CWE-426— Untrusted Search Path
528 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-426page 7 of 11
- CVE-2022-25348HIGHCVSS 7.8EG 7.82022-03-31
Untrusted search path vulnerability in AttacheCase ver.4.0.2.7 and earlier allows an attacker to gain privileges and execute arbitrary code via a Trojan horse DLL in an unspecified directory.
- CVE-2022-25366HIGHCVSS 7.8EG 7.82022-02-19
Cryptomator through 1.6.5 allows DYLIB injection because, although it has the flag 0x1000 for Hardened Runtime, it has the com.apple.security.cs.disable-library-validation and com.apple.security.cs.allow-dyld-environment-variables entitlem…
- CVE-2022-26183HIGHCVSS 8.8EG 8.82022-03-21
PNPM v6.15.1 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute PNPM commands in a directory containing malicious content. This vulnerability occurs whe…
- CVE-2022-26184CRITICALCVSS 9.8EG 9.82022-03-21
Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute Poetry commands in a directory containing malicious content. This vulnerability occurs …
- CVE-2022-26488HIGHCVSS 7.0EG 7.02022-03-10
In Python before 3.10.3 on Windows, local users can gain privileges because the search path is inadequately secured. The installer may allow a local attacker to add user-writable directories to the system search path. To exploit, an admini…
- CVE-2022-26526HIGHCVSS 7.8EG 7.82022-03-17
Anaconda Anaconda3 (Anaconda Distribution) through 2021.11.0.0 and Miniconda3 through 4.11.0.0 can create a world-writable directory under %PROGRAMDATA% and place that directory into the system PATH environment variable. Thus, for example,…
- CVE-2022-28128HIGHCVSS 7.8EG 7.82022-03-31
Untrusted search path vulnerability in AttacheCase ver.3.6.1.0 and earlier allows an attacker to gain privileges and execute arbitrary code via a Trojan horse DLL in an unspecified directory.
- CVE-2022-28964HIGHCVSS 7.1EG 7.12022-05-20
An arbitrary file write vulnerability in Avast Premium Security before v21.11.2500 (build 21.11.6809.528) allows attackers to cause a Denial of Service (DoS) via a crafted DLL file.
- CVE-2022-29583HIGHCVSS 7.8EG 7.82022-04-22
service_windows.go in the kardianos service package for Go omits quoting that is sometimes needed for execution of a Windows service executable from the intended directory. NOTE: this finding could not be reproduced by its original reporte…
- CVE-2022-31012HIGHCVSS 8.2EG 8.22022-07-12
Git for Windows is a fork of Git that contains Windows-specific patches. This vulnerability in versions prior to 2.37.1 lets Git for Windows' installer execute a binary into `C:\mingw64\bin\git.exe` by mistake. This only happens upon a fre…
- CVE-2022-31253HIGHCVSS 7.1EG 7.82022-11-09
A Untrusted Search Path vulnerability in openldap2 of openSUSE Factory allows local attackers with control of the ldap user or group to change ownership of arbitrary directory entries to this user/group, leading to escalation to root. This…
- CVE-2022-35868MEDIUMCVSS 6.7EG 7.32023-02-14
A vulnerability has been identified in TIA Multiuser Server V14 (All versions), TIA Multiuser Server V15 (All versions < V15.1 Update 8), TIA Project-Server (All versions < V1.1), TIA Project-Server V16 (All versions), TIA Project-Server V…
- CVE-2022-36070HIGHCVSS 7.3EG 7.32022-09-07
Poetry is a dependency manager for Python. To handle dependencies that come from a Git repository, Poetry executes various commands, e.g. `git config`. These commands are being executed using the executable’s name and not its absolute pa…
- CVE-2022-36403HIGHCVSS 7.8EG 7.82022-09-08
Untrusted search path vulnerability in the installer of Device Software Manager prior to Ver.2.20.3.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
- CVE-2022-3734MEDIUMCVSS 6.3EG 9.82022-10-28
A vulnerability was found in a port or fork of Redis. It has been declared as critical. This vulnerability affects unknown code in the library C:/Program Files/Redis/dbghelp.dll. The manipulation leads to uncontrolled search path. The atta…
- CVE-2022-38060HIGHCVSS 8.8EG 8.82022-12-21
A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A misconfiguration in /etc/sudoers within a container can lead to increased privileges.
- CVE-2022-39245HIGHCVSS 8.4EG 8.42022-09-26
Mist is the command-line interface for the makedeb Package Repository. Prior to version 0.9.5, a user-provided `sudo` binary via the `PATH` variable can allow a local user to run arbitrary commands on the user's system with root permission…
- CVE-2022-41796HIGHCVSS 7.8EG 7.82022-10-24
Untrusted search path vulnerability in the installer of Content Transfer (for Windows) Ver.1.3 and prior allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
- CVE-2022-41953HIGHCVSS 8.6EG 8.62023-01-17
Git GUI is a convenient graphical tool that comes with Git for Windows. Its target audience is users who are uncomfortable with using Git on the command-line. Git GUI has a function to clone repositories. Immediately after the local clone …
- CVE-2022-43456MEDIUMCVSS 6.7EG 6.72023-08-11
Uncontrolled search path in some Intel(R) RST software before versions 16.8.5.1014.5, 17.11.3.1010.2, 18.7.6.1011.2 and 19.5.2.1049.5 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-4883HIGHCVSS 8.8EG 8.82023-02-07
A flaw was found in libXpm. When processing files with .Z or .gz extensions, the library calls external programs to compress and uncompress files, relying on the PATH environment variable to find these programs, which could allow a malicio…
- CVE-2022-4987HIGHCVSS 7.3EG 7.32026-04-03
Hirschmann Industrial HiVision version 08.1.03 prior to 08.1.04 and 08.2.00 contains a vulnerability in the execution of user-configured external applications that allows a local attacker to execute arbitrary binaries. Due to insufficient …
- CVE-2023-1521HIGHCVSS 7.8EG 7.82024-11-26
On Linux the sccache client can execute arbitrary code with the privileges of a local sccache server, by preloading the code in a shared library passed to LD_PRELOAD. If the server is run as root (which is the default when installing the…
- CVE-2023-21763HIGHCVSS 7.8EG 7.82023-01-10
Microsoft Exchange Server Elevation of Privilege Vulnerability
- CVE-2023-21764HIGHCVSS 7.8EG 7.82023-01-10
Microsoft Exchange Server Elevation of Privilege Vulnerability
- CVE-2023-22368HIGHCVSS 7.8EG 7.82023-02-15
Untrusted search path vulnerability in ELECOM Camera Assistant 1.00 and QuickFileDealer Ver.1.2.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
- CVE-2023-22743HIGHCVSS 7.2EG 7.22023-02-14
Git for Windows is the Windows port of the revision control system Git. Prior to Git for Windows version 2.39.2, by carefully crafting DLL and putting into a subdirectory of a specific name living next to the Git for Windows installer, Win…
- CVE-2023-23618HIGHCVSS 8.6EG 8.62023-02-14
Git for Windows is the Windows port of the revision control system Git. Prior to Git for Windows version 2.39.2, when `gitk` is run on Windows, it potentially runs executables from the current directory inadvertently, which can be exploite…
- CVE-2023-23920MEDIUMCVSS 4.2EG 4.22023-02-23
An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges.
- CVE-2023-26031HIGHCVSS 7.5EG 7.52023-11-16
Relative library resolution in linux container-executor binary in Apache Hadoop 3.3.1-3.3.4 on Linux allows local user to gain root privileges. If the YARN cluster is accepting work from remote (authenticated) users, this MAY permit remote…
- CVE-2023-26036HIGHCVSS 8.1EG 8.12023-02-25
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain a Local File Inclusion (Untrusted Search Path) vulnerabilit…
- CVE-2023-26038MEDIUMCVSS 5.4EG 5.42023-02-25
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain a Local File Inclusion (Untrusted Search Path) vulnerabilit…
- CVE-2023-26358HIGHCVSS 8.6EG 8.62023-03-22
Creative Cloud version 5.9.1 (and earlier) is affected by an Untrusted Search Path vulnerability that might allow attackers to execute their own programs, access unauthorized data files, or modify configuration in unexpected ways. If the a…
- CVE-2023-27759HIGHCVSS 7.8EG 7.82023-04-04
An issue found in Wondershare Technology Co, Ltd Edrawmind v.10.0.6 allows a remote attacker to executea arbitrary commands via the WindowsCodescs.dll file.
- CVE-2023-27760HIGHCVSS 7.8EG 7.82023-04-04
An issue found in Wondershare Technology Co, Ltd Filmora v.12.0.9 allows a remote attacker to execute arbitrary commands via the filmora_setup_full846.exe.
- CVE-2023-27761HIGHCVSS 7.8EG 7.82023-04-04
An issue found in Wondershare Technology Co., Ltd UniConverter v.14.0.0 allows a remote attacker to execute arbitrary commands via the uniconverter14_64bit_setup_full14204.exe file.
- CVE-2023-27762HIGHCVSS 7.8EG 7.82023-04-04
An issue found in Wondershare Technology Co., Ltd DemoCreator v.6.0.0 allows a remote attacker to execute arbitrary commands via the democreator_setup_full7743.exe file.
- CVE-2023-27763HIGHCVSS 7.8EG 7.82023-04-04
An issue found in Wondershare Technology Co.,Ltd MobileTrans v.4.0.2 allows a remote attacker to execute arbitrary commands via the mobiletrans_setup_full5793.exe file.
- CVE-2023-27764HIGHCVSS 7.8EG 7.82023-04-04
An issue found in Wondershare Technology Co.,Ltd Repairit v.3.5.4 allows a remote attacker to execute arbitrary commands via the repairit_setup_full5913.exe file.
- CVE-2023-27765HIGHCVSS 7.8EG 7.82023-04-04
An issue found in Wondershare Technology Co.,Ltd Recoverit v.10.6.3 allows a remote attacker to execute arbitrary commands via the recoverit_setup_full4134.exe file.
- CVE-2023-27766HIGHCVSS 7.8EG 7.82023-04-04
An issue found in Wondershare Technology Co.,Ltd Anireel 1.5.4 allows a remote attacker to execute arbitrary commands via the anireel_setup_full9589.exe file.
- CVE-2023-27767HIGHCVSS 7.8EG 7.82023-04-04
An issue found in Wondershare Technology Co.,Ltd Dr.Fone v.12.4.9 allows a remote attacker to execute arbitrary commands via the drfone_setup_full3360.exe file.
- CVE-2023-27768HIGHCVSS 7.8EG 7.82023-04-04
An issue found in Wondershare Technology Co.,Ltd PDFelement v9.1.1 allows a remote attacker to execute arbitrary commands via the pdfelement-pro_setup_full5239.exe file.
- CVE-2023-27769HIGHCVSS 7.8EG 7.82023-04-04
An issue found in Wondershare Technology Co.,Ltd PDF Reader v.1.0.1 allows a remote attacker to execute arbitrary commands via the pdfreader_setup_full13143.exe file.
- CVE-2023-27770HIGHCVSS 7.8EG 7.82023-04-04
An issue found in Wondershare Technology Co.,Ltd Edraw-max v.12.0.4 allows a remote attacker to execute arbitrary commands via the edraw-max_setup_full5371.exe file.
- CVE-2023-27771HIGHCVSS 7.8EG 7.82023-04-04
An issue found in Wondershare Technology Co.,Ltd Creative Centerr v.1.0.8 allows a remote attacker to execute arbitrary commands via the wondershareCC_setup_full10819.exe file.
- CVE-2023-28143MEDIUMCVSS 6.7EG 6.72023-04-18
Qualys Cloud Agent for macOS (versions 2.5.1-75 before 3.7) installer allows a local escalation of privilege bounded only to the time of installation and only on older macOSX (macOS 10.15 and older) versions. Attackers may exploit incorre…
- CVE-2023-29299MEDIUMCVSS 4.7EG 4.72023-08-10
Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Untrusted Search Path vulnerability that could lead to Application denial-of-service. An attacker could leverage this vulnerability …
- CVE-2023-29790HIGHCVSS 7.5EG 7.52023-05-12
kodbox 1.2.x through 1.3.7 has a Sensitive Information Leakage issue.
- CVE-2023-30330CRITICALCVSS 9.8EG 9.82023-05-12
SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42300/generic/gn_defaultframe/2.0/defaultframe_filter.php.
Map vulnerabilities like CWE-426 to your infrastructure
EchelonGraph correlates every CVE — across CWE-426 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →