Skip to content
Noroxi

CWE-427 · 1,149 records

Uncontrolled Search Path Element

CVEs in this class

1,148 records

  • CVE-2020-27955
    64This week

    Git LFS 2.12.0 allows Remote Code Execution.

    CriticalCVSS 9.8WeaponizedEPSS 82%

    git large file storage project · git large file storageNov 5, 2020

  • CVE-2020-3153
    64This week

    Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability

    MediumCVSS 6.5KEVWeaponizedEPSS 28%

    cisco · anyconnect secure mobility clientFeb 19, 2020

  • CVE-2020-3433
    64This week

    Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability

    HighCVSS 7.8KEVWeaponizedEPSS 10%

    cisco · anyconnect secure mobility clientAug 17, 2020

  • Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the ta

    CriticalCVSS 9.8No exploitEPSS 46%

    microsoft · skypeMar 23, 2017

  • Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability.

    CriticalCVSS 9.8No exploitEPSS 8%

    adobe · digital editionsJun 20, 2017

  • Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability.

    CriticalCVSS 9.8No exploitEPSS 8%

    adobe · digital editionsJun 20, 2017

  • Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability.

    CriticalCVSS 9.8No exploitEPSS 7%

    adobe · digital editionsJun 20, 2017

  • Adobe Connect versions 9.7.5 and earlier have an Insecure Library Loading vulnerability.

    CriticalCVSS 9.8No exploitEPSS 4%

    adobe · connectJul 20, 2018

  • STARFACE UCC Client before 6.7.1.204 on WIndows allows binary planting to execute code with System rights, aka usd-2020-0006.

    CriticalCVSS 9.8No exploitEPSS 3%

    starface · unified communication \& collaboration clientApr 2, 2020

  • SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.

    CriticalCVSS 9.8No exploitEPSS 3%

    solarwinds · orion platformMar 1, 2019

  • The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the current working director

    CriticalCVSS 9.8No exploitEPSS 2%

    debian · debian linuxFeb 8, 2019

  • An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker to achieve a remote c

    CriticalCVSS 9.8No exploitEPSS 2%

    trendmicro · apex oneMar 10, 2023

  • git-bug before 0.7.2 has an Uncontrolled Search Path Element.

    CriticalCVSS 9.8No exploitEPSS 2%

    git-bug project · git-bugMar 22, 2021

  • An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS.

    CriticalCVSS 9.8No exploitEPSS 1%

    mattermost · mattermost desktopJun 19, 2020

  • Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0

    CriticalCVSS 9.8No exploitEPSS 1%

    nec · expresscluster xNov 8, 2022

  • An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package liste

    CriticalCVSS 9.8No exploitEPSS 1%

    plone · plone docker official imageFeb 5, 2024

  • A dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted PyPI package to the c

    CriticalCVSS 9.8No exploitEPSS 1%

    pipreqs project · pipreqsJun 30, 2023

  • Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files.

    CriticalCVSS 9.8No exploitEPSS 1%

    foxit · pdf readerFeb 10, 2022

  • CVE-2025-4981
    39Monitor

    Path Traversal Leading to RCE by Any Authenticated Mattermost User

    CriticalCVSS 9.9No exploitEPSS 1%

    mattermost · mattermost serverJun 20, 2025

  • NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape.

    CriticalCVSS 9.9No exploitEPSS 1%

    nvidia · openshellAug 25, 2026

  • An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x be

    CriticalCVSS 9.8No exploitEPSS 1%

    enterprisedb · postgres advanced serverDec 12, 2023

  • IBM i is Affected By Remote Code Execution Vulnerability []

    CriticalCVSS 9.9No exploitEPSS 1%

    ibm · iAug 12, 2026

  • Traversal Path on PHP file

    CriticalCVSS 9.8No exploitEPSS 1%

    artica · pandora fmsNov 23, 2023

  • Sublime Text 3 Build 3208 or prior for MacOS is vulnerable to Dylib Injection.

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    sublimetext · sublime text 3Dec 9, 2025

  • An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software.

    CriticalCVSS 9.8No exploitEPSS 0%

    google · androidApr 17, 2020

All vulnerability classes