Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-427

MITRE ↗

CWE-427

26
CRITICAL
791
HIGH
347
MEDIUM
5
LOW
1,213 CVEs · Page 7/25
7.0
CVE-2025-9000

A vulnerability was found in Mechrevo Control Center GX V2 5.56.51.48. Affected by this vulnerability is an unknown func

7.0
CVE-2025-9016

A vulnerability was identified in Mechrevo Control Center GX V2 5.56.51.48. This affects an unknown part of the file C:\

7.0
CVE-2025-11940

A security vulnerability has been detected in LibreWolf up to 143.0.4-1 on Windows. This affects an unknown function of

6.8
CVE-2024-13946

DLL's are not digitally signed when loaded in ASPECT's configuration toolset exposing the application to binary planting

6.8
CVE-2025-49487

An uncontrolled search path vulnerability in the Trend Micro Worry-Free Business Security Services (WFBSS) agent could h

6.8
CVE-2025-14405

PDFsam Enhanced Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows phy

6.7
CVE-2024-53977

A vulnerability has been identified in ModelSim (All versions < V2025.1), Questa (All versions < V2025.1). An example se

6.7
CVE-2024-21830

Uncontrolled search path in some Intel(R) VPL software before version 2023.4.0 may allow an authenticated user to potent

6.7
CVE-2024-24852

Uncontrolled search path in some Intel(R) Ethernet Adapter Complete Driver Pack install before versions 29.1 may allow a

6.7
CVE-2024-29223

Uncontrolled search path for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticat

6.7
CVE-2024-32938

Uncontrolled search path for some Intel(R) MPI Library for Windows software before version 2021.13 may allow an authenti

6.7
CVE-2024-36280

Uncontrolled search path for some Intel(R) High Level Synthesis Compiler software before version 24.2 may allow an authe

6.7
CVE-2024-36283

Uncontrolled search path for the Intel(R) Thread Director Visualizer software before version 1.0.1 may allow an authenti

6.7
CVE-2024-36291

Uncontrolled search path for some Intel(R) Chipset Software Installation Utility before version 10.1.19867.8574 may allo

6.7
CVE-2024-39284

Uncontrolled search path for some Intel(R) Advisor software before version 2024.2 may allow an authenticated user to pot

6.7
CVE-2024-39365

Uncontrolled search path for the FPGA Support Package for the Intel(R) oneAPI DPC++/C++ Compiler software for Windows be

6.7
CVE-2024-39372

Uncontrolled search path for the Intel(R) XTU software for Windows before version 7.14.2.14 may allow an authenticated u

6.7
CVE-2024-39813

Uncontrolled search path for some EPCT software before version 1.42.8.0 may allow an authenticated user to potentially e

6.7
CVE-2024-42405

Uncontrolled search path for some Intel(R) Quartus(R) Prime Software before version 23.1.1 Patch 1.01std may allow an au

6.7
CVE-2024-42492

Uncontrolled search path element in some BIOS and System Firmware Update Package for Intel(R) Server M50FCP family befor

6.7
CVE-2024-47006

Uncontrolled search path for the Intel(R) RealSense D400 Series Universal Windows Platform (UWP) Driver for Windows(R) 1

6.7
CVE-2024-31073

Uncontrolled search path for some Intel(R) oneAPI Level Zero software may allow an authenticated user to potentially ena

6.7
CVE-2024-39833

Uncontrolled search path for some Intel(R) QAT software before version 2.3.0 may allow an authenticated user to potentia

6.7
CVE-2024-46895

Uncontrolled search path for some Intel(R) Arc™ &amp; Iris(R) Xe graphics software before version 32.0.101.6083/32.0.101

6.7
CVE-2024-47795

Uncontrolled search path for some Intel(R) oneAPI DPC++/C++ Compiler software before version 2025.0.0 may allow an authe

6.7
CVE-2024-47800

Uncontrolled search path for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enabl

6.7
CVE-2025-20015

Uncontrolled search path element for some Intel(R) Ethernet Connection software before version 29.4 may allow an authent

6.7
CVE-2025-20041

Uncontrolled search path for some Intel(R) Graphics software for Intel(R) Arc™ graphics and Intel(R) Iris(R) Xe graphics

6.7
CVE-2025-20043

Uncontrolled search path for some Intel(R) RealSense™ SDK software before version 2.56.2 may allow an authenticated user

6.7
CVE-2025-20079

Uncontrolled search path for some Intel(R) Advisor software may allow an authenticated user to potentially enable escala

6.7
CVE-2025-20108

Uncontrolled search path element for some Intel(R) Network Adapter Driver installers for Windows 11 before version 29.4

6.7
CVE-2025-21099

Uncontrolled search path for some Intel(R) Graphics software may allow an authenticated user to potentially enable escal

6.7
CVE-2025-49158

An uncontrolled search path vulnerability in the Trend Micro Apex One security agent could allow a local attacker to esc

6.7
CVE-2025-1729

A DLL hijacking vulnerability was reported in TrackPoint Quick Menu software that, under certain conditions, could allow

6.7
CVE-2025-20017

Uncontrolled search path for some Intel(R) oneAPI Toolkit and component software installers may allow an authenticated u

6.7
CVE-2025-20048

Uncontrolled search path for the Intel(R) Trace Analyzer and Collector software all verions may allow an authenticated u

6.7
CVE-2025-20092

Uncontrolled search path for some Clock Jitter Tool software before version 6.0.1 may allow an authenticated user to pot

6.7
CVE-2025-20627

Uncontrolled search path for some Intel(R) oneAPI DPC++/C++ Compiler software before version 2025.0.1 may allow an authe

6.7
CVE-2025-21093

Uncontrolled search path element for some Intel(R) Driver &amp; Support Assistant Tool software before version 24.6.49.8

6.7
CVE-2025-22838

Uncontrolled search path for some Intel(R) RealSense(TM) Dynamic Calibrator software before version 2.14.2.0 may allow a

6.7
CVE-2025-24923

Uncontrolled search path in some Intel(R) AI for Enterprise Retrieval-augmented Generation software may allow an authent

6.7
CVE-2025-26404

Uncontrolled search path for some Intel(R) DSA software before version 25.2.15.9 may allow an authenticated user to pote

6.7
CVE-2025-27717

Uncontrolled search path for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enabl

6.7
CVE-2025-23355

NVIDIA Nsight Graphics for Windows contains a vulnerability in an ngfx component, where an attacker could cause a DLL hi

6.7
CVE-2025-62185

In Ankitects Anki before 25.02.5, a crafted shared deck can place a YouTube downloader executable in the media folder, a

6.7
CVE-2025-57716

An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.

6.7
CVE-2025-20050

Uncontrolled search path for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applicati

6.7
CVE-2025-20065

Uncontrolled search path for some Display Virtualization for Windows OS software before version 1797 within Ring 2: Devi

6.7
CVE-2025-24491

Uncontrolled search path for some Intel(R) Killer(TM) Performance Suite software before version killer 4.0 40.25.509.146

6.7
CVE-2025-24842

Uncontrolled search path for the Intel(R) System Support Utility before version 4.1.0 within Ring 3: User Applications m

Frequently Asked Questions

What is CWE-427?

CWE-427 (CWE-427) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-427?

There are 1,525 CVE records associated with CWE-427 in our database. Of these, 26 are critical severity, 791 are high severity, and 347 are medium severity.

How can I protect against CWE-427 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-427 using AI-powered security agents.

Detect CWE-427 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-427 vulnerabilities across your infrastructure.

Get Started