Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-427

MITRE ↗

CWE-427

26
CRITICAL
791
HIGH
347
MEDIUM
5
LOW
1,213 CVEs · Page 9/25
8.8
CVE-2023-44439

Ashlar-Vellum Xenon Uncontrolled Search Path Element Remote Code Execution Vulnerability. This vulnerability allows remo

8.8
CVE-2023-44440

Ashlar-Vellum Lithium Uncontrolled Search Path Element Remote Code Execution Vulnerability. This vulnerability allows re

8.8
CVE-2024-5290

An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a lo

8.8
CVE-2024-44107

DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local aut

8.8
CVE-2024-2208

Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research

8.4
CVE-2024-22346

Db2 for IBM i 7.2, 7.3, 7.4, and 7.5 infrastructure could allow a local user to gain elevated privileges due to an unqua

8.4
CVE-2024-25050

IBM i 7.2, 7.3, 7.4, 7.5 and IBM Rational Development Studio for i 7.2, 7.3, 7.4, 7.5 networking and compiler infrastruc

7.9
CVE-2023-32272

Uncontrolled search path in some Intel NUC Pro Software Suite Configuration Tool software installers before version 3.0.

7.9
CVE-2024-22167

A potential DLL hijacking vulnerability in the SanDisk PrivateAccess application for Windows that could lead to arbitrar

7.8
CVE-2023-6338

Uncontrolled search path vulnerabilities were reported in the Lenovo Universal Device Client (UDC) that could allow an a

7.8
CVE-2023-29445

An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authent

7.8
CVE-2023-51711

An issue was discovered in Regify Regipay Client for Windows version 4.5.1.0 allows DLL hijacking: a user can trigger th

7.8
CVE-2024-23940

Trend Micro uiAirSupport, included in the Trend Micro Security 2023 family of consumer products, version 6.0.2092 and be

7.8
CVE-2024-1595

Delta Electronics CNCSoft-B DOPSoft prior to v4.0.0.82 insecurely loads libraries, which may allow an attacker to use

7.8
CVE-2023-42920

Claris International has fixed a dylib hijacking vulnerability in the FileMaker Pro.app and Claris Pro.app versions on m

7.8
CVE-2024-28131

EasyRange Ver 1.41 contains an issue with the executable file search path when displaying an extracted file on Explorer,

7.8
CVE-2024-29734

Uncontrolled search path element issue exists in SonicDICOM Media Viewer 2.3.2 and earlier, which may lead to insecurely

7.8
CVE-2024-28099

VT STUDIO Ver.8.32 and earlier contains an issue with the DLL search path, which may lead to insecurely loading Dynamic

7.8
CVE-2023-27362

3CX Uncontrolled Search Path Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to esca

7.8
CVE-2023-44437

Ashlar-Vellum Cobalt Uncontrolled Search Path Element Remote Code Execution Vulnerability. This vulnerability allows rem

7.8
CVE-2024-20366

A vulnerability in the Tail-f High Availability Cluster Communications (HCC) function pack of Cisco Crosswork Network Se

7.8
CVE-2024-5292

D-Link Network Assistant Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability a

7.8
CVE-2024-5509

Luxion KeyShot BIP File Parsing Uncontrolled Search Path Element Remote Code Execution Vulnerability. This vulnerability

7.8
CVE-2024-37127

Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker

7.8
CVE-2024-7324

A vulnerability was found in IObit iTop Data Recovery Pro 4.4.0.687. It has been declared as critical. Affected by this

7.8
CVE-2024-7325

A vulnerability was found in IObit Driver Booster 11.0.0.0. It has been rated as critical. Affected by this issue is som

7.8
CVE-2024-7326

A vulnerability classified as critical has been found in IObit DualSafe Password Manager 1.4.0.3. This affects an unknow

7.8
CVE-2024-7886

A vulnerability has been found in Scooter Software Beyond Compare up to 3.3.5.15075 and classified as critical. Affected

7.8
CVE-2024-5929

VIPRE Advanced Security PMAgent Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerab

7.8
CVE-2024-7834

A local privilege escalation is caused by Overwolf loading and executing certain dynamic link library files from a user-

7.8
CVE-2024-6510

Local Privilege Escalation in AVG Internet Security v24 on Windows allows a local unprivileged user to escalate privileg

7.8
CVE-2024-33578

A DLL hijack vulnerability was reported in Lenovo Leyun that could allow a local attacker to execute code with elevated

7.8
CVE-2024-33579

A DLL hijack vulnerability was reported in Lenovo Baiying that could allow a local attacker to execute code with elevate

7.8
CVE-2024-33580

A DLL hijack vulnerability was reported in Lenovo Personal Cloud that could allow a local attacker to execute code with

7.8
CVE-2024-33581

A DLL hijack vulnerability was reported in Lenovo PC Manager AI intelligent scenario that could allow a local attacker t

7.8
CVE-2024-33582

A DLL hijack vulnerability was reported in Lenovo Service Framework that could allow a local attacker to execute code wi

7.8
CVE-2024-4089

A DLL hijack vulnerability was reported in Lenovo Super File that could allow a local attacker to execute code with elev

7.8
CVE-2024-4130

A DLL hijack vulnerability was reported in Lenovo App Store that could allow a local attacker to execute code with eleva

7.8
CVE-2024-4131

A DLL hijack vulnerability was reported in Lenovo Emulator that could allow a local attacker to execute code with elevat

7.8
CVE-2024-4132

A DLL hijack vulnerability was reported in Lenovo Lock Screen that could allow a local attacker to execute code with ele

7.8
CVE-2024-9046

A DLL hijack vulnerability was reported in Lenovo stARstudio that could allow a local attacker to execute code with elev

7.8
CVE-2024-45710

SolarWinds Platform is susceptible to an Uncontrolled Search Path Element Local Privilege Escalation vulnerability. This

7.8
CVE-2024-10068

A vulnerability was found in OpenSight Software FlashFXP 5.4.0.3970. It has been classified as critical. Affected is an

7.8
CVE-2024-10093

A vulnerability, which was classified as critical, was found in VSO ConvertXtoDvd 7.0.0.83. Affected is an unknown funct

7.8
CVE-2024-48605

An issue in Helakuru Desktop Application v1.1 allows a local attacker to execute arbitrary code via the lack of proper v

7.8
CVE-2024-48990

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tric

7.8
CVE-2024-48992

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tric

7.8
CVE-2024-7244

Panda Security Dome VPN DLL Hijacking Local Privilege Escalation Vulnerability. This vulnerability allows local attacker

7.8
CVE-2024-7253

NoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local att

7.8
CVE-2024-8299

Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi E

Frequently Asked Questions

What is CWE-427?

CWE-427 (CWE-427) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-427?

There are 1,525 CVE records associated with CWE-427 in our database. Of these, 26 are critical severity, 791 are high severity, and 347 are medium severity.

How can I protect against CWE-427 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-427 using AI-powered security agents.

Detect CWE-427 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-427 vulnerabilities across your infrastructure.

Get Started