CWE-428 · 440 records
Unquoted Search Path or Element
CVEs in this class
440 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
63This week | CVE-2023-38408Proof of concept | The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if openbsd · openssh · CWE-428 | Critical9.8 | — | 79.7% | Jul 19, 2023 |
40Plan | CVE-2019-17658Proof of concept | An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an attacker to gafortinet · forticlient · CWE-428 | Critical9.8 | — | 2.2% | Mar 12, 2020 |
39Monitor | CVE-2020-9292No exploit | An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated privileges via the Aofortinet · fortisiem windows agent · CWE-428 | Critical9.8 | — | 1.5% | Jun 4, 2020 |
39Monitor | CVE-2020-14521No exploit | Mitsubishi Electric Factory Automation Engineering Products Unquoted Search Path or Elementmitsubishielectric · c controller interface module utility · CWE-428 | Critical9.8 | — | 1.3% | Feb 11, 2022 |
39Monitor | CVE-2019-8459No exploit | Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the pacheckpoint · jumbo hotfix for endpoint security server · CWE-428 | Critical9.8 | — | 1.2% | Jun 20, 2019 |
39Monitor | CVE-2022-36344No exploit | An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate justsystems · atok medical 2 · CWE-428 | Critical9.8 | — | 0.9% | Aug 16, 2022 |
36Monitor | CVE-2024-24722No exploit | An unquoted service path vulnerability in the 12d Synergy Server and File Replication Server components may allow an attacker to gain elevat12dsynergy · 12dsynergy · CWE-428 | Critical9.1 | — | 0.6% | Feb 19, 2024 |
36Monitor | CVE-2025-8070No exploit | Windows service registered with an unquoted ImagePath vulnerability in the system registryasustor · abp and aes · CWE-428 | Critical9.2 | — | 0.2% | Jul 23, 2025 |
35Monitor | CVE-2020-27645No exploit | The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.1e · client · CWE-428 | High8.8 | — | 1.2% | Dec 29, 2020 |
35Monitor | CVE-2020-27644No exploit | The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.1e · client · CWE-428 | High8.8 | — | 1.2% | Dec 29, 2020 |
35Monitor | CVE-2016-5793No exploit | Unquoted Windows search path vulnerability in Moxa Active OPC Server before 2.4.19 allows local users to gain privileges via a Trojan horse moxa · active opc server · CWE-428 | High8.8 | — | 0.4% | Sep 24, 2016 |
35Monitor | CVE-2025-12507No exploit | Insecure service configuration – unquoted pathbizerba · _connect.brain · CWE-428 | High8.8 | — | 0.1% | Oct 31, 2025 |
34Monitor | CVE-2016-20058No exploit | Netgate AMITI Antivirus build 23.0.305 Unquoted Service Path Privilege Escalationnetgate · amiti antivirus · CWE-428 | High8.5 | — | 0.7% | Apr 4, 2026 |
34Monitor | CVE-2016-20057No exploit | NETGATE Registry Cleaner build 16.0.205 Unquoted Service Path Privilege Escalationnetgate · registry cleaner · CWE-428 | High8.5 | — | 0.6% | Apr 4, 2026 |
34Monitor | CVE-2025-66575No exploit | VeeVPN 1.6.1 - Unquoted Service Path Remote Code Executionveepn · veepn · CWE-428 | High8.5 | — | 0.5% | Dec 4, 2025 |
34Monitor | CVE-2022-50935No exploit | FLAME II MODEM USB - Unquoted Service Pathtelcel · flame ii modem usb · CWE-428 | High8.5 | — | 0.4% | Jan 13, 2026 |
34Monitor | CVE-2024-58288No exploit | Genexus Protection Server 9.7.2.10 Unquoted Service Path Privilege Escalationgenexus · genexus protection server · CWE-428 | High8.7 | — | 0.4% | Dec 11, 2025 |
34Monitor | CVE-2019-25269No exploit | Amiti Antivirus 25.0.640 - Unquoted Service Path Vulnerabilitynetgate · amiti antivirus · CWE-428 | High8.5 | — | 0.4% | Feb 4, 2026 |
34Monitor | CVE-2019-25271No exploit | NETGATE Data Backup 3.0.620 - 'NGDatBckpSrv' Unquoted Service Pathnetgate · data backup · CWE-428 | High8.5 | — | 0.4% | Feb 4, 2026 |
34Monitor | CVE-2021-47773No exploit | Dynojet Power Core 2.3.0 - Unquoted Service Pathdynojet · power core · CWE-428 | High8.5 | — | 0.3% | Jan 15, 2026 |
34Monitor | CVE-2022-50901No exploit | Wondershare Dr.Fone 11.4.9 - 'DFWSIDService' Unquoted Service Pathwondershare · dr.fone · CWE-428 | High8.5 | — | 0.3% | Jan 13, 2026 |
34Monitor | CVE-2022-50903No exploit | Wondershare MobileTrans 3.5.9 - 'ElevationService' Unquoted Service Pathwondershare · mobiletrans · CWE-428 | High8.5 | — | 0.3% | Jan 13, 2026 |
34Monitor | CVE-2020-36879No exploit | Flexsense DiskBoss Service Unquoted Service Path Vulnerabilityflexsense · diskboss · CWE-428 | High8.5 | — | 0.3% | Dec 5, 2025 |
34Monitor | CVE-2020-36928No exploit | Brother BRAgent 1.38 - 'WBA_Agent_Client' Unquoted Service Pathbrother · bragent · CWE-428 | High8.5 | — | 0.3% | Jan 15, 2026 |
34Monitor | CVE-2021-47787No exploit | TotalAV 5.15.69 - Unquoted Service Pathtotalav · totalav · CWE-428 | High8.5 | — | 0.3% | Jan 16, 2026 |
- CVE-2023-3840863This week
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if
CriticalCVSS 9.8Proof of conceptEPSS 80%openbsd · opensshJul 19, 2023
- CVE-2019-1765840Plan
An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an attacker to ga
CriticalCVSS 9.8Proof of conceptEPSS 2%fortinet · forticlientMar 12, 2020
- CVE-2020-929239Monitor
An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated privileges via the Ao
CriticalCVSS 9.8No exploitEPSS 2%fortinet · fortisiem windows agentJun 4, 2020
- CVE-2020-1452139Monitor
Mitsubishi Electric Factory Automation Engineering Products Unquoted Search Path or Element
CriticalCVSS 9.8No exploitEPSS 1%mitsubishielectric · c controller interface module utilityFeb 11, 2022
- CVE-2019-845939Monitor
Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the pa
CriticalCVSS 9.8No exploitEPSS 1%checkpoint · jumbo hotfix for endpoint security serverJun 20, 2019
- CVE-2022-3634439Monitor
An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate
CriticalCVSS 9.8No exploitEPSS 1%justsystems · atok medical 2Aug 16, 2022
- CVE-2024-2472236Monitor
An unquoted service path vulnerability in the 12d Synergy Server and File Replication Server components may allow an attacker to gain elevat
CriticalCVSS 9.1No exploitEPSS 1%12dsynergy · 12dsynergyFeb 19, 2024
- CVE-2025-807036Monitor
Windows service registered with an unquoted ImagePath vulnerability in the system registry
CriticalCVSS 9.2No exploitEPSS 0%asustor · abp and aesJul 23, 2025
- CVE-2020-2764535Monitor
The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.
HighCVSS 8.8No exploitEPSS 1%1e · clientDec 29, 2020
- CVE-2020-2764435Monitor
The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.
HighCVSS 8.8No exploitEPSS 1%1e · clientDec 29, 2020
- CVE-2016-579335Monitor
Unquoted Windows search path vulnerability in Moxa Active OPC Server before 2.4.19 allows local users to gain privileges via a Trojan horse
HighCVSS 8.8No exploitEPSS 0%moxa · active opc serverSep 24, 2016
- CVE-2025-1250735Monitor
Insecure service configuration – unquoted path
HighCVSS 8.8No exploitEPSS 0%bizerba · _connect.brainOct 31, 2025
- CVE-2016-2005834Monitor
Netgate AMITI Antivirus build 23.0.305 Unquoted Service Path Privilege Escalation
HighCVSS 8.5No exploitEPSS 1%netgate · amiti antivirusApr 4, 2026
- CVE-2016-2005734Monitor
NETGATE Registry Cleaner build 16.0.205 Unquoted Service Path Privilege Escalation
HighCVSS 8.5No exploitEPSS 1%netgate · registry cleanerApr 4, 2026
- CVE-2025-6657534Monitor
VeeVPN 1.6.1 - Unquoted Service Path Remote Code Execution
HighCVSS 8.5No exploitEPSS 0%veepn · veepnDec 4, 2025
- CVE-2022-5093534Monitor
FLAME II MODEM USB - Unquoted Service Path
HighCVSS 8.5No exploitEPSS 0%telcel · flame ii modem usbJan 13, 2026
- CVE-2024-5828834Monitor
Genexus Protection Server 9.7.2.10 Unquoted Service Path Privilege Escalation
HighCVSS 8.7No exploitEPSS 0%genexus · genexus protection serverDec 11, 2025
- CVE-2019-2526934Monitor
Amiti Antivirus 25.0.640 - Unquoted Service Path Vulnerability
HighCVSS 8.5No exploitEPSS 0%netgate · amiti antivirusFeb 4, 2026
- CVE-2019-2527134Monitor
NETGATE Data Backup 3.0.620 - 'NGDatBckpSrv' Unquoted Service Path
HighCVSS 8.5No exploitEPSS 0%netgate · data backupFeb 4, 2026
- CVE-2021-4777334Monitor
Dynojet Power Core 2.3.0 - Unquoted Service Path
HighCVSS 8.5No exploitEPSS 0%dynojet · power coreJan 15, 2026
- CVE-2022-5090134Monitor
Wondershare Dr.Fone 11.4.9 - 'DFWSIDService' Unquoted Service Path
HighCVSS 8.5No exploitEPSS 0%wondershare · dr.foneJan 13, 2026
- CVE-2022-5090334Monitor
Wondershare MobileTrans 3.5.9 - 'ElevationService' Unquoted Service Path
HighCVSS 8.5No exploitEPSS 0%wondershare · mobiletransJan 13, 2026
- CVE-2020-3687934Monitor
Flexsense DiskBoss Service Unquoted Service Path Vulnerability
HighCVSS 8.5No exploitEPSS 0%flexsense · diskbossDec 5, 2025
- CVE-2020-3692834Monitor
Brother BRAgent 1.38 - 'WBA_Agent_Client' Unquoted Service Path
HighCVSS 8.5No exploitEPSS 0%brother · bragentJan 15, 2026
- CVE-2021-4778734Monitor
TotalAV 5.15.69 - Unquoted Service Path
HighCVSS 8.5No exploitEPSS 0%totalav · totalavJan 16, 2026