It has been identified that a vulnerability (CWE-427) exists in the UPS (Uninterruptible Power Supply) management applic
Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to a
The installers of LiveOn Meet Client for Windows (Downloader5Installer.exe and Downloader5InstallerForAdmin.exe) and the
NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as
AVACAST developed by eMPIA Technology, has a DLL Hijacking vulnerability, allowing authenticated local attackers to plac
Uncontrolled Search Path Element vulnerability in WatchGuard Agent on Windows allows Using Malicious Files.
OpenClaw before 2026.4.23 contains an arbitrary code execution vulnerability in the bundled plugin setup resolver that l
Bytello Share (Windows Edition) installer executable provided by Bytello insecurely loads Dynamic Link Libraries. If the
Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk <2.4.0p29, <2.3.0p47, and 2.2.0 (EOL) allows a l
A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potenti
Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attac
A local user with low privileges may be able to influence the behavior of a privileged system service by manipulating co
Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13
A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escalate privileges and e
A potential uncontrolled search path vulnerability was reported in the LanSchool Classic client application that could a
A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated lo
OpenClaw before 2026.4.25 contains a path traversal vulnerability in memory-core artifact loading where workspace state
Multiple printer drivers provided by Ricoh Company, Ltd. and KONICA MINOLTA JAPAN, INC. contain a privilege escalation v
electron-updater allows for automatic updates for Electron apps. Prior to 26.15.0, AppImage targets built by app-builder
Notepad3 through 6.25.822.1 contains a DLL search-order hijacking vulnerability in the About-dialog code path in src/Not
Uncontrolled search path element issue exists in Pupsman versions prior to 3.9.0. If a crafted DLL file is placed in the
Creative Cloud Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary c
The installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory wh
An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated a
An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated ac
An issue in CGM Germany - CompuGroup Medical CGM ISIS MED 2510.1.0.20 allows a remote attacker to execute arbtirary code
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Uncontrolled Search Path Element vulne
IBM Trusteer Rapport installer 3.5.2309.290 IBM Trusteer Rapport could allow a local attacker to execute arbitrary code
NVIDIA Nsight Visual Studio for Windows contains a vulnerability in Nsight Monitor where an attacker can execute arbitra
D-Link D-View 8 versions 2.0.1.107 and below contain an uncontrolled search path vulnerability in the installer. When ex
Discord Client Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows loca
beat-access for Windows version 3.0.3 and prior contains an issue with the DLL search path, which may lead to insecurely
A DLL hijacking vulnerability in Vivado could allow a local attacker to achieve privilege escalation, potentially result
A DLL hijacking vulnerability in Doc Nav could allow a local attacker to achieve privilege escalation, potentially resul
PDF-XChange Editor TrackerUpdate Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnera
Dell Repository Manager (DRM), versions prior to 3.4.8, contains an Uncontrolled Search Path Element vulnerability. A lo
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec
KeePassXC OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerab
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during ins
IP Setting Software contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Librar
Mullvad VPN is a VPN client app for desktop and mobile. When using macOS with versions 2026.1 and below, Mullvad VPN may
Local privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock D
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock D
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock D
A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads on
Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desk
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerability. A low privile
OpenClaw versions 2026.1.5 prior to 2026.2.14 contain a vulnerability in the Gateway in which it does not sufficiently c
Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, whe
Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locall
Frequently Asked Questions
What is CWE-427?
CWE-427 (CWE-427) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-427?
There are 1,525 CVE records associated with CWE-427 in our database. Of these, 26 are critical severity, 791 are high severity, and 347 are medium severity.
How can I protect against CWE-427 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-427 using AI-powered security agents.
Detect CWE-427 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-427 vulnerabilities across your infrastructure.
Get Started