CWE-428 · 440 записей
Unquoted Search Path or Element
CVE этого класса
440 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
63На этой неделе | CVE-2023-38408Proof of concept | The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if openbsd · openssh · CWE-428 | Критическая9,8 | — | 79,7 % | 19 июл. 2023 г. |
40В плане | CVE-2019-17658Proof of concept | An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an attacker to gafortinet · forticlient · CWE-428 | Критическая9,8 | — | 2,2 % | 12 мар. 2020 г. |
39Наблюдать | CVE-2020-9292Эксплойта нет | An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated privileges via the Aofortinet · fortisiem windows agent · CWE-428 | Критическая9,8 | — | 1,5 % | 4 июн. 2020 г. |
39Наблюдать | CVE-2020-14521Эксплойта нет | Mitsubishi Electric Factory Automation Engineering Products Unquoted Search Path or Elementmitsubishielectric · c controller interface module utility · CWE-428 | Критическая9,8 | — | 1,3 % | 11 февр. 2022 г. |
39Наблюдать | CVE-2019-8459Эксплойта нет | Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the pacheckpoint · jumbo hotfix for endpoint security server · CWE-428 | Критическая9,8 | — | 1,2 % | 20 июн. 2019 г. |
39Наблюдать | CVE-2022-36344Эксплойта нет | An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate justsystems · atok medical 2 · CWE-428 | Критическая9,8 | — | 0,9 % | 16 авг. 2022 г. |
36Наблюдать | CVE-2024-24722Эксплойта нет | An unquoted service path vulnerability in the 12d Synergy Server and File Replication Server components may allow an attacker to gain elevat12dsynergy · 12dsynergy · CWE-428 | Критическая9,1 | — | 0,6 % | 19 февр. 2024 г. |
36Наблюдать | CVE-2025-8070Эксплойта нет | Windows service registered with an unquoted ImagePath vulnerability in the system registryasustor · abp and aes · CWE-428 | Критическая9,2 | — | 0,2 % | 23 июл. 2025 г. |
35Наблюдать | CVE-2020-27645Эксплойта нет | The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.1e · client · CWE-428 | Высокая8,8 | — | 1,2 % | 29 дек. 2020 г. |
35Наблюдать | CVE-2020-27644Эксплойта нет | The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.1e · client · CWE-428 | Высокая8,8 | — | 1,2 % | 29 дек. 2020 г. |
35Наблюдать | CVE-2016-5793Эксплойта нет | Unquoted Windows search path vulnerability in Moxa Active OPC Server before 2.4.19 allows local users to gain privileges via a Trojan horse moxa · active opc server · CWE-428 | Высокая8,8 | — | 0,4 % | 24 сент. 2016 г. |
35Наблюдать | CVE-2025-12507Эксплойта нет | Insecure service configuration – unquoted pathbizerba · _connect.brain · CWE-428 | Высокая8,8 | — | 0,1 % | 31 окт. 2025 г. |
34Наблюдать | CVE-2016-20058Эксплойта нет | Netgate AMITI Antivirus build 23.0.305 Unquoted Service Path Privilege Escalationnetgate · amiti antivirus · CWE-428 | Высокая8,5 | — | 0,7 % | 4 апр. 2026 г. |
34Наблюдать | CVE-2016-20057Эксплойта нет | NETGATE Registry Cleaner build 16.0.205 Unquoted Service Path Privilege Escalationnetgate · registry cleaner · CWE-428 | Высокая8,5 | — | 0,6 % | 4 апр. 2026 г. |
34Наблюдать | CVE-2025-66575Эксплойта нет | VeeVPN 1.6.1 - Unquoted Service Path Remote Code Executionveepn · veepn · CWE-428 | Высокая8,5 | — | 0,5 % | 4 дек. 2025 г. |
34Наблюдать | CVE-2022-50935Эксплойта нет | FLAME II MODEM USB - Unquoted Service Pathtelcel · flame ii modem usb · CWE-428 | Высокая8,5 | — | 0,4 % | 13 янв. 2026 г. |
34Наблюдать | CVE-2024-58288Эксплойта нет | Genexus Protection Server 9.7.2.10 Unquoted Service Path Privilege Escalationgenexus · genexus protection server · CWE-428 | Высокая8,7 | — | 0,4 % | 11 дек. 2025 г. |
34Наблюдать | CVE-2019-25269Эксплойта нет | Amiti Antivirus 25.0.640 - Unquoted Service Path Vulnerabilitynetgate · amiti antivirus · CWE-428 | Высокая8,5 | — | 0,3 % | 4 февр. 2026 г. |
34Наблюдать | CVE-2019-25271Эксплойта нет | NETGATE Data Backup 3.0.620 - 'NGDatBckpSrv' Unquoted Service Pathnetgate · data backup · CWE-428 | Высокая8,5 | — | 0,3 % | 4 февр. 2026 г. |
34Наблюдать | CVE-2021-47773Эксплойта нет | Dynojet Power Core 2.3.0 - Unquoted Service Pathdynojet · power core · CWE-428 | Высокая8,5 | — | 0,3 % | 15 янв. 2026 г. |
34Наблюдать | CVE-2020-36879Эксплойта нет | Flexsense DiskBoss Service Unquoted Service Path Vulnerabilityflexsense · diskboss · CWE-428 | Высокая8,5 | — | 0,3 % | 5 дек. 2025 г. |
34Наблюдать | CVE-2022-50901Эксплойта нет | Wondershare Dr.Fone 11.4.9 - 'DFWSIDService' Unquoted Service Pathwondershare · dr.fone · CWE-428 | Высокая8,5 | — | 0,3 % | 13 янв. 2026 г. |
34Наблюдать | CVE-2022-50903Эксплойта нет | Wondershare MobileTrans 3.5.9 - 'ElevationService' Unquoted Service Pathwondershare · mobiletrans · CWE-428 | Высокая8,5 | — | 0,3 % | 13 янв. 2026 г. |
34Наблюдать | CVE-2020-36928Эксплойта нет | Brother BRAgent 1.38 - 'WBA_Agent_Client' Unquoted Service Pathbrother · bragent · CWE-428 | Высокая8,5 | — | 0,3 % | 15 янв. 2026 г. |
34Наблюдать | CVE-2021-47787Эксплойта нет | TotalAV 5.15.69 - Unquoted Service Pathtotalav · totalav · CWE-428 | Высокая8,5 | — | 0,3 % | 15 янв. 2026 г. |
- CVE-2023-3840863На этой неделе
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if
КритическаяCVSS 9,8Proof of conceptEPSS 80 %openbsd · openssh19 июл. 2023 г.
- CVE-2019-1765840В плане
An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an attacker to ga
КритическаяCVSS 9,8Proof of conceptEPSS 2 %fortinet · forticlient12 мар. 2020 г.
- CVE-2020-929239Наблюдать
An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated privileges via the Ao
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %fortinet · fortisiem windows agent4 июн. 2020 г.
- CVE-2020-1452139Наблюдать
Mitsubishi Electric Factory Automation Engineering Products Unquoted Search Path or Element
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mitsubishielectric · c controller interface module utility11 февр. 2022 г.
- CVE-2019-845939Наблюдать
Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the pa
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %checkpoint · jumbo hotfix for endpoint security server20 июн. 2019 г.
- CVE-2022-3634439Наблюдать
An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %justsystems · atok medical 216 авг. 2022 г.
- CVE-2024-2472236Наблюдать
An unquoted service path vulnerability in the 12d Synergy Server and File Replication Server components may allow an attacker to gain elevat
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %12dsynergy · 12dsynergy19 февр. 2024 г.
- CVE-2025-807036Наблюдать
Windows service registered with an unquoted ImagePath vulnerability in the system registry
КритическаяCVSS 9,2Эксплойта нетEPSS 0 %asustor · abp and aes23 июл. 2025 г.
- CVE-2020-2764535Наблюдать
The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %1e · client29 дек. 2020 г.
- CVE-2020-2764435Наблюдать
The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %1e · client29 дек. 2020 г.
- CVE-2016-579335Наблюдать
Unquoted Windows search path vulnerability in Moxa Active OPC Server before 2.4.19 allows local users to gain privileges via a Trojan horse
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %moxa · active opc server24 сент. 2016 г.
- CVE-2025-1250735Наблюдать
Insecure service configuration – unquoted path
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %bizerba · _connect.brain31 окт. 2025 г.
- CVE-2016-2005834Наблюдать
Netgate AMITI Antivirus build 23.0.305 Unquoted Service Path Privilege Escalation
ВысокаяCVSS 8,5Эксплойта нетEPSS 1 %netgate · amiti antivirus4 апр. 2026 г.
- CVE-2016-2005734Наблюдать
NETGATE Registry Cleaner build 16.0.205 Unquoted Service Path Privilege Escalation
ВысокаяCVSS 8,5Эксплойта нетEPSS 1 %netgate · registry cleaner4 апр. 2026 г.
- CVE-2025-6657534Наблюдать
VeeVPN 1.6.1 - Unquoted Service Path Remote Code Execution
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %veepn · veepn4 дек. 2025 г.
- CVE-2022-5093534Наблюдать
FLAME II MODEM USB - Unquoted Service Path
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %telcel · flame ii modem usb13 янв. 2026 г.
- CVE-2024-5828834Наблюдать
Genexus Protection Server 9.7.2.10 Unquoted Service Path Privilege Escalation
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %genexus · genexus protection server11 дек. 2025 г.
- CVE-2019-2526934Наблюдать
Amiti Antivirus 25.0.640 - Unquoted Service Path Vulnerability
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %netgate · amiti antivirus4 февр. 2026 г.
- CVE-2019-2527134Наблюдать
NETGATE Data Backup 3.0.620 - 'NGDatBckpSrv' Unquoted Service Path
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %netgate · data backup4 февр. 2026 г.
- CVE-2021-4777334Наблюдать
Dynojet Power Core 2.3.0 - Unquoted Service Path
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %dynojet · power core15 янв. 2026 г.
- CVE-2020-3687934Наблюдать
Flexsense DiskBoss Service Unquoted Service Path Vulnerability
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %flexsense · diskboss5 дек. 2025 г.
- CVE-2022-5090134Наблюдать
Wondershare Dr.Fone 11.4.9 - 'DFWSIDService' Unquoted Service Path
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %wondershare · dr.fone13 янв. 2026 г.
- CVE-2022-5090334Наблюдать
Wondershare MobileTrans 3.5.9 - 'ElevationService' Unquoted Service Path
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %wondershare · mobiletrans13 янв. 2026 г.
- CVE-2020-3692834Наблюдать
Brother BRAgent 1.38 - 'WBA_Agent_Client' Unquoted Service Path
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %brother · bragent15 янв. 2026 г.
- CVE-2021-4778734Наблюдать
TotalAV 5.15.69 - Unquoted Service Path
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %totalav · totalav15 янв. 2026 г.