CWE-426— Untrusted Search Path
528 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-426page 10 of 11
- CVE-2025-15569HIGHCVSS 7.0EG 7.02026-02-10
A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The impacted element is the function get_system_dpi of the file platform/x11/win_main.c. This manipulation causes uncontrolled search path. The attack requires local access. T…
- CVE-2025-1755HIGHCVSS 7.5EG 7.52025-02-27
MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue …
- CVE-2025-1756HIGHCVSS 7.5EG 7.52025-02-27
mongosh may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privilege, when a crafted file is stored in C:\node_modules\. This issue affects m…
- CVE-2025-1804HIGHCVSS 7.0EG 7.02025-03-01
A vulnerability was found in Blizzard Battle.Net up to 2.39.0.15212 on Windows and classified as critical. Affected by this issue is some unknown functionality in the library profapi.dll. The manipulation leads to uncontrolled search path.…
- CVE-2025-21365HIGHCVSS 7.8EG 7.82025-01-14
Microsoft Office Remote Code Execution Vulnerability
- CVE-2025-21399HIGHCVSS 7.4EG 7.42025-01-17
Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability
- CVE-2025-23266CRITICALCVSS 9.0EG 9.02025-07-17
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might …
- CVE-2025-24789HIGHCVSS 7.8EG 7.82025-01-29
Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake JDBC Driver. When the EXTERNALBROWSER authen…
- CVE-2025-24827MEDIUMCVSS 6.3EG 6.32025-01-31
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378.
- CVE-2025-24828MEDIUMCVSS 6.3EG 6.32025-01-31
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378.
- CVE-2025-24829MEDIUMCVSS 6.3EG 6.32025-01-31
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378.
- CVE-2025-24830MEDIUMCVSS 6.3EG 6.32025-01-31
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378.
- CVE-2025-2501HIGHCVSS 7.8EG 7.82025-05-30
An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.
- CVE-2025-26155CRITICALCVSS 9.8EG 9.82025-11-26
NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability.
- CVE-2025-26624MEDIUMCVSS 6.8EG 0.02025-02-18
Rufus is a utility that helps format and create bootable USB flash drives. A DLL hijacking vulnerability in Rufus 4.6.2208 and earlier versions allows an attacker loading and executing a malicious DLL with escalated privileges (since the e…
- CVE-2025-27167HIGHCVSS 7.8EG 7.82025-03-11
Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute their own programs, access unauthorized data files, or modify configuration in unexpected ways. If…
- CVE-2025-27743HIGHCVSS 7.8EG 7.82025-04-08
Untrusted search path in System Center allows an authorized attacker to elevate privileges locally.
- CVE-2025-29903MEDIUMCVSS 5.2EG 5.22025-03-12
In JetBrains Runtime before 21.0.6b872.80 arbitrary dynamic library execution due to insecure macOS flags was possible
- CVE-2025-30399HIGHCVSS 7.5EG 7.52025-06-13
Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
- CVE-2025-30407MEDIUMCVSS 6.3EG 6.32025-03-26
Local privilege escalation due to a binary hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39713.
- CVE-2025-31480CRITICALCVSS 9.1EG 9.12025-04-04
aiven-extras is a PostgreSQL extension. This is a privilege escalation vulnerability, allowing elevation to superuser inside PostgreSQL databases that use the aiven-extras package. The vulnerability leverages the format function not being …
- CVE-2025-39666HIGHCVSS 7.3EG 7.32026-04-07
Local privilege escalation in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0b3 allows a site user to escalate their privileges to root, by manipulating files in the …
- CVE-2025-40909MEDIUMCVSS 5.9EG 5.92025-05-30
Perl threads have a working directory race condition where file operations may target unintended paths. If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone�…
- CVE-2025-4272HIGHCVSS 7.0EG 7.02025-05-05
A vulnerability was found in Mechrevo Control Console 1.0.2.70. It has been rated as critical. Affected by this issue is some unknown functionality in the library C:\Program Files\OEM\MECHREVO Control Center\UniwillService\MyControlCenter\…
- CVE-2025-43079MEDIUMCVSS 6.3EG 6.32025-11-10
The Qualys Cloud Agent included a bundled uninstall script (qagent_uninstall.sh), specific to Mac and Linux supported versions that invoked multiple system commands without using absolute paths and without sanitizing the $PATH environment.…
- CVE-2025-4455HIGHCVSS 7.0EG 7.02025-05-09
A vulnerability was found in Patch My PC Home Updater up to 5.1.3.0. It has been rated as critical. This issue affects some unknown processing in the library advapi32.dll/BCrypt.dll/comctl32.dll/crypt32.dll/dwmapi.dll/gdi32.dll/gdiplus.dll…
- CVE-2025-4525HIGHCVSS 7.0EG 7.02025-05-10
A vulnerability, which was classified as critical, has been found in Discord 1.0.9188 on Windows. Affected by this issue is some unknown functionality in the library WINSTA.dll. The manipulation leads to uncontrolled search path. The attac…
- CVE-2025-4532HIGHCVSS 7.0EG 7.02025-05-11
A vulnerability classified as critical has been found in Shanghai Bairui Information Technology SunloginClient 15.8.3.19819. This affects an unknown part in the library process.dll of the file sunlogin_guard.exe. The manipulation leads to …
- CVE-2025-4539HIGHCVSS 7.0EG 7.02025-05-11
A vulnerability was found in Hainan ToDesk 4.7.6.3. It has been declared as critical. This vulnerability affects unknown code in the library profapi.dll of the component DLL File Parser. The manipulation leads to uncontrolled search path. …
- CVE-2025-4540HIGHCVSS 7.0EG 7.02025-05-11
A vulnerability was found in MTSoftware C-Lodop 6.6.1.1 on Windows. It has been rated as critical. This issue affects some unknown processing of the component CLodopPrintService. The manipulation leads to unquoted search path. The attack n…
- CVE-2025-4769HIGHCVSS 7.0EG 7.02025-05-16
A vulnerability classified as critical was found in CBEWIN Anytxt Searcher 1.3.1128.0. This vulnerability affects unknown code of the file ATService.exe. The manipulation leads to uncontrolled search path. The attack needs to be approached…
- CVE-2025-4802HIGHCVSS 7.8EG 9.82025-05-16
Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including inte…
- CVE-2025-49124HIGHCVSS 8.4EG 8.42025-06-16
Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.…
- CVE-2025-49456MEDIUMCVSS 6.2EG 6.22025-08-12
Race condition in the installer for certain Zoom Clients for Windows may allow an unauthenticated user to impact application integrity via local access.
- CVE-2025-49457CRITICALCVSS 9.6EG 9.62025-08-12
Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access
- CVE-2025-49642MEDIUMCVSS 5.9EG 5.92025-12-01
Library loading on AIX Zabbix Agent builds can be hijacked by local users with write access to the /home/cecuser directory.
- CVE-2025-4971HIGHCVSS 8.5EG 0.02025-05-20
Broadcom Automic Automation Agent Unix versions < 24.3.0 HF4 and < 21.0.13 HF1 allow low privileged users who have execution rights on the agent executable to escalate their privileges.
- CVE-2025-5039HIGHCVSS 7.8EG 7.82025-07-24
A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized.
- CVE-2025-5129HIGHCVSS 7.0EG 7.02025-05-24
A vulnerability has been found in Sangfor 零信任访问控制系统 aTrust 2.3.10.60 and classified as critical. Affected by this vulnerability is an unknown functionality in the library MSASN1.dll. The manipulation leads to uncontrolled…
- CVE-2025-5180HIGHCVSS 7.0EG 7.02025-05-26
A vulnerability, which was classified as critical, has been found in Wondershare Filmora 14.5.16. Affected by this issue is some unknown functionality in the library CRYPTBASE.dll of the file NFWCHK.exe of the component Installer. The mani…
- CVE-2025-5335HIGHCVSS 7.8EG 7.82025-06-10
A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to an untrusted search path being utilized in the Autodesk Installer application. Exploitation of this vulnerability may le…
- CVE-2025-59489HIGHCVSS 7.4EG 8.42025-10-03
Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the…
- CVE-2025-60718HIGHCVSS 7.8EG 7.82025-11-11
Untrusted search path in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.
- CVE-2025-64785HIGHCVSS 7.8EG 7.82025-12-09
Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the curr…
- CVE-2025-65078CRITICALCVSS 9.3EG 0.02026-02-03
An untrusted search path vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code.
- CVE-2025-67722HIGHCVSS 7.8EG 7.82025-12-16
FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to versions 16.0.45 and 17.0.24 of the FreePBX framework, an authenticated local privilege escalation exists in the deprecated FreePBX startup …
- CVE-2025-9000HIGHCVSS 7.0EG 7.02025-08-15
A vulnerability was found in Mechrevo Control Center GX V2 5.56.51.48. Affected by this vulnerability is an unknown functionality of the component reg File Handler. The manipulation leads to uncontrolled search path. It is possible to laun…
- CVE-2025-9016HIGHCVSS 7.0EG 7.02025-08-15
A vulnerability was identified in Mechrevo Control Center GX V2 5.56.51.48. This affects an unknown part of the file C:\Program Files\OEM\机械革命控制中心\AiStoneService\MyControlCenter\Command of the component Powershell Script Ha…
- CVE-2025-9267HIGHCVSS 7.0EG 0.02025-09-26
In Seagate Toolkit on Windows a vulnerability exists in the Toolkit Installer prior to versions 2.35.0.6 where it attempts to load DLLs from the current working directory without validating their origin or integrity. This behavior can be…
- CVE-2026-0251MEDIUMCVSS 5.9EG 5.92026-05-13
Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administra…
Map vulnerabilities like CWE-426 to your infrastructure
EchelonGraph correlates every CVE — across CWE-426 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →