CWE-427 · 1,149 records
Uncontrolled Search Path Element
CVEs in this class
1,148 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
64This week | CVE-2020-27955Weaponized | Git LFS 2.12.0 allows Remote Code Execution.git large file storage project · git large file storage · CWE-427 | Critical9.8 | — | 82.3% | Nov 5, 2020 |
64This week | CVE-2020-3153Weaponized | Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerabilitycisco · anyconnect secure mobility client · CWE-427 | Medium6.5 | KEV | 28.3% | Feb 19, 2020 |
64This week | CVE-2020-3433Weaponized | Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerabilitycisco · anyconnect secure mobility client · CWE-427 | High7.8 | KEV | 10.0% | Aug 17, 2020 |
53Plan | CVE-2017-6517No exploit | Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the tamicrosoft · skype · CWE-427 | Critical9.8 | — | 46.3% | Mar 23, 2017 |
42Plan | CVE-2017-3090No exploit | Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability.adobe · digital editions · CWE-427 | Critical9.8 | — | 8.5% | Jun 20, 2017 |
42Plan | CVE-2017-3092No exploit | Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability.adobe · digital editions · CWE-427 | Critical9.8 | — | 8.5% | Jun 20, 2017 |
41Plan | CVE-2017-3097No exploit | Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability.adobe · digital editions · CWE-427 | Critical9.8 | — | 7.1% | Jun 20, 2017 |
40Plan | CVE-2018-12805No exploit | Adobe Connect versions 9.7.5 and earlier have an Insecure Library Loading vulnerability.adobe · connect · CWE-427 | Critical9.8 | — | 4.1% | Jul 20, 2018 |
40Plan | CVE-2020-10515No exploit | STARFACE UCC Client before 6.7.1.204 on WIndows allows binary planting to execute code with System rights, aka usd-2020-0006.starface · unified communication \& collaboration client · CWE-427 | Critical9.8 | — | 2.9% | Apr 2, 2020 |
40Plan | CVE-2019-9546No exploit | SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.solarwinds · orion platform · CWE-427 | Critical9.8 | — | 2.8% | Mar 1, 2019 |
40Plan | CVE-2019-7653No exploit | The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the current working directordebian · debian linux · CWE-427 | Critical9.8 | — | 2.3% | Feb 8, 2019 |
40Plan | CVE-2023-25143No exploit | An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker to achieve a remote ctrendmicro · apex one · CWE-427 | Critical9.8 | — | 1.7% | Mar 10, 2023 |
40Plan | CVE-2021-28955No exploit | git-bug before 0.7.2 has an Uncontrolled Search Path Element.git-bug project · git-bug · CWE-427 | Critical9.8 | — | 1.7% | Mar 22, 2021 |
39Monitor | CVE-2019-20856No exploit | An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS.mattermost · mattermost desktop · CWE-427 | Critical9.8 | — | 1.4% | Jun 19, 2020 |
39Monitor | CVE-2022-34825No exploit | Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0nec · expresscluster x · CWE-427 | Critical9.8 | — | 1.3% | Nov 8, 2022 |
39Monitor | CVE-2024-23054No exploit | An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listeplone · plone docker official image · CWE-427 | Critical9.8 | — | 1.3% | Feb 5, 2024 |
39Monitor | CVE-2023-31543No exploit | A dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted PyPI package to the cpipreqs project · pipreqs · CWE-427 | Critical9.8 | — | 1.2% | Jun 30, 2023 |
39Monitor | CVE-2022-24955No exploit | Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files.foxit · pdf reader · CWE-427 | Critical9.8 | — | 1.1% | Feb 10, 2022 |
39Monitor | CVE-2025-4981No exploit | Path Traversal Leading to RCE by Any Authenticated Mattermost Usermattermost · mattermost server · CWE-427 | Critical9.9 | — | 0.8% | Jun 20, 2025 |
39Monitor | CVE-2026-65093No exploit | NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape.nvidia · openshell · CWE-427 | Critical9.9 | — | 0.8% | Aug 25, 2026 |
39Monitor | CVE-2023-41117No exploit | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x beenterprisedb · postgres advanced server · CWE-427 | Critical9.8 | — | 0.8% | Dec 12, 2023 |
39Monitor | CVE-2026-16860No exploit | IBM i is Affected By Remote Code Execution Vulnerability []ibm · i · CWE-427 | Critical9.9 | — | 0.7% | Aug 12, 2026 |
39Monitor | CVE-2023-41790No exploit | Traversal Path on PHP fileartica · pandora fms · CWE-427 | Critical9.8 | — | 0.6% | Nov 23, 2023 |
39Monitor | CVE-2025-65741Proof of concept | Sublime Text 3 Build 3208 or prior for MacOS is vulnerable to Dylib Injection.sublimetext · sublime text 3 · CWE-427 | Critical9.8 | — | 0.5% | Dec 9, 2025 |
39Monitor | CVE-2019-20780No exploit | An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software.google · android · CWE-427 | Critical9.8 | — | 0.4% | Apr 17, 2020 |
- CVE-2020-2795564This week
Git LFS 2.12.0 allows Remote Code Execution.
CriticalCVSS 9.8WeaponizedEPSS 82%git large file storage project · git large file storageNov 5, 2020
- CVE-2020-315364This week
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
MediumCVSS 6.5KEVWeaponizedEPSS 28%cisco · anyconnect secure mobility clientFeb 19, 2020
- CVE-2020-343364This week
Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 10%cisco · anyconnect secure mobility clientAug 17, 2020
- CVE-2017-651753Plan
Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the ta
CriticalCVSS 9.8No exploitEPSS 46%microsoft · skypeMar 23, 2017
- CVE-2017-309042Plan
Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability.
CriticalCVSS 9.8No exploitEPSS 8%adobe · digital editionsJun 20, 2017
- CVE-2017-309242Plan
Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability.
CriticalCVSS 9.8No exploitEPSS 8%adobe · digital editionsJun 20, 2017
- CVE-2017-309741Plan
Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability.
CriticalCVSS 9.8No exploitEPSS 7%adobe · digital editionsJun 20, 2017
- CVE-2018-1280540Plan
Adobe Connect versions 9.7.5 and earlier have an Insecure Library Loading vulnerability.
CriticalCVSS 9.8No exploitEPSS 4%adobe · connectJul 20, 2018
- CVE-2020-1051540Plan
STARFACE UCC Client before 6.7.1.204 on WIndows allows binary planting to execute code with System rights, aka usd-2020-0006.
CriticalCVSS 9.8No exploitEPSS 3%starface · unified communication \& collaboration clientApr 2, 2020
- CVE-2019-954640Plan
SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.
CriticalCVSS 9.8No exploitEPSS 3%solarwinds · orion platformMar 1, 2019
- CVE-2019-765340Plan
The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the current working director
CriticalCVSS 9.8No exploitEPSS 2%debian · debian linuxFeb 8, 2019
- CVE-2023-2514340Plan
An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker to achieve a remote c
CriticalCVSS 9.8No exploitEPSS 2%trendmicro · apex oneMar 10, 2023
- CVE-2021-2895540Plan
git-bug before 0.7.2 has an Uncontrolled Search Path Element.
CriticalCVSS 9.8No exploitEPSS 2%git-bug project · git-bugMar 22, 2021
- CVE-2019-2085639Monitor
An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS.
CriticalCVSS 9.8No exploitEPSS 1%mattermost · mattermost desktopJun 19, 2020
- CVE-2022-3482539Monitor
Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0
CriticalCVSS 9.8No exploitEPSS 1%nec · expresscluster xNov 8, 2022
- CVE-2024-2305439Monitor
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package liste
CriticalCVSS 9.8No exploitEPSS 1%plone · plone docker official imageFeb 5, 2024
- CVE-2023-3154339Monitor
A dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted PyPI package to the c
CriticalCVSS 9.8No exploitEPSS 1%pipreqs project · pipreqsJun 30, 2023
- CVE-2022-2495539Monitor
Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files.
CriticalCVSS 9.8No exploitEPSS 1%foxit · pdf readerFeb 10, 2022
- CVE-2025-498139Monitor
Path Traversal Leading to RCE by Any Authenticated Mattermost User
CriticalCVSS 9.9No exploitEPSS 1%mattermost · mattermost serverJun 20, 2025
- CVE-2026-6509339Monitor
NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape.
CriticalCVSS 9.9No exploitEPSS 1%nvidia · openshellAug 25, 2026
- CVE-2023-4111739Monitor
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x be
CriticalCVSS 9.8No exploitEPSS 1%enterprisedb · postgres advanced serverDec 12, 2023
- CVE-2026-1686039Monitor
IBM i is Affected By Remote Code Execution Vulnerability []
CriticalCVSS 9.9No exploitEPSS 1%ibm · iAug 12, 2026
- CVE-2023-4179039Monitor
Traversal Path on PHP file
CriticalCVSS 9.8No exploitEPSS 1%artica · pandora fmsNov 23, 2023
- CVE-2025-6574139Monitor
Sublime Text 3 Build 3208 or prior for MacOS is vulnerable to Dylib Injection.
CriticalCVSS 9.8Proof of conceptEPSS 1%sublimetext · sublime text 3Dec 9, 2025
- CVE-2019-2078039Monitor
An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software.
CriticalCVSS 9.8No exploitEPSS 0%google · androidApr 17, 2020