VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,213)

page 53 of 61
  • CVE-2017-5565MedMar 21, 2017
    risk 0.44cvss 6.7epss 0.01

    Code injection vulnerability in Trend Micro Maximum Security 11.0 (and earlier), Internet Security 11.0 (and earlier), and Antivirus+ Security 11.0 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full control of any…

  • CVE-2026-28393HigMar 5, 2026
    risk 0.43cvss 7.7epss 0.00

    OpenClaw versions 2.0.0-beta3 prior to 2026.2.14 contain a path traversal vulnerability in hook transform module loading that allows arbitrary JavaScript execution. The hooks.mappings[].transform.module parameter accepts absolute paths and traversal sequences, enabling attackers…

  • CVE-2025-11772MedDec 1, 2025
    risk 0.43cvss 6.6epss 0.00

    A carefully crafted DLL, copied to C:\ProgramData\Synaptics folder, allows a local user to execute arbitrary code with elevated privileges during driver installation.

  • CVE-2024-39820MedJul 15, 2024
    risk 0.43cvss 6.6epss 0.00

    Uncontrolled search path element in the installer for Zoom Workplace Desktop App for macOS before version 6.0.10 may allow an authenticated user to conduct a denial of service via local access.

  • CVE-2019-3667MedDec 11, 2019
    risk 0.43cvss 6.6epss 0.00

    DLL Search Order Hijacking vulnerability in the Microsoft Windows client in McAfee Tech Check 3.0.0.17 and earlier allows local users to execute arbitrary code via the local folder placed there by an attacker.

  • CVE-2025-64995MedDec 11, 2025
    risk 0.42cvss 6.5epss 0.00

    A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Exchange-NomadClientHealth-ConfigureGeneralSetting instruction prior V3.4. Improper protection of the execution path on the local device allows attackers, with local…

  • CVE-2025-64994MedDec 11, 2025
    risk 0.42cvss 6.5epss 0.00

    A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-SetWorkRate instruction prior V17.1. The improper handling of executable search paths could allow local attackers with write access to a PATH directory on a…

  • CVE-2024-24916MedJun 19, 2025
    risk 0.42cvss 6.5epss 0.02

    Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution with the installer's privileges (admin).

  • CVE-2024-42191MedMay 30, 2025
    risk 0.42cvss 6.5epss 0.00

    HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.

  • CVE-2024-42190MedMay 30, 2025
    risk 0.42cvss 6.5epss 0.00

    HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.

  • CVE-2025-3051MedApr 1, 2025
    risk 0.42cvss 6.5epss 0.00

    Linux::Statm::Tiny for Perl before 0.0701 allows untrusted code from the current working directory ('.') to be loaded similar to CVE-2016-1238. If an attacker can place a malicious file in current working directory, it may be loaded instead of the intended file, potentially…

  • CVE-2025-30673MedApr 1, 2025
    risk 0.42cvss 6.5epss 0.00

    Sub::HandlesVia for Perl before 0.050002 allows untrusted code from the current working directory ('.') to be loaded similar to CVE-2016-1238. If an attacker can place a malicious file in current working directory, it may be loaded instead of the intended file, potentially…

  • CVE-2025-30672MedApr 1, 2025
    risk 0.42cvss 6.5epss 0.00

    Mite for Perl before 0.013000 generates code with the current working directory ('.') added to the @INC path similar to CVE-2016-1238. If an attacker can place a malicious file in current working directory, it may be loaded instead of the intended file, potentially leading to…

  • CVE-2024-10389HigNov 4, 2024
    risk 0.42cvss 7.5epss 0.00

    There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Write Arbitrary Files via Archive Extraction containing symbolic links. We recommend upgrading past…

  • CVE-2024-34016MedSep 16, 2024
    risk 0.42cvss 6.5epss 0.00

    Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 38235.

  • CVE-2023-27859MedJan 22, 2024
    risk 0.42cvss 6.5epss 0.01

    IBM Db2 10.1, 10.5, and 11.1 could allow a remote user to execute arbitrary code caused by installing like named jar files across multiple databases. A user could exploit this by installing a malicious jar file that overwrites the existing like named jar file in another…

  • CVE-2023-41780MedJan 3, 2024
    risk 0.42cvss 6.4epss 0.00

    There is an unsafe DLL loading vulnerability in ZTE ZXCLOUD iRAI. Due to the  program  failed to adequately validate the user's input, an attacker could exploit this vulnerability  to escalate local privileges.

  • CVE-2023-4770MedNov 30, 2023
    risk 0.42cvss 6.5epss 0.00

    An uncontrolled search path element vulnerability has been found on 4D and 4D server Windows executables applications, affecting version 19 R8 100218. This vulnerability consists in a DLL hijacking by replacing x64 shfolder.dll in the installation path, causing an arbitrary code…

  • CVE-2023-37849MedJul 13, 2023
    risk 0.42cvss 6.5epss 0.00

    A DLL hijacking vulnerability in Panda Security VPN for Windows prior to version v15.14.8 allows attackers to execute arbitrary code via placing a crafted DLL file in the same directory as PANDAVPN.exe.

  • CVE-2023-0142MedJun 13, 2023
    risk 0.42cvss 6.5epss 0.01

    Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7 and 7.1-42661 allows remote authenticated users with administrator privileges to read or write arbitrary files via…