Skip to content
Noroxi

CWE-428 · 440 records

Unquoted Search Path or Element

CVEs in this class

440 records

  • CVE-2023-38408
    63This week

    The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if

    CriticalCVSS 9.8Proof of conceptEPSS 80%

    openbsd · opensshJul 19, 2023

  • An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an attacker to ga

    CriticalCVSS 9.8Proof of conceptEPSS 2%

    fortinet · forticlientMar 12, 2020

  • CVE-2020-9292
    39Monitor

    An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated privileges via the Ao

    CriticalCVSS 9.8No exploitEPSS 2%

    fortinet · fortisiem windows agentJun 4, 2020

  • Mitsubishi Electric Factory Automation Engineering Products Unquoted Search Path or Element

    CriticalCVSS 9.8No exploitEPSS 1%

    mitsubishielectric · c controller interface module utilityFeb 11, 2022

  • CVE-2019-8459
    39Monitor

    Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the pa

    CriticalCVSS 9.8No exploitEPSS 1%

    checkpoint · jumbo hotfix for endpoint security serverJun 20, 2019

  • An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate

    CriticalCVSS 9.8No exploitEPSS 1%

    justsystems · atok medical 2Aug 16, 2022

  • An unquoted service path vulnerability in the 12d Synergy Server and File Replication Server components may allow an attacker to gain elevat

    CriticalCVSS 9.1No exploitEPSS 1%

    12dsynergy · 12dsynergyFeb 19, 2024

  • CVE-2025-8070
    36Monitor

    Windows service registered with an unquoted ImagePath vulnerability in the system registry

    CriticalCVSS 9.2No exploitEPSS 0%

    asustor · abp and aesJul 23, 2025

  • The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.

    HighCVSS 8.8No exploitEPSS 1%

    1e · clientDec 29, 2020

  • The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.

    HighCVSS 8.8No exploitEPSS 1%

    1e · clientDec 29, 2020

  • CVE-2016-5793
    35Monitor

    Unquoted Windows search path vulnerability in Moxa Active OPC Server before 2.4.19 allows local users to gain privileges via a Trojan horse

    HighCVSS 8.8No exploitEPSS 0%

    moxa · active opc serverSep 24, 2016

  • Insecure service configuration – unquoted path

    HighCVSS 8.8No exploitEPSS 0%

    bizerba · _connect.brainOct 31, 2025

  • Netgate AMITI Antivirus build 23.0.305 Unquoted Service Path Privilege Escalation

    HighCVSS 8.5No exploitEPSS 1%

    netgate · amiti antivirusApr 4, 2026

  • NETGATE Registry Cleaner build 16.0.205 Unquoted Service Path Privilege Escalation

    HighCVSS 8.5No exploitEPSS 1%

    netgate · registry cleanerApr 4, 2026

  • VeeVPN 1.6.1 - Unquoted Service Path Remote Code Execution

    HighCVSS 8.5No exploitEPSS 0%

    veepn · veepnDec 4, 2025

  • FLAME II MODEM USB - Unquoted Service Path

    HighCVSS 8.5No exploitEPSS 0%

    telcel · flame ii modem usbJan 13, 2026

  • Genexus Protection Server 9.7.2.10 Unquoted Service Path Privilege Escalation

    HighCVSS 8.7No exploitEPSS 0%

    genexus · genexus protection serverDec 11, 2025

  • Amiti Antivirus 25.0.640 - Unquoted Service Path Vulnerability

    HighCVSS 8.5No exploitEPSS 0%

    netgate · amiti antivirusFeb 4, 2026

  • NETGATE Data Backup 3.0.620 - 'NGDatBckpSrv' Unquoted Service Path

    HighCVSS 8.5No exploitEPSS 0%

    netgate · data backupFeb 4, 2026

  • Dynojet Power Core 2.3.0 - Unquoted Service Path

    HighCVSS 8.5No exploitEPSS 0%

    dynojet · power coreJan 15, 2026

  • Wondershare Dr.Fone 11.4.9 - 'DFWSIDService' Unquoted Service Path

    HighCVSS 8.5No exploitEPSS 0%

    wondershare · dr.foneJan 13, 2026

  • Wondershare MobileTrans 3.5.9 - 'ElevationService' Unquoted Service Path

    HighCVSS 8.5No exploitEPSS 0%

    wondershare · mobiletransJan 13, 2026

  • Flexsense DiskBoss Service Unquoted Service Path Vulnerability

    HighCVSS 8.5No exploitEPSS 0%

    flexsense · diskbossDec 5, 2025

  • Brother BRAgent 1.38 - 'WBA_Agent_Client' Unquoted Service Path

    HighCVSS 8.5No exploitEPSS 0%

    brother · bragentJan 15, 2026

  • TotalAV 5.15.69 - Unquoted Service Path

    HighCVSS 8.5No exploitEPSS 0%

    totalav · totalavJan 16, 2026

All vulnerability classes