VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,213)

page 59 of 61
  • CVE-2025-13162MedJun 23, 2026
    risk 0.29cvss 4.4epss 0.00

    Uncontrolled Search Path Element vulnerability in ABB Control Builder A, ABB 800xA for Advant Master. This issue affects Control Builder A: through 1.4/4; 800xA for Advant Master: through 6.0.3-1, through 6.1.1-1, 6.1.1-3, 6.2.0-1.

  • CVE-2025-13919MedJan 28, 2026
    risk 0.29cvss 4.4epss 0.00

    Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a COM Hijacking vulnerability, which is a type of issue whereby an attacker attempts to establish persistence and evade detection by hijacking COM references in the…

  • CVE-2022-36840MedAug 5, 2022
    risk 0.29cvss 4.5epss 0.00

    DLL hijacking vulnerability in Samsung Update Setup prior to version 2.2.9.50 allows attackers to execute arbitrary code.

  • CVE-2026-12003MedJun 16, 2026
    risk 0.27cvss epss 0.00

    To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark is found relative to VPATH relative to the…

  • CVE-2024-39613MedSep 16, 2024
    risk 0.27cvss 5.3epss 0.00

    Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able to put an cmd.exe file in the Downloads folder of a user's machine to cause remote code execution on that machine.

  • CVE-2023-51710MedApr 29, 2024
    risk 0.27cvss 4.2epss 0.00

    EMS SQL Manager 3.6.2 (build 55333) for Oracle allows DLL hijacking: a user can trigger the execution of arbitrary code every time the product is executed.

  • CVE-2023-25182MedAug 11, 2023
    risk 0.27cvss 4.2epss 0.00

    Uncontrolled search path element in the Intel(R) Unite(R) Client software for Mac before version 4.2.11 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-27180MedMay 10, 2023
    risk 0.27cvss 4.2epss 0.00

    Uncontrolled search path in the Intel(R) MacCPUID software before version 3.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2017-12266MedOct 5, 2017
    risk 0.27cvss 4.2epss 0.00

    A vulnerability in the routine that loads DLL files in Cisco Meeting App for Windows could allow an authenticated, local attacker to run an executable file with privileges equivalent to those of Cisco Meeting App. The vulnerability is due to incomplete input validation of the…

  • CVE-2026-45003MedMay 11, 2026
    risk 0.26cvss 5.0epss 0.00

    OpenClaw before 2026.4.22 allows workspace dotenv files to override connector endpoint hosts for Matrix, Mattermost, IRC, and Synology connectors. Attackers with workspace access can redirect runtime traffic to malicious endpoints by setting endpoint variables in dotenv files.

  • CVE-2023-41782LowJan 5, 2024
    risk 0.25cvss 3.9epss 0.00

    There is a DLL hijacking vulnerability in ZTE ZXCLOUD iRAI, an attacker could place a fake DLL file in a specific directory and successfully exploit this vulnerability to execute malicious code.

  • CVE-2025-10939LowOct 28, 2025
    risk 0.24cvss 3.7epss 0.00

    A flaw was found in Keycloak. The Keycloak guides recommend to not expose /admin path to the outside in case the installation is using a proxy. The issue occurs at least via ha-proxy, as it can be tricked to using relative/non-normalized paths to access the /admin application…

  • CVE-2024-47576LowDec 10, 2024
    risk 0.21cvss 3.3epss 0.00

    SAP Product Lifecycle Costing Client (versions below 4.7.1) application loads on demand a DLL that is available with Windows OS. This DLL is loaded from the computer running SAP Product Lifecycle Costing Client application. That particular DLL could be replaced by a malicious…

  • CVE-2022-28766LowNov 17, 2022
    risk 0.21cvss 3.3epss 0.01

    Windows 32-bit versions of the Zoom Client for Meetings before 5.12.6 and Zoom Rooms for Conference Room before version 5.12.6 are susceptible to a DLL injection vulnerability. A local low-privileged user could exploit this vulnerability to run arbitrary code in the context of…

  • CVE-2024-30117LowOct 14, 2024
    risk 0.16cvss 2.5epss 0.00

    A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file under some circumstances.

  • CVE-2025-14575LowMay 19, 2026
    risk 0.12cvss epss 0.00

    An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attacker to load a rogue CA certificate as a trusted system authority via a crafted certificate file placed in the application's working…

  • CVE-2024-48990HigNov 19, 2024
    risk 0.05cvss 7.8epss 0.20

    Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable.

  • CVE-2024-48992HigNov 19, 2024
    risk 0.01cvss 7.8epss 0.07

    Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Ruby interpreter with an attacker-controlled RUBYLIB environment variable.

  • CVE-2026-66344MedAug 5, 2026
    risk 0.00cvss 6.7epss 0.00

    NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerability (CWE-427). An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges.

  • CVE-2026-9593MedAug 3, 2026
    risk 0.00cvss 6.7epss 0.00

    A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory, potentially resulting in unauthorized access to connected devices and exposure,…