CWE-427 · 1 149 записей
Uncontrolled Search Path Element
CVE этого класса
1 148 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
64На этой неделе | CVE-2020-27955Готовый эксплойт | Git LFS 2.12.0 allows Remote Code Execution.git large file storage project · git large file storage · CWE-427 | Критическая9,8 | — | 82,3 % | 5 нояб. 2020 г. |
64На этой неделе | CVE-2020-3153Готовый эксплойт | Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerabilitycisco · anyconnect secure mobility client · CWE-427 | Средняя6,5 | KEV | 28,3 % | 19 февр. 2020 г. |
64На этой неделе | CVE-2020-3433Готовый эксплойт | Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerabilitycisco · anyconnect secure mobility client · CWE-427 | Высокая7,8 | KEV | 10,0 % | 17 авг. 2020 г. |
53В плане | CVE-2017-6517Эксплойта нет | Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the tamicrosoft · skype · CWE-427 | Критическая9,8 | — | 46,3 % | 23 мар. 2017 г. |
42В плане | CVE-2017-3090Эксплойта нет | Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability.adobe · digital editions · CWE-427 | Критическая9,8 | — | 8,5 % | 20 июн. 2017 г. |
42В плане | CVE-2017-3092Эксплойта нет | Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability.adobe · digital editions · CWE-427 | Критическая9,8 | — | 8,5 % | 20 июн. 2017 г. |
41В плане | CVE-2017-3097Эксплойта нет | Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability.adobe · digital editions · CWE-427 | Критическая9,8 | — | 7,1 % | 20 июн. 2017 г. |
40В плане | CVE-2018-12805Эксплойта нет | Adobe Connect versions 9.7.5 and earlier have an Insecure Library Loading vulnerability.adobe · connect · CWE-427 | Критическая9,8 | — | 4,1 % | 20 июл. 2018 г. |
40В плане | CVE-2020-10515Эксплойта нет | STARFACE UCC Client before 6.7.1.204 on WIndows allows binary planting to execute code with System rights, aka usd-2020-0006.starface · unified communication \& collaboration client · CWE-427 | Критическая9,8 | — | 2,9 % | 2 апр. 2020 г. |
40В плане | CVE-2019-9546Эксплойта нет | SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.solarwinds · orion platform · CWE-427 | Критическая9,8 | — | 2,8 % | 1 мар. 2019 г. |
40В плане | CVE-2019-7653Эксплойта нет | The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the current working directordebian · debian linux · CWE-427 | Критическая9,8 | — | 2,3 % | 8 февр. 2019 г. |
40В плане | CVE-2023-25143Эксплойта нет | An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker to achieve a remote ctrendmicro · apex one · CWE-427 | Критическая9,8 | — | 1,7 % | 10 мар. 2023 г. |
40В плане | CVE-2021-28955Эксплойта нет | git-bug before 0.7.2 has an Uncontrolled Search Path Element.git-bug project · git-bug · CWE-427 | Критическая9,8 | — | 1,7 % | 22 мар. 2021 г. |
39Наблюдать | CVE-2019-20856Эксплойта нет | An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS.mattermost · mattermost desktop · CWE-427 | Критическая9,8 | — | 1,4 % | 19 июн. 2020 г. |
39Наблюдать | CVE-2022-34825Эксплойта нет | Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0nec · expresscluster x · CWE-427 | Критическая9,8 | — | 1,3 % | 8 нояб. 2022 г. |
39Наблюдать | CVE-2024-23054Эксплойта нет | An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listeplone · plone docker official image · CWE-427 | Критическая9,8 | — | 1,3 % | 5 февр. 2024 г. |
39Наблюдать | CVE-2023-31543Эксплойта нет | A dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted PyPI package to the cpipreqs project · pipreqs · CWE-427 | Критическая9,8 | — | 1,2 % | 30 июн. 2023 г. |
39Наблюдать | CVE-2022-24955Эксплойта нет | Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files.foxit · pdf reader · CWE-427 | Критическая9,8 | — | 1,1 % | 10 февр. 2022 г. |
39Наблюдать | CVE-2025-4981Эксплойта нет | Path Traversal Leading to RCE by Any Authenticated Mattermost Usermattermost · mattermost server · CWE-427 | Критическая9,9 | — | 0,8 % | 20 июн. 2025 г. |
39Наблюдать | CVE-2026-65093Эксплойта нет | NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape.nvidia · openshell · CWE-427 | Критическая9,9 | — | 0,8 % | 25 авг. 2026 г. |
39Наблюдать | CVE-2023-41117Эксплойта нет | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x beenterprisedb · postgres advanced server · CWE-427 | Критическая9,8 | — | 0,8 % | 12 дек. 2023 г. |
39Наблюдать | CVE-2026-16860Эксплойта нет | IBM i is Affected By Remote Code Execution Vulnerability []ibm · i · CWE-427 | Критическая9,9 | — | 0,7 % | 12 авг. 2026 г. |
39Наблюдать | CVE-2023-41790Эксплойта нет | Traversal Path on PHP fileartica · pandora fms · CWE-427 | Критическая9,8 | — | 0,6 % | 23 нояб. 2023 г. |
39Наблюдать | CVE-2025-65741Proof of concept | Sublime Text 3 Build 3208 or prior for MacOS is vulnerable to Dylib Injection.sublimetext · sublime text 3 · CWE-427 | Критическая9,8 | — | 0,5 % | 9 дек. 2025 г. |
39Наблюдать | CVE-2019-20780Эксплойта нет | An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software.google · android · CWE-427 | Критическая9,8 | — | 0,4 % | 17 апр. 2020 г. |
- CVE-2020-2795564На этой неделе
Git LFS 2.12.0 allows Remote Code Execution.
КритическаяCVSS 9,8Готовый эксплойтEPSS 82 %git large file storage project · git large file storage5 нояб. 2020 г.
- CVE-2020-315364На этой неделе
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
СредняяCVSS 6,5KEVГотовый эксплойтEPSS 28 %cisco · anyconnect secure mobility client19 февр. 2020 г.
- CVE-2020-343364На этой неделе
Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 10 %cisco · anyconnect secure mobility client17 авг. 2020 г.
- CVE-2017-651753В плане
Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the ta
КритическаяCVSS 9,8Эксплойта нетEPSS 46 %microsoft · skype23 мар. 2017 г.
- CVE-2017-309042В плане
Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %adobe · digital editions20 июн. 2017 г.
- CVE-2017-309242В плане
Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %adobe · digital editions20 июн. 2017 г.
- CVE-2017-309741В плане
Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %adobe · digital editions20 июн. 2017 г.
- CVE-2018-1280540В плане
Adobe Connect versions 9.7.5 and earlier have an Insecure Library Loading vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %adobe · connect20 июл. 2018 г.
- CVE-2020-1051540В плане
STARFACE UCC Client before 6.7.1.204 on WIndows allows binary planting to execute code with System rights, aka usd-2020-0006.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %starface · unified communication \& collaboration client2 апр. 2020 г.
- CVE-2019-954640В плане
SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %solarwinds · orion platform1 мар. 2019 г.
- CVE-2019-765340В плане
The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the current working director
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %debian · debian linux8 февр. 2019 г.
- CVE-2023-2514340В плане
An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker to achieve a remote c
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %trendmicro · apex one10 мар. 2023 г.
- CVE-2021-2895540В плане
git-bug before 0.7.2 has an Uncontrolled Search Path Element.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %git-bug project · git-bug22 мар. 2021 г.
- CVE-2019-2085639Наблюдать
An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mattermost · mattermost desktop19 июн. 2020 г.
- CVE-2022-3482539Наблюдать
Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nec · expresscluster x8 нояб. 2022 г.
- CVE-2024-2305439Наблюдать
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package liste
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %plone · plone docker official image5 февр. 2024 г.
- CVE-2023-3154339Наблюдать
A dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted PyPI package to the c
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %pipreqs project · pipreqs30 июн. 2023 г.
- CVE-2022-2495539Наблюдать
Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %foxit · pdf reader10 февр. 2022 г.
- CVE-2025-498139Наблюдать
Path Traversal Leading to RCE by Any Authenticated Mattermost User
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %mattermost · mattermost server20 июн. 2025 г.
- CVE-2026-6509339Наблюдать
NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape.
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %nvidia · openshell25 авг. 2026 г.
- CVE-2023-4111739Наблюдать
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x be
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %enterprisedb · postgres advanced server12 дек. 2023 г.
- CVE-2026-1686039Наблюдать
IBM i is Affected By Remote Code Execution Vulnerability []
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %ibm · i12 авг. 2026 г.
- CVE-2023-4179039Наблюдать
Traversal Path on PHP file
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %artica · pandora fms23 нояб. 2023 г.
- CVE-2025-6574139Наблюдать
Sublime Text 3 Build 3208 or prior for MacOS is vulnerable to Dylib Injection.
КритическаяCVSS 9,8Proof of conceptEPSS 1 %sublimetext · sublime text 39 дек. 2025 г.
- CVE-2019-2078039Наблюдать
An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %google · android17 апр. 2020 г.