrolled Search Path Element Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Lithium. User interaction is required to exploit this vulnerability in that…

  • CVE-2023-44439HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    Ashlar-Vellum Xenon Uncontrolled Search Path Element Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Xenon. User interaction is required to exploit this vulnerability in that the…

  • CVE-2023-44438HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    Ashlar-Vellum Argon Uncontrolled Search Path Element Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Argon. User interaction is required to exploit this vulnerability in that the…

  • CVE-2024-0670HigMar 11, 2024
    risk 0.57cvss 8.8epss 0.00

    Privilege escalation in windows agent plugin in Checkmk before 2.2.0p23, 2.1.0p40 and 2.0.0 (EOL) allows local user to escalate privileges

  • CVE-2023-6740HigJan 12, 2024
    risk 0.57cvss 8.8epss 0.00

    Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges

  • CVE-2023-31210HigDec 13, 2023
    risk 0.57cvss 8.8epss 0.01

    Usage of user controlled LD_LIBRARY_PATH in agent in Checkmk 2.2.0p10 up to 2.2.0p16 allows malicious Checkmk site user to escalate rights via injection of malicious libraries

  • CVE-2023-41117HigDec 12, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contain packages, standalone packages, and functions that run SECURITY DEFINER but are inadequately…

  • CVE-2023-28380HigAug 11, 2023
    risk 0.57cvss 8.8epss 0.01

    Uncontrolled search path for the Intel(R) AI Hackathon software before version 2.0.0 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2023-31543CriJun 30, 2023
    risk 0.57cvss 9.8epss 0.01

    A dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted PyPI package to the chosen repository server.

  • CVE-2023-27298HigMay 10, 2023
    risk 0.57cvss 8.8epss 0.01

    Uncontrolled search path in the WULT software maintained by Intel(R) before version 1.0.0 (commit id 592300b) may allow an unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2023-0213HigMar 29, 2023
    risk 0.57cvss 8.8epss 0.00

    Elevation of privilege issue in M-Files Installer versions before 22.6 on Windows allows user to gain SYSTEM privileges via DLL hijacking.