Flame II HSPA USB Modem contains an unquoted service path vulnerability in its Windows service configuration. Attackers
devolo dLAN Cockpit 4.3.1 contains an unquoted service path vulnerability in the 'DevoloNetworkService' that allows loca
Splashtop 8.71.12001.0 contains an unquoted service path vulnerability in the Splashtop Software Updater Service that al
Wondershare Dr.Fone 12.0.18 contains an unquoted service path vulnerability that allows local users to execute arbitrary
Wondershare Dr.Fone 11.4.9 contains an unquoted service path vulnerability in the DFWSIDService that allows local users
Wondershare MobileTrans 3.5.9 contains an unquoted service path vulnerability in the ElevationService that allows local
Wondershare UBackit 2.0.5 contains an unquoted service path vulnerability that allows local users to potentially execute
ITeC ITeCProteccioAppServer contains an unquoted service path vulnerability that allows local attackers to execute code
EaseUS Data Recovery 15.1.0.0 contains an unquoted service path vulnerability in the EaseUS UPDATE SERVICE executable. A
VIVE Runtime Service 1.0.0.4 contains an unquoted service path vulnerability that allows local users to execute arbitrar
Sandboxie-Plus 5.50.2 contains an unquoted service path vulnerability in the SbieSvc Windows service that allows local a
Private Internet Access 3.3 contains an unquoted service path vulnerability that allows local users to potentially execu
Connectify Hotspot 2018 contains an unquoted service path vulnerability in its ConnectifyService executable that allows
Emerson PAC Machine Edition 9.80 contains an unquoted service path vulnerability in the TrapiServer service that allows
CONTPAQi AdminPAQ 14.0.0 contains an unquoted service path vulnerability in the AppKeyLicenseServer service running with
Clevo HotKey Clipboard 2.1.0.6 contains an unquoted service path vulnerability in the HKClipSvc service that allows loca
Mediconta 3.7.27 contains an unquoted service path vulnerability in the servermedicontservice that allows local users to
Tftpd32 SE 4.60 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbit
IBM Db2 for Windows 12.1.0 - 12.1.3 could allow a local user with filesystem access to escalate their privileges due to
PTPublisher 2.3.4 contains an unquoted service path vulnerability in the PTProtect service that allows local attackers t
ProtonVPN 1.26.0 contains an unquoted service path vulnerability in its WireGuard service configuration that allows loca
WOW21 5.0.1.9 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitra
Cobian Backup 0.9 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with
BlueSoleilCS 5.4.277 contains an unquoted service path vulnerability in its Windows service configuration that allows lo
Cain & Abel 4.9.56 contains an unquoted service path vulnerability that allows local attackers to potentially execute ar
Outline 1.6.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitra
HTTPDebuggerPro 9.11 contains an unquoted service path vulnerability that allows local attackers to potentially execute
10-Strike Network Inventory Explorer Pro 9.31 contains an unquoted service path vulnerability in the srvInventoryWebServ
Dynojet Power Core 2.3.0 contains an unquoted service path vulnerability in the DJ.UpdateService that allows local authe
DiskPulse Enterprise 13.6.14 contains an unquoted service path vulnerability in its Windows service configuration that a
Brother BRAgent 1.38 contains an unquoted service path vulnerability in the WBA_Agent_Client service running with LocalS
Brother BRPrint Auditor 3.0.7 contains an unquoted service path vulnerability in its Windows service configurations that
SysGauge Server 7.9.18 contains an unquoted service path vulnerability in its binary path configuration that allows loca
Macro Expert 4.7 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrar
TotalAV 5.15.69 contains an unquoted service path vulnerability in multiple system services running with LocalSystem pri
Active WebCam 11.5 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code
Remote Mouse 4.002 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code
iFunbox 4.2 contains an unquoted service path vulnerability in the Apple Mobile Device Service that allows local attacke
Wise Care 365 5.6.7.568 contains an unquoted service path vulnerability in the WiseBootAssistant service running with Lo
Disk Savvy 13.6.14 contains an unquoted service path vulnerability in its Windows service configuration that allows loca
Dup Scout 13.5.28 contains an unquoted service path vulnerability in its Windows service configuration that allows local
Sync Breeze 13.6.18 contains an unquoted service path vulnerability in its Windows service configuration that allows loc
Disk Sorter Enterprise 13.6.12 contains an unquoted service path vulnerability in its Windows service configuration that
WibuKey Runtime 6.51 contains an unquoted service path vulnerability in the WkSvW32.exe service that allows local attack
DiskBoss Service 12.2.18 contains an unquoted service path vulnerability in its binary path configuration that allows lo
Acer ePowerSvc 6.0.3008.0 contains an unquoted service path vulnerability that allows local users to potentially execute
Acer Updater Service 1.2.3500.0 contains an unquoted service path vulnerability that allows local users to execute code
Acer Backup Manager 3.0.0.99 contains an unquoted service path vulnerability in the NTI IScheduleSvc service that allows
BOOTP Turbo 2.0.0.1253 contains an unquoted service path vulnerability in its Windows service configuration. Attackers c
DHCP Broadband 4.1.0.1503 contains an unquoted service path vulnerability in its service configuration that allows local
Frequently Asked Questions
What is CWE-428?
CWE-428 (CWE-428) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-428?
There are 204 CVE records associated with CWE-428 in our database. Of these, 1 are critical severity, 195 are high severity, and 6 are medium severity.
How can I protect against CWE-428 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-428 using AI-powered security agents.
Detect CWE-428 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-428 vulnerabilities across your infrastructure.
Get Started