CWE-427— Uncontrolled Search Path Element
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.— MITRE CWE catalog
1,242 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-427page 1 of 25
- CVE-2020-3433CRITICALCVSS 7.8EG 9.0⚠ KEV2020-08-17
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attac…
- CVE-2020-3153CRITICALCVSS 6.5EG 9.0⚠ KEV2020-02-19
A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnera…
- CVE-2026-65093CRITICALCVSS 9.9EG 9.92026-08-25
NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosu…
- CVE-2026-16860CRITICALCVSS 9.9EG 9.92026-08-12
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.
- CVE-2026-40342CRITICALCVSS 9.9EG 9.92026-04-17
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine name into a filesystem path without filtering path separa…
- CVE-2025-4981CRITICALCVSS 9.9EG 9.92025-06-20
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sanitize filenames in the archive extractor which allows authenticated users to write files to arbitrary locations on the…
- CVE-2025-69599CRITICALCVSS 9.8EG 9.82026-05-08
RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control the value of the PATH environment variable. NOTE: this is disputed because ability of an attacker to control the environment is a site-specifi…
- CVE-2019-25268CRITICALCVSS 9.8EG 9.82026-01-08
NREL BEopt 2.8.0.0 contains a DLL hijacking vulnerability that allows attackers to load arbitrary libraries by tricking users into opening application files from remote shares. Attackers can exploit insecure library loading of sdl2.dll and…
- CVE-2023-53959CRITICALCVSS 9.8EG 9.82025-12-19
FileZilla Client 3.63.1 contains a DLL hijacking vulnerability that allows attackers to execute malicious code by placing a crafted TextShaping.dll in the application directory. Attackers can generate a reverse shell payload using msfvenom…
- CVE-2025-65741CRITICALCVSS 9.8EG 9.82025-12-09
Sublime Text 3 Build 3208 or prior for MacOS is vulnerable to Dylib Injection. An attacker could compile a .dylib file and force the execution of this library in the context of the Sublime Text application.
- CVE-2024-23054CRITICALCVSS 9.8EG 9.82024-02-05
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components not existing in the public package index (npm).
- CVE-2023-41117CRITICALCVSS 9.8EG 9.82023-12-12
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contain packages, standalone packages, and functions that r…
- CVE-2023-41790CRITICALCVSS 9.8EG 9.82023-11-23
Uncontrolled Search Path Element vulnerability in Pandora FMS on all allows Leveraging/Manipulating Configuration File Search Paths. This vulnerability allows to access the server configuration file and to compromise the database. This iss…
- CVE-2023-31543CRITICALCVSS 9.8EG 9.82023-06-30
A dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted PyPI package to the chosen repository server.
- CVE-2023-25143CRITICALCVSS 9.8EG 9.82023-03-10
An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker to achieve a remote code execution state on affected products.
- CVE-2022-34825CRITICALCVSS 9.8EG 9.82022-11-08
Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and ea…
- CVE-2022-24955CRITICALCVSS 9.8EG 9.82022-02-11
Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files.
- CVE-2021-28955CRITICALCVSS 9.8EG 9.82021-03-22
git-bug before 0.7.2 has an Uncontrolled Search Path Element. It will execute git.bat from the current directory in certain PATH situations (most often seen on Windows).
- CVE-2020-27955CRITICALCVSS 9.8EG 9.82020-11-05
Git LFS 2.12.0 allows Remote Code Execution.
- CVE-2019-20856CRITICALCVSS 9.8EG 9.82020-06-19
An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection.
- CVE-2019-20780CRITICALCVSS 9.8EG 9.82020-04-17
An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. Certain security settings, related to whether packages are verified and accepted only from known sources, are mishandled. The LG ID is LVE-S…
- CVE-2020-10515CRITICALCVSS 9.8EG 9.82020-04-02
STARFACE UCC Client before 6.7.1.204 on WIndows allows binary planting to execute code with System rights, aka usd-2020-0006.
- CVE-2019-9546CRITICALCVSS 9.8EG 9.82019-03-01
SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.
- CVE-2019-7653CRITICALCVSS 9.8EG 9.82019-02-09
The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the current working directory, allowing code injection, because "python -m" looks in this directory, as demonstrated by rdf2dot…
- CVE-2018-12805CRITICALCVSS 9.8EG 9.82018-07-20
Adobe Connect versions 9.7.5 and earlier have an Insecure Library Loading vulnerability. Successful exploitation could lead to privilege escalation.
- CVE-2017-3097CRITICALCVSS 9.8EG 9.82017-06-20
Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability. The vulnerability is due to unsafe library loading functions in the installer plugin. A successful exploitation could lead to arbitrary co…
- CVE-2017-3092CRITICALCVSS 9.8EG 9.82017-06-20
Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability. The vulnerability is due to unsafe library loading of editor control library functions in the installer plugin. A successful exploitation …
- CVE-2017-3090CRITICALCVSS 9.8EG 9.82017-06-20
Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability. The vulnerability is due to unsafe library loading of browser related library extensions in the installer plugin. A successful exploitatio…
- CVE-2017-6517CRITICALCVSS 9.8EG 9.82017-03-23
Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded by Skype. It allows a…
- CVE-2023-26266CRITICALCVSS 7.3EG 9.82023-02-21
In AFL++ 4.05c, the CmpLog component uses the current working directory to resolve and execute unprefixed fuzzing targets, allowing code execution.
- CVE-2022-3734CRITICALCVSS 6.3EG 9.82022-10-28
A vulnerability was found in a port or fork of Redis. It has been declared as critical. This vulnerability affects unknown code in the library C:/Program Files/Redis/dbghelp.dll. The manipulation leads to uncontrolled search path. The atta…
- CVE-2025-13051CRITICALCVSS 9.3EG 9.32025-11-19
When the service of ABP and AES is installed in a directory writable by non-administrative users, an attacker can replace or plant a DLL with the same name as one loaded by the service. Upon service restart, the malicious DLL is loaded and…
- CVE-2021-38469CRITICALCVSS 9.1EG 9.12021-10-22
Many of the services used by the affected product do not specify full paths for the DLLs they are loading. An attacker can exploit the uncontrolled search path by implanting their own DLL near the affected product’s binaries, thus hijack…
- CVE-2025-30248HIGHCVSS 8.9EG 8.92026-01-26
DLL hijacking in the WD Discovery Installer in Western Digital WD Discovery 5.2.730 on Windows allows a local attacker to execute arbitrary code via placement of a crafted dll in the installer's search path.
- CVE-2022-29580HIGHCVSS 8.9EG 8.92022-12-13
There exists a path traversal vulnerability in the Android Google Search app. This is caused by the incorrect usage of uri.getLastPathSegment. A symbolic encoded string can bypass the path logic to get access to unintended directories. An …
- CVE-2026-25264HIGHCVSS 8.8EG 8.82026-09-22
Privilege escalation due to weak configuration during package extraction process.
- CVE-2026-54916HIGHCVSS 8.8EG 8.82026-09-17
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The absence of tests/init.py and the lack of --import-mode=importlib cause pytest prepend import mode to place the tests direct…
- CVE-2026-9169HIGHCVSS 8.8EG 8.82026-08-07
DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by placing a malicious DLL in a user-controlled directory listed in the…
- CVE-2026-5674HIGHCVSS 8.8EG 8.82026-07-16
A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions withi…
- CVE-2026-54232HIGHCVSS 8.8EG 8.82026-06-22
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.1, the vLLM Dockerfile is vulnerable to a dependency confusion attack through the flashinfer-jit-cache package. The package is installed from a custom …
- CVE-2026-49241HIGHCVSS 8.8EG 8.82026-06-22
The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. Prior to 21.2.4, the client-side Angular Language Service VS Code extension reads the custom TypeScript SDK paths typescript.tsdk and …
- CVE-2026-7870HIGHCVSS 8.8EG 8.82026-06-11
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege.
- CVE-2026-30478HIGHCVSS 8.8EG 8.82026-04-09
A Dynamic-link Library Injection vulnerability in GatewayGeo MapServer for Windows version 5 allows attackers to escalate privileges via a crafted executable.
- CVE-2025-69784HIGHCVSS 8.8EG 8.82026-03-16
A local, non-privileged attacker can abuse a vulnerable IOCTL interface exposed by the OpenEDR 2.5.1.0 kernel driver to modify the DLL injection path used by the product. By redirecting this path to a user-writable location, an attacker ca…
- CVE-2026-29610HIGHCVSS 8.8EG 8.82026-03-05
OpenClaw versions prior to 2026.2.14 contain a command hijacking vulnerability that allows attackers to execute unintended binaries by manipulating PATH environment variables through node-host execution or project-local bootstrapping. Atta…
- CVE-2026-23741HIGHCVSS 8.8EG 8.82026-02-06
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the asterisk/contrib/scripts/ast_coredumper runs as root, as noted by the NOTES tag on line 689 o…
- CVE-2025-65118HIGHCVSS 8.8EG 8.82026-01-16
The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to trick Process Optimization services into loading arbitrary code and escalate privileges to OS System, potentially resulting in complete compro…
- CVE-2025-33208HIGHCVSS 8.8EG 8.82025-12-03
NVIDIA TAO contains a vulnerability where an attacker may cause a resource to be loaded via an uncontrolled search path. A successful exploit of this vulnerability may lead to escalation of privileges, data tampering, denial of service, in…
- CVE-2025-9164HIGHCVSS 8.8EG 8.82025-10-27
Docker Desktop Installer.exe is vulnerable to DLL hijacking due to insecure DLL search order. The installer searches for required DLLs in the user's Downloads folder before checking system directories, allowing local privilege escalation t…
- CVE-2025-59684HIGHCVSS 8.8EG 8.82025-10-01
DigiSign DigiSigner ONE 1.0.4.60 allows DLL Hijacking.
Map vulnerabilities like CWE-427 to your infrastructure
EchelonGraph correlates every CVE — across CWE-427 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →