CWE-427 · 1.149 kayıt
Uncontrolled Search Path Element
Bu sınıftaki CVE’ler
1.148 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
64Bu hafta | CVE-2020-27955Silahlaştırılmış | Git LFS 2.12.0 allows Remote Code Execution.git large file storage project · git large file storage · CWE-427 | Kritik9,8 | — | %82,3 | 5 Kas 2020 |
64Bu hafta | CVE-2020-3153Silahlaştırılmış | Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerabilitycisco · anyconnect secure mobility client · CWE-427 | Orta6,5 | KEV | %28,3 | 19 Şub 2020 |
64Bu hafta | CVE-2020-3433Silahlaştırılmış | Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerabilitycisco · anyconnect secure mobility client · CWE-427 | Yüksek7,8 | KEV | %10,0 | 17 Ağu 2020 |
53Planlayın | CVE-2017-6517İstismar yok | Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the tamicrosoft · skype · CWE-427 | Kritik9,8 | — | %46,3 | 23 Mar 2017 |
42Planlayın | CVE-2017-3090İstismar yok | Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability.adobe · digital editions · CWE-427 | Kritik9,8 | — | %8,5 | 20 Haz 2017 |
42Planlayın | CVE-2017-3092İstismar yok | Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability.adobe · digital editions · CWE-427 | Kritik9,8 | — | %8,5 | 20 Haz 2017 |
41Planlayın | CVE-2017-3097İstismar yok | Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability.adobe · digital editions · CWE-427 | Kritik9,8 | — | %7,1 | 20 Haz 2017 |
40Planlayın | CVE-2018-12805İstismar yok | Adobe Connect versions 9.7.5 and earlier have an Insecure Library Loading vulnerability.adobe · connect · CWE-427 | Kritik9,8 | — | %4,1 | 20 Tem 2018 |
40Planlayın | CVE-2020-10515İstismar yok | STARFACE UCC Client before 6.7.1.204 on WIndows allows binary planting to execute code with System rights, aka usd-2020-0006.starface · unified communication \& collaboration client · CWE-427 | Kritik9,8 | — | %2,9 | 2 Nis 2020 |
40Planlayın | CVE-2019-9546İstismar yok | SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.solarwinds · orion platform · CWE-427 | Kritik9,8 | — | %2,8 | 1 Mar 2019 |
40Planlayın | CVE-2019-7653İstismar yok | The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the current working directordebian · debian linux · CWE-427 | Kritik9,8 | — | %2,3 | 8 Şub 2019 |
40Planlayın | CVE-2023-25143İstismar yok | An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker to achieve a remote ctrendmicro · apex one · CWE-427 | Kritik9,8 | — | %1,7 | 10 Mar 2023 |
40Planlayın | CVE-2021-28955İstismar yok | git-bug before 0.7.2 has an Uncontrolled Search Path Element.git-bug project · git-bug · CWE-427 | Kritik9,8 | — | %1,7 | 22 Mar 2021 |
39İzleyin | CVE-2019-20856İstismar yok | An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS.mattermost · mattermost desktop · CWE-427 | Kritik9,8 | — | %1,4 | 19 Haz 2020 |
39İzleyin | CVE-2022-34825İstismar yok | Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0nec · expresscluster x · CWE-427 | Kritik9,8 | — | %1,3 | 8 Kas 2022 |
39İzleyin | CVE-2024-23054İstismar yok | An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listeplone · plone docker official image · CWE-427 | Kritik9,8 | — | %1,3 | 5 Şub 2024 |
39İzleyin | CVE-2023-31543İstismar yok | A dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted PyPI package to the cpipreqs project · pipreqs · CWE-427 | Kritik9,8 | — | %1,2 | 30 Haz 2023 |
39İzleyin | CVE-2022-24955İstismar yok | Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files.foxit · pdf reader · CWE-427 | Kritik9,8 | — | %1,1 | 10 Şub 2022 |
39İzleyin | CVE-2025-4981İstismar yok | Path Traversal Leading to RCE by Any Authenticated Mattermost Usermattermost · mattermost server · CWE-427 | Kritik9,9 | — | %0,8 | 20 Haz 2025 |
39İzleyin | CVE-2026-65093İstismar yok | NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape.nvidia · openshell · CWE-427 | Kritik9,9 | — | %0,8 | 25 Ağu 2026 |
39İzleyin | CVE-2023-41117İstismar yok | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x beenterprisedb · postgres advanced server · CWE-427 | Kritik9,8 | — | %0,8 | 12 Ara 2023 |
39İzleyin | CVE-2026-16860İstismar yok | IBM i is Affected By Remote Code Execution Vulnerability []ibm · i · CWE-427 | Kritik9,9 | — | %0,7 | 12 Ağu 2026 |
39İzleyin | CVE-2023-41790İstismar yok | Traversal Path on PHP fileartica · pandora fms · CWE-427 | Kritik9,8 | — | %0,6 | 23 Kas 2023 |
39İzleyin | CVE-2025-65741Kavram kanıtı | Sublime Text 3 Build 3208 or prior for MacOS is vulnerable to Dylib Injection.sublimetext · sublime text 3 · CWE-427 | Kritik9,8 | — | %0,5 | 9 Ara 2025 |
39İzleyin | CVE-2019-20780İstismar yok | An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software.google · android · CWE-427 | Kritik9,8 | — | %0,4 | 17 Nis 2020 |
- CVE-2020-2795564Bu hafta
Git LFS 2.12.0 allows Remote Code Execution.
KritikCVSS 9,8SilahlaştırılmışEPSS %82git large file storage project · git large file storage5 Kas 2020
- CVE-2020-315364Bu hafta
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %28cisco · anyconnect secure mobility client19 Şub 2020
- CVE-2020-343364Bu hafta
Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %10cisco · anyconnect secure mobility client17 Ağu 2020
- CVE-2017-651753Planlayın
Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the ta
KritikCVSS 9,8İstismar yokEPSS %46microsoft · skype23 Mar 2017
- CVE-2017-309042Planlayın
Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability.
KritikCVSS 9,8İstismar yokEPSS %8adobe · digital editions20 Haz 2017
- CVE-2017-309242Planlayın
Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability.
KritikCVSS 9,8İstismar yokEPSS %8adobe · digital editions20 Haz 2017
- CVE-2017-309741Planlayın
Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability.
KritikCVSS 9,8İstismar yokEPSS %7adobe · digital editions20 Haz 2017
- CVE-2018-1280540Planlayın
Adobe Connect versions 9.7.5 and earlier have an Insecure Library Loading vulnerability.
KritikCVSS 9,8İstismar yokEPSS %4adobe · connect20 Tem 2018
- CVE-2020-1051540Planlayın
STARFACE UCC Client before 6.7.1.204 on WIndows allows binary planting to execute code with System rights, aka usd-2020-0006.
KritikCVSS 9,8İstismar yokEPSS %3starface · unified communication \& collaboration client2 Nis 2020
- CVE-2019-954640Planlayın
SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.
KritikCVSS 9,8İstismar yokEPSS %3solarwinds · orion platform1 Mar 2019
- CVE-2019-765340Planlayın
The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the current working director
KritikCVSS 9,8İstismar yokEPSS %2debian · debian linux8 Şub 2019
- CVE-2023-2514340Planlayın
An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker to achieve a remote c
KritikCVSS 9,8İstismar yokEPSS %2trendmicro · apex one10 Mar 2023
- CVE-2021-2895540Planlayın
git-bug before 0.7.2 has an Uncontrolled Search Path Element.
KritikCVSS 9,8İstismar yokEPSS %2git-bug project · git-bug22 Mar 2021
- CVE-2019-2085639İzleyin
An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS.
KritikCVSS 9,8İstismar yokEPSS %1mattermost · mattermost desktop19 Haz 2020
- CVE-2022-3482539İzleyin
Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0
KritikCVSS 9,8İstismar yokEPSS %1nec · expresscluster x8 Kas 2022
- CVE-2024-2305439İzleyin
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package liste
KritikCVSS 9,8İstismar yokEPSS %1plone · plone docker official image5 Şub 2024
- CVE-2023-3154339İzleyin
A dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted PyPI package to the c
KritikCVSS 9,8İstismar yokEPSS %1pipreqs project · pipreqs30 Haz 2023
- CVE-2022-2495539İzleyin
Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files.
KritikCVSS 9,8İstismar yokEPSS %1foxit · pdf reader10 Şub 2022
- CVE-2025-498139İzleyin
Path Traversal Leading to RCE by Any Authenticated Mattermost User
KritikCVSS 9,9İstismar yokEPSS %1mattermost · mattermost server20 Haz 2025
- CVE-2026-6509339İzleyin
NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape.
KritikCVSS 9,9İstismar yokEPSS %1nvidia · openshell25 Ağu 2026
- CVE-2023-4111739İzleyin
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x be
KritikCVSS 9,8İstismar yokEPSS %1enterprisedb · postgres advanced server12 Ara 2023
- CVE-2026-1686039İzleyin
IBM i is Affected By Remote Code Execution Vulnerability []
KritikCVSS 9,9İstismar yokEPSS %1ibm · i12 Ağu 2026
- CVE-2023-4179039İzleyin
Traversal Path on PHP file
KritikCVSS 9,8İstismar yokEPSS %1artica · pandora fms23 Kas 2023
- CVE-2025-6574139İzleyin
Sublime Text 3 Build 3208 or prior for MacOS is vulnerable to Dylib Injection.
KritikCVSS 9,8Kavram kanıtıEPSS %1sublimetext · sublime text 39 Ara 2025
- CVE-2019-2078039İzleyin
An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software.
KritikCVSS 9,8İstismar yokEPSS %0google · android17 Nis 2020