Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-428

MITRE ↗

CWE-428

1
CRITICAL
195
HIGH
6
MEDIUM
1
LOW
204 CVEs · Page 1/5
9.8
CVE-2022-50935

Flame II HSPA USB Modem contains an unquoted service path vulnerability in its Windows service configuration. Attackers

8.4
CVE-2019-25231

devolo dLAN Cockpit 4.3.1 contains an unquoted service path vulnerability in the 'DevoloNetworkService' that allows loca

8.4
CVE-2022-50693

Splashtop 8.71.12001.0 contains an unquoted service path vulnerability in the Splashtop Software Updater Service that al

8.4
CVE-2022-50900

Wondershare Dr.Fone 12.0.18 contains an unquoted service path vulnerability that allows local users to execute arbitrary

8.4
CVE-2022-50901

Wondershare Dr.Fone 11.4.9 contains an unquoted service path vulnerability in the DFWSIDService that allows local users

8.4
CVE-2022-50903

Wondershare MobileTrans 3.5.9 contains an unquoted service path vulnerability in the ElevationService that allows local

8.4
CVE-2022-50904

Wondershare UBackit 2.0.5 contains an unquoted service path vulnerability that allows local users to potentially execute

8.4
CVE-2022-50913

ITeC ITeCProteccioAppServer contains an unquoted service path vulnerability that allows local attackers to execute code

8.4
CVE-2022-50914

EaseUS Data Recovery 15.1.0.0 contains an unquoted service path vulnerability in the EaseUS UPDATE SERVICE executable. A

8.4
CVE-2022-50918

VIVE Runtime Service 1.0.0.4 contains an unquoted service path vulnerability that allows local users to execute arbitrar

8.4
CVE-2022-50920

Sandboxie-Plus 5.50.2 contains an unquoted service path vulnerability in the SbieSvc Windows service that allows local a

8.4
CVE-2022-50924

Private Internet Access 3.3 contains an unquoted service path vulnerability that allows local users to potentially execu

8.4
CVE-2022-50929

Connectify Hotspot 2018 contains an unquoted service path vulnerability in its ConnectifyService executable that allows

8.4
CVE-2022-50930

Emerson PAC Machine Edition 9.80 contains an unquoted service path vulnerability in the TrapiServer service that allows

8.4
CVE-2022-50938

CONTPAQi AdminPAQ 14.0.0 contains an unquoted service path vulnerability in the AppKeyLicenseServer service running with

8.4
CVE-2023-53984

Clevo HotKey Clipboard 2.1.0.6 contains an unquoted service path vulnerability in the HKClipSvc service that allows loca

8.4
CVE-2023-54336

Mediconta 3.7.27 contains an unquoted service path vulnerability in the servermedicontservice that allows local users to

8.4
CVE-2023-54338

Tftpd32 SE 4.60 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbit

8.4
CVE-2025-36384

IBM Db2 for Windows 12.1.0 - 12.1.3 could allow a local user with filesystem access to escalate their privileges due to

7.8
CVE-2022-50915

PTPublisher 2.3.4 contains an unquoted service path vulnerability in the PTProtect service that allows local attackers t

7.8
CVE-2022-50917

ProtonVPN 1.26.0 contains an unquoted service path vulnerability in its WireGuard service configuration that allows loca

7.8
CVE-2022-50921

WOW21 5.0.1.9 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitra

7.8
CVE-2022-50923

Cobian Backup 0.9 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with

7.8
CVE-2022-50928

BlueSoleilCS 5.4.277 contains an unquoted service path vulnerability in its Windows service configuration that allows lo

7.8
CVE-2022-50933

Cain & Abel 4.9.56 contains an unquoted service path vulnerability that allows local attackers to potentially execute ar

7.8
CVE-2023-54331

Outline 1.6.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitra

7.8
CVE-2021-47762

HTTPDebuggerPro 9.11 contains an unquoted service path vulnerability that allows local attackers to potentially execute

7.8
CVE-2021-47767

10-Strike Network Inventory Explorer Pro 9.31 contains an unquoted service path vulnerability in the srvInventoryWebServ

7.8
CVE-2021-47773

Dynojet Power Core 2.3.0 contains an unquoted service path vulnerability in the DJ.UpdateService that allows local authe

7.8
CVE-2020-36927

DiskPulse Enterprise 13.6.14 contains an unquoted service path vulnerability in its Windows service configuration that a

7.8
CVE-2020-36928

Brother BRAgent 1.38 contains an unquoted service path vulnerability in the WBA_Agent_Client service running with LocalS

7.8
CVE-2020-36929

Brother BRPrint Auditor 3.0.7 contains an unquoted service path vulnerability in its Windows service configurations that

7.8
CVE-2020-36930

SysGauge Server 7.9.18 contains an unquoted service path vulnerability in its binary path configuration that allows loca

7.8
CVE-2021-47780

Macro Expert 4.7 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrar

7.8
CVE-2021-47787

TotalAV 5.15.69 contains an unquoted service path vulnerability in multiple system services running with LocalSystem pri

7.8
CVE-2021-47790

Active WebCam 11.5 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code

7.8
CVE-2021-47792

Remote Mouse 4.002 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code

7.8
CVE-2021-47803

iFunbox 4.2 contains an unquoted service path vulnerability in the Apple Mobile Device Service that allows local attacke

7.8
CVE-2021-47804

Wise Care 365 5.6.7.568 contains an unquoted service path vulnerability in the WiseBootAssistant service running with Lo

7.8
CVE-2021-47805

Disk Savvy 13.6.14 contains an unquoted service path vulnerability in its Windows service configuration that allows loca

7.8
CVE-2021-47806

Dup Scout 13.5.28 contains an unquoted service path vulnerability in its Windows service configuration that allows local

7.8
CVE-2021-47807

Sync Breeze 13.6.18 contains an unquoted service path vulnerability in its Windows service configuration that allows loc

7.8
CVE-2021-47809

Disk Sorter Enterprise 13.6.12 contains an unquoted service path vulnerability in its Windows service configuration that

7.8
CVE-2021-47810

WibuKey Runtime 6.51 contains an unquoted service path vulnerability in the WkSvW32.exe service that allows local attack

7.8
CVE-2021-47822

DiskBoss Service 12.2.18 contains an unquoted service path vulnerability in its binary path configuration that allows lo

7.8
CVE-2021-47823

Acer ePowerSvc 6.0.3008.0 contains an unquoted service path vulnerability that allows local users to potentially execute

7.8
CVE-2021-47825

Acer Updater Service 1.2.3500.0 contains an unquoted service path vulnerability that allows local users to execute code

7.8
CVE-2021-47826

Acer Backup Manager 3.0.0.99 contains an unquoted service path vulnerability in the NTI IScheduleSvc service that allows

7.8
CVE-2021-47828

BOOTP Turbo 2.0.0.1253 contains an unquoted service path vulnerability in its Windows service configuration. Attackers c

7.8
CVE-2021-47829

DHCP Broadband 4.1.0.1503 contains an unquoted service path vulnerability in its service configuration that allows local

Frequently Asked Questions

What is CWE-428?

CWE-428 (CWE-428) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-428?

There are 204 CVE records associated with CWE-428 in our database. Of these, 1 are critical severity, 195 are high severity, and 6 are medium severity.

How can I protect against CWE-428 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-428 using AI-powered security agents.

Detect CWE-428 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-428 vulnerabilities across your infrastructure.

Get Started