CWE-426 · 659 kayıt
Untrusted Search Path
Bu sınıftaki CVE’ler
658 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
67Bu hafta | CVE-2012-1854Silahlaştırılmış | Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basimicrosoft · office · CWE-426 | Yüksek7,8 | KEV | %21,0 | 10 Tem 2012 |
67Bu hafta | CVE-2022-22047Silahlaştırılmış | Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-426 | Yüksek7,8 | KEV | %18,8 | 12 Tem 2022 |
58Planlayın | CVE-2015-0096Silahlaştırılmış | Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 Smicrosoft · windows 7 · CWE-426 | Kritik9,3 | — | %71,0 | 11 Mar 2015 |
41Planlayın | CVE-2023-30330Kavram kanıtı | SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42300/generic/gn_defausoftexpert · excellence suite · CWE-426 | Kritik9,8 | — | %5,9 | 11 May 2023 |
40Planlayın | CVE-2016-10009Kavram kanıtı | Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local PKCopenbsd · openssh · CWE-426 | Yüksek7,3 | — | %37,4 | 4 Oca 2017 |
40Planlayın | CVE-2016-0016Kavram kanıtı | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Winmicrosoft · windows 10 · CWE-426 | Yüksek7,8 | — | %29,7 | 13 Oca 2016 |
40Planlayın | CVE-2011-2019İstismar yok | Untrusted search path vulnerability in Microsoft Internet Explorer 9 on Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows microsoft · internet explorer · CWE-426 | Kritik9,3 | — | %11,1 | 13 Ara 2011 |
40Planlayın | CVE-2018-19486İstismar yok | Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain caslinux · linux kernel · CWE-426 | Kritik9,8 | — | %4,1 | 23 Kas 2018 |
40Planlayın | CVE-2020-15801İstismar yok | In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from arbitrary locations.python · python · CWE-426 | Kritik9,8 | — | %3,5 | 16 Tem 2020 |
40Planlayın | CVE-2011-4125İstismar yok | A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute acalibre-ebook · calibre · CWE-426 | Kritik9,8 | — | %2,3 | 26 Eki 2021 |
40Planlayın | CVE-2022-26184İstismar yok | Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when uspython-poetry · poetry · CWE-426 | Kritik9,8 | — | %1,9 | 21 Mar 2022 |
39İzleyin | CVE-2017-12414İstismar yok | Format Factory 4.1.0 has a DLL Hijacking Vulnerability because an untrusted search path is used for msimg32.dll, WindowsCodecs.dll, and dwmapcfreetime · format factory · CWE-426 | Kritik9,8 | — | %1,6 | 3 Ağu 2017 |
39İzleyin | CVE-2017-2225İstismar yok | Untrusted search path vulnerability in EbidSettingChecker.exe (version 1.0.0.0) allows an attacker to gain privileges via a Trojan horse DLLmext · ebidsettingchecker · CWE-426 | Kritik9,8 | — | %1,5 | 7 Tem 2017 |
39İzleyin | CVE-2023-26036İstismar yok | ZoneMinder contains Local File Inclusion vulnerabilityzoneminder · zoneminder · CWE-426 | Kritik9,8 | — | %0,9 | 24 Şub 2023 |
39İzleyin | CVE-2024-35260İstismar yok | Microsoft Dataverse Remote Code Execution Vulnerabilitymicrosoft · power platform · CWE-426 | Kritik9,8 | — | %0,8 | 27 Haz 2024 |
39İzleyin | CVE-2022-3734İstismar yok | Redis on Windows dbghelp.dll uncontrolled search pathredis · redis · CWE-426 | Kritik9,8 | — | %0,6 | 28 Eki 2022 |
39İzleyin | CVE-2024-38462İstismar yok | iRODS before 4.3.2 provides an msiSendMail function with a problematic dependency on the mail binary, such as in the mailMS.cpp#L94-L106 refirods · irods · CWE-426 | Kritik9,8 | — | %0,6 | 16 Haz 2024 |
39İzleyin | CVE-2025-26155İstismar yok | NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability.ncp-e · ncp secure entry client · CWE-426 | Kritik9,8 | — | %0,6 | 26 Kas 2025 |
39İzleyin | CVE-2026-78155İstismar yok | Untrusted Search Path in StackGresongres · stackgres · CWE-426 | Kritik9,9 | — | %0,5 | 23 Ağu 2026 |
38İzleyin | CVE-2012-2040İstismar yok | Untrusted search path vulnerability in the installer in Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Maadobe · flash player · CWE-426 | Kritik9,3 | — | %4,0 | 8 Haz 2012 |
38İzleyin | CVE-2010-4833İstismar yok | Untrusted search path vulnerability in modules/engines/ms-windows/xp_theme.c in GTK+ before 2.24.0 allows local users to gain privileges viagnome · gtk · CWE-426 | Kritik9,3 | — | %2,0 | 6 Eyl 2011 |
38İzleyin | CVE-2011-5158İstismar yok | Multiple untrusted search path vulnerabilities in the DMTGUI2.EXE and DvInesLogFileViewer.Exe components in DATEV Grundpaket Basis CD23.20 adatev · grundpaket basis · CWE-426 | Kritik9,3 | — | %2,0 | 7 Eyl 2012 |
37İzleyin | CVE-2018-12589Kavram kanıtı | Polaris Office 2017 8.1 allows attackers to execute arbitrary code via a Trojan horse puiframeworkproresenu.dll file in the current working polarisoffice · polaris office 2017 · CWE-426 | Yüksek7,8 | — | %20,1 | 28 Haz 2018 |
37İzleyin | CVE-2024-26198İstismar yok | Microsoft Exchange Server Remote Code Execution Vulnerabilitymicrosoft · exchange server · CWE-426 | Yüksek8,8 | — | %6,8 | 12 Mar 2024 |
37İzleyin | CVE-2025-23266Kavram kanıtı | NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could nvidia · container toolkit · CWE-426 | Kritik9,0 | — | %3,2 | 17 Tem 2025 |
- CVE-2012-185467Bu hafta
Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basi
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %21microsoft · office10 Tem 2012
- CVE-2022-2204767Bu hafta
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %19microsoft · windows 10 150712 Tem 2022
- CVE-2015-009658Planlayın
Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 S
KritikCVSS 9,3SilahlaştırılmışEPSS %71microsoft · windows 711 Mar 2015
- CVE-2023-3033041Planlayın
SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42300/generic/gn_defau
KritikCVSS 9,8Kavram kanıtıEPSS %6softexpert · excellence suite11 May 2023
- CVE-2016-1000940Planlayın
Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local PKC
YüksekCVSS 7,3Kavram kanıtıEPSS %37openbsd · openssh4 Oca 2017
- CVE-2016-001640Planlayın
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Win
YüksekCVSS 7,8Kavram kanıtıEPSS %30microsoft · windows 1013 Oca 2016
- CVE-2011-201940Planlayın
Untrusted search path vulnerability in Microsoft Internet Explorer 9 on Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows
KritikCVSS 9,3İstismar yokEPSS %11microsoft · internet explorer13 Ara 2011
- CVE-2018-1948640Planlayın
Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cas
KritikCVSS 9,8İstismar yokEPSS %4linux · linux kernel23 Kas 2018
- CVE-2020-1580140Planlayın
In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from arbitrary locations.
KritikCVSS 9,8İstismar yokEPSS %3python · python16 Tem 2020
- CVE-2011-412540Planlayın
A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute a
KritikCVSS 9,8İstismar yokEPSS %2calibre-ebook · calibre26 Eki 2021
- CVE-2022-2618440Planlayın
Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when us
KritikCVSS 9,8İstismar yokEPSS %2python-poetry · poetry21 Mar 2022
- CVE-2017-1241439İzleyin
Format Factory 4.1.0 has a DLL Hijacking Vulnerability because an untrusted search path is used for msimg32.dll, WindowsCodecs.dll, and dwma
KritikCVSS 9,8İstismar yokEPSS %2pcfreetime · format factory3 Ağu 2017
- CVE-2017-222539İzleyin
Untrusted search path vulnerability in EbidSettingChecker.exe (version 1.0.0.0) allows an attacker to gain privileges via a Trojan horse DLL
KritikCVSS 9,8İstismar yokEPSS %1mext · ebidsettingchecker7 Tem 2017
- CVE-2023-2603639İzleyin
ZoneMinder contains Local File Inclusion vulnerability
KritikCVSS 9,8İstismar yokEPSS %1zoneminder · zoneminder24 Şub 2023
- CVE-2024-3526039İzleyin
Microsoft Dataverse Remote Code Execution Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1microsoft · power platform27 Haz 2024
- CVE-2022-373439İzleyin
Redis on Windows dbghelp.dll uncontrolled search path
KritikCVSS 9,8İstismar yokEPSS %1redis · redis28 Eki 2022
- CVE-2024-3846239İzleyin
iRODS before 4.3.2 provides an msiSendMail function with a problematic dependency on the mail binary, such as in the mailMS.cpp#L94-L106 ref
KritikCVSS 9,8İstismar yokEPSS %1irods · irods16 Haz 2024
- CVE-2025-2615539İzleyin
NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability.
KritikCVSS 9,8İstismar yokEPSS %1ncp-e · ncp secure entry client26 Kas 2025
- CVE-2026-7815539İzleyin
Untrusted Search Path in StackGres
KritikCVSS 9,9İstismar yokEPSS %1ongres · stackgres23 Ağu 2026
- CVE-2012-204038İzleyin
Untrusted search path vulnerability in the installer in Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Ma
KritikCVSS 9,3İstismar yokEPSS %4adobe · flash player8 Haz 2012
- CVE-2010-483338İzleyin
Untrusted search path vulnerability in modules/engines/ms-windows/xp_theme.c in GTK+ before 2.24.0 allows local users to gain privileges via
KritikCVSS 9,3İstismar yokEPSS %2gnome · gtk6 Eyl 2011
- CVE-2011-515838İzleyin
Multiple untrusted search path vulnerabilities in the DMTGUI2.EXE and DvInesLogFileViewer.Exe components in DATEV Grundpaket Basis CD23.20 a
KritikCVSS 9,3İstismar yokEPSS %2datev · grundpaket basis7 Eyl 2012
- CVE-2018-1258937İzleyin
Polaris Office 2017 8.1 allows attackers to execute arbitrary code via a Trojan horse puiframeworkproresenu.dll file in the current working
YüksekCVSS 7,8Kavram kanıtıEPSS %20polarisoffice · polaris office 201728 Haz 2018
- CVE-2024-2619837İzleyin
Microsoft Exchange Server Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %7microsoft · exchange server12 Mar 2024
- CVE-2025-2326637İzleyin
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could
KritikCVSS 9,0Kavram kanıtıEPSS %3nvidia · container toolkit17 Tem 2025