VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,213)

page 41 of 61
  • CVE-2026-1636MedApr 15, 2026
    risk 0.44cvss 6.7epss 0.00

    A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a local authenticated user to execute code with elevated privileges.

  • CVE-2026-40031HigApr 8, 2026
    risk 0.44cvss 7.8epss 0.00

    MemProcFS before 5.17 contains multiple unsafe library-loading patterns that enable DLL and shared-library hijacking across six attack surfaces, including bare-name LoadLibraryU and dlopen calls without path qualification for vmmpyc, libMSCompression, and plugin DLLs. An…

  • CVE-2026-28728MedApr 2, 2026
    risk 0.44cvss 6.7epss 0.00

    Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42902.

  • CVE-2026-27774MedApr 2, 2026
    risk 0.44cvss 6.7epss 0.00

    Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42902.

  • CVE-2026-5271HigApr 1, 2026
    risk 0.44cvss 7.8epss 0.00

    pymanager included the current working directory in sys.path meaning modules could be shadowed by modules in the current working directory. As a result, if a user executes a pymanager-generated command (e.g., pip, pytest) from an attacker-controlled directory, a malicious…

  • CVE-2026-34054HigMar 31, 2026
    risk 0.44cvss 7.8epss 0.01

    vcpkg is a free and open-source C/C++ package manager. Prior to version 3.6.1#3, vcpkg's Windows builds of OpenSSL set openssldir to a path on the build machine, making that path be attackable later on customer machines. This issue has been patched in version 3.6.1#3.

  • CVE-2026-22270MedMar 4, 2026
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an uncontrolled search path element vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service,…

  • CVE-2026-3091MedFeb 24, 2026
    risk 0.44cvss 6.7epss 0.00

    An uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read or write arbitrary files and conduct denial-of-service during installation by placing a malicious DLL in advance in the same directory as the installer.

  • CVE-2026-2492HigFeb 20, 2026
    risk 0.44cvss 7.8epss 0.00

    TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of TensorFlow. An attacker must first obtain the ability to execute low-privileged code…

  • CVE-2025-32452MedFeb 10, 2026
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for some AI Playground before version 2.6.1 beta within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege.…

  • CVE-2025-20106MedFeb 10, 2026
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some software installer for some VTune(TM) Profiler software and Intel(R) oneAPI Base Toolkits before version 2025.0. within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined…

  • CVE-2025-33231MedJan 20, 2026
    risk 0.44cvss 6.7epss 0.00

    NVIDIA Nsight Systems for Windows contains a vulnerability in the application’s DLL loading mechanism where an attacker could cause an uncontrolled search path element by exploiting insecure DLL search paths. A successful exploit of this vulnerability might lead to code…

  • CVE-2025-14625MedJan 7, 2026
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard on Windows (Nios II Command Shell modules), Altera Quartus Prime Lite on Windows (Nios II Command Shell modules) allows Search Order Hijacking.This issue affects Quartus Prime Standard: from 19.1…

  • CVE-2025-14605MedJan 7, 2026
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro on Windows (System Console modules) allows Search Order Hijacking.This issue affects Quartus Prime Pro: from 17.0 through 25.1.1.

  • CVE-2025-14599MedJan 7, 2026
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard Installer (SFX) on Windows, Altera Quartus Prime Lite  Installer (SFX) on Windows allows Search Order Hijacking.This issue affects Quartus Prime Standard: from 23.1 through 24.1; Quartus Prime…

  • CVE-2025-14596MedJan 7, 2026
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro Installer (SFX) on Windows allows Search Order Hijacking.This issue affects Quartus Prime Pro: from 24.1 through 24.3.1.

  • CVE-2025-14405MedDec 23, 2025
    risk 0.44cvss 6.8epss 0.00

    PDFsam Enhanced Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows phyiscally-present attackers to escalate privileges on affected installations of PDFsam Enhanced. An attacker must first obtain the ability to mount a malicious…

  • CVE-2025-53000HigDec 17, 2025
    risk 0.44cvss 7.8epss 0.00

    The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions of nbconvert up to and including 7.16.6 on Windows have a vulnerability in which converting a notebook containing SVG output to a PDF results in unauthorized…

  • CVE-2025-13670MedDec 12, 2025
    risk 0.44cvss 6.7epss 0.00

    The High Level Synthesis Compiler i++ command for Windows is vulnerable to a DLL planting vulnerability

  • CVE-2025-13669MedDec 12, 2025
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled Search Path Element vulnerability in Altera High Level Synthesis Compiler on Windows allows Search Order Hijacking.This issue affects High Level Synthesis Compiler: from 19.1 through 24.3.