Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-427

MITRE ↗

CWE-427

26
CRITICAL
791
HIGH
347
MEDIUM
5
LOW
1,213 CVEs · Page 10/25
7.8
CVE-2024-9852

Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi E

7.8
CVE-2022-27595

An insecure library loading vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerabilit

7.7
CVE-2024-33672

An issue was discovered in Veritas NetBackup before 10.4. The Multi-Threaded Agent used in NetBackup can be leveraged to

7.5
CVE-2024-10389

There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS).

7.4
CVE-2024-22450

Dell Alienware Command Center, versions prior to 6.2.7.0, contain an uncontrolled search path element vulnerability. A l

7.3
CVE-2023-6132

The vulnerability, if exploited, could allow a malicious entity with access to the file system to achieve arbitrary cod

7.3
CVE-2024-20338

A vulnerability in the ISE Posture (System Scan) module of Cisco Secure Client for Linux could allow an authenticated, l

7.3
CVE-2024-27303

electron-builder is a solution to package and build a ready for distribution Electron, Proton Native app for macOS, Wind

7.3
CVE-2024-37130

Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains a Local Privilege Escalation vulnerability v

7.3
CVE-2024-32857

Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacke

7.3
CVE-2024-37142

Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker

7.3
CVE-2023-31348

A DLL hijacking vulnerability in AMD μProf could allow an attacker to achieve privilege escalation, potentially resultin

7.3
CVE-2024-34017

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy

7.3
CVE-2024-34019

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy

7.3
CVE-2024-20430

A vulnerability in Cisco Meraki Systems Manager (SM) Agent for Windows could allow an authenticated, local attacker to e

7.3
CVE-2024-45246

Diebold Nixdorf – CWE-427: Uncontrolled Search Path Element

7.3
CVE-2024-49390

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files

7.3
CVE-2024-49391

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files

7.3
CVE-2024-47942

A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 9). The affected applications suf

7.3
CVE-2024-30376

Famatech Advanced IP Scanner Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerabili

7.2
CVE-2024-2637

An Uncontrolled Search Path Element vulnerability in B&R Industrial Automation Scene Viewer, B&R Industrial Automation A

7.2
CVE-2021-22280

Improper DLL loading algorithms in B&R Automation Studio versions >=4.0 and <4.12 may allow an authenticated local attac

7.1
CVE-2024-0980

The Auto-update service for Okta Verify for Windows is vulnerable to two flaws which in combination could be used to exe

7.1
CVE-2024-34116

Creative Cloud Desktop versions 6.1.0.587 and earlier are affected by an Uncontrolled Search Path Element vulnerability

7.0
CVE-2024-39708

An issue was discovered in the Agent in Delinea Privilege Manager (formerly Thycotic Privilege Manager) before 12.0.1096

7.0
CVE-2024-1182

Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi E

7.0
CVE-2024-38330

IBM System Management for i 7.2, 7.3, and 7.4 could allow a local user to gain elevated privileges due to an unqualified

7.0
CVE-2024-41817

ImageMagick is a free and open-source software suite, used for editing and manipulating digital images. The `AppImage` v

6.7
CVE-2023-24591

Uncontrolled search path in some Intel(R) Binary Configuration Tool software before version 3.4.4 may allow an authentic

6.7
CVE-2023-25779

Uncontrolled search path element in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an

6.7
CVE-2023-28407

Uncontrolled search path in some Intel(R) XTU software before version 7.12.0.29 may allow an authenticated user to poten

6.7
CVE-2023-28745

Uncontrolled search path in Intel(R) QSFP+ Configuration Utility software, all versions, may allow an authenticated user

6.7
CVE-2023-32618

Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.2 may allo

6.7
CVE-2023-32646

Uncontrolled search path element in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated use

6.7
CVE-2023-35060

Uncontrolled search path in some Intel(R) Battery Life Diagnostic Tool software before version 2.3.1 may allow an authen

6.7
CVE-2023-35769

Uncontrolled search path in some Intel(R) CIP software before version 2.4.10577 may allow an authenticated user to poten

6.7
CVE-2023-36493

Uncontrolled search path in some Intel(R) SDK for OpenCL(TM) Applications software may allow an authenticated user to po

6.7
CVE-2023-38566

Uncontrolled search path in some Intel(R) ISPC software before version 1.21.0 may allow an authenticated user to potenti

6.7
CVE-2023-39932

Uncontrolled search path in the Intel(R) SUR for Gameplay Software before version 2.0.1901 may allow a privillaged user

6.7
CVE-2023-40156

Uncontrolled search path element in some Intel(R) SSU software before version 3.0.0.2 may allow an authenticated user to

6.7
CVE-2023-41091

Uncontrolled search path for some Intel(R) MPI Library Software before version 2021.11 may allow an authenticated user t

6.7
CVE-2023-49114

A DLL hijacking vulnerability was identified in the Qognify VMS Client Viewer version 7.1 or higher, which allows local

6.7
CVE-2023-39254

Dell Update Package (DUP), Versions prior to 4.9.10 contain an Uncontrolled Search Path vulnerability. A malicious user

6.7
CVE-2023-35192

Uncontrolled search path in some Intel(R) GPA Framework software before version 2023.3 may allow an authenticated user t

6.7
CVE-2023-39929

Uncontrolled search path in some Libva software maintained by Intel(R) before version 2.20.0 may allow an authenticated

6.7
CVE-2023-40155

Uncontrolled search path for some Intel(R) CST software before version 2.1.10300 may allow an authenticated user to pote

6.7
CVE-2023-41961

Uncontrolled search path in some Intel(R) GPA software before version 2023.3 may allow an authenticated user to potentia

6.7
CVE-2023-43751

Uncontrolled search path in Intel(R) Graphics Command Center Service bundled in some Intel(R) Graphics Windows DCH drive

6.7
CVE-2023-45320

Uncontrolled search path element in some Intel(R) VTune(TM) Profiler software before version 2024.0 may allow an authent

6.7
CVE-2023-45743

Uncontrolled search path in some Intel(R) DSA software uninstallers before version 23.4.39.10 may allow an authenticated

Frequently Asked Questions

What is CWE-427?

CWE-427 (CWE-427) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-427?

There are 1,525 CVE records associated with CWE-427 in our database. Of these, 26 are critical severity, 791 are high severity, and 347 are medium severity.

How can I protect against CWE-427 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-427 using AI-powered security agents.

Detect CWE-427 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-427 vulnerabilities across your infrastructure.

Get Started