ShareMouse 5.0.43 contains an unquoted service path vulnerability that allows local users to potentially execute arbitra
Nord VPN 6.31.13.0 contains an unquoted service path vulnerability in its nordvpn-service that allows local attackers to
BarcodeOCR 19.3.6 contains an unquoted service path vulnerability that allows local attackers to execute code with eleva
CodeMeter 6.60 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary
SonarQube 8.3.1 contains an unquoted service path vulnerability that allows local attackers to gain SYSTEM privileges by
10-Strike Bandwidth Monitor 3.9 contains an unquoted service path vulnerability in multiple services that allows local a
Outline Service 1.3.3 contains an unquoted service path vulnerability that allows local users to potentially execute arb
Andrea ST Filters Service 1.0.64.7 contains an unquoted service path vulnerability in its Windows service configuration.
Popcorn Time 6.2.1.14 contains an unquoted service path vulnerability that allows local non-privileged users to potentia
Atomic Alarm Clock 6.3 contains a local privilege escalation vulnerability in its service configuration that allows atta
Avast SecureLine 5.5.522.0 contains an unquoted service path vulnerability that allows local users to potentially execut
Veritas NetBackup 7.0 contains an unquoted service path vulnerability in the NetBackup INET Daemon service that allows l
Deep Instinct Windows Agent 1.2.29.0 contains an unquoted service path vulnerability in the DeepMgmtService that allows
Iskysoft Application Framework Service 2.4.3.241 contains an unquoted service path vulnerability that allows local users
SpyHunter 4 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary cod
BOOTP Turbo 2.0.1214 contains an unquoted service path vulnerability that allows local attackers to potentially execute
DHCP Turbo 4.61298 contains an unquoted service path vulnerability that allows local attackers to potentially execute ar
TFTP Turbo 4.6.1273 contains an unquoted service path vulnerability that allows local attackers to potentially execute a
EPSON EasyMP Network Projection 2.81 contains an unquoted service path vulnerability in the EMP_NSWLSV service that allo
AnyDesk 5.4.0 contains an unquoted service path vulnerability in its Windows service configuration that allows local att
Disk Sorter Enterprise 12.4.16 contains an unquoted service path vulnerability that allows local attackers to execute ar
Disk Savvy Enterprise 12.3.18 contains an unquoted service path vulnerability in its service configuration that allows l
Sync Breeze Enterprise 12.4.18 contains an unquoted service path vulnerability that allows local attackers to execute ar
VPN Unlimited 6.1 contains an unquoted service path vulnerability that allows local attackers to inject malicious execut
Adaware Web Companion 4.9.2159 contains an unquoted service path vulnerability in the WCAssistantService that allows loc
Wing FTP Server 6.0.7 contains an unquoted service path vulnerability that allows local attackers to potentially execute
Amiti Antivirus 25.0.640 contains an unquoted service path vulnerability in its Windows service configurations. Attacker
NETGATE Data Backup 3.0.620 contains an unquoted service path vulnerability in its NGDatBckpSrv Windows service configur
TexasSoft CyberPlanet 6.4.131 contains an unquoted service path vulnerability in the CCSrvProxy service that allows loca
Easy-Hide-IP 5.0.0.3 contains an unquoted service path vulnerability in the EasyRedirect service that allows local attac
ProShow Producer 9.0.3797 contains an unquoted service path vulnerability in the ScsiAccess service that allows local at
BartVPN 1.2.2 contains an unquoted service path vulnerability in the BartVPNService that allows local attackers to poten
Studio 5000 Logix Designer 30.01.00 contains an unquoted service path vulnerability in the FactoryTalk Activation Servic
NCP Secure Entry Client 9.2 contains an unquoted service path vulnerability in multiple Windows services that allows loc
Shrew Soft VPN Client 2.2.2 contains an unquoted service path vulnerability that allows local users to execute arbitrary
Alps Pointing-device Controller 8.1202.1711.04 contains an unquoted service path vulnerability in the ApHidMonitorServic
GCafé 3.0 contains an unquoted service path vulnerability in the gbClientService that allows local attackers to potentia
Adaware Web Companion version 4.8.2078.3950 contains an unquoted service path vulnerability in the WCAssistantService th
Wacom WTabletService 6.6.7-3 contains an unquoted service path vulnerability that allows local attackers to execute mali
Wondershare Application Framework Service 2.4.3.231 contains an unquoted service path vulnerability that allows local at
Alps HID Monitor Service 8.1.0.10 contains an unquoted service path vulnerability that allows local attackers to potenti
BlueStacks App Player 2.4.44.62.57 contains an unquoted service path vulnerability in the BstHdLogRotatorSvc service tha
Acer Launch Manager 6.1.7600.16385 contains an unquoted service path vulnerability in the DsiWMIService that allows loca
SecurOS Enterprise 10.2 contains an unquoted service path vulnerability in the SecurosCtrlService that allows local user
JumpStart 0.6.0.0 contains an unquoted service path vulnerability in the jswpbapi service running with LocalSystem privi
BlackMoon FTP Server 3.1.2.1731 contains an unquoted service path vulnerability that allows local users to potentially e
WorkgroupMail 7.5.1 contains an unquoted service path vulnerability in its Windows service configuration that allows loc
Mikogo 5.2.2.150317 contains an unquoted service path vulnerability in the Mikogo-Service Windows service configuration.
Zilab Remote Console Server 3.2.9 contains an unquoted service path vulnerability that allows local attackers to potenti
ActiveFax Server 6.92 Build 0316 contains an unquoted service path vulnerability in the ActiveFaxServiceNT service that
Frequently Asked Questions
What is CWE-428?
CWE-428 (CWE-428) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-428?
There are 510 CVE records associated with CWE-428 in our database. Of these, 7 are critical severity, 337 are high severity, and 89 are medium severity.
How can I protect against CWE-428 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-428 using AI-powered security agents.
Detect CWE-428 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-428 vulnerabilities across your infrastructure.
Get Started