Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-428

MITRE ↗

CWE-428

7
CRITICAL
337
HIGH
89
MEDIUM
3
LOW
447 CVEs · Page 5/9
6.7
CVE-2026-7280

AVACAST developed by eMPIA Technology has a Unquoted Service Path vulnerability, allowing privileged local attackers to

6.7
CVE-2026-66839

NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerabil

3.9
CVE-2026-34768

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version

CVE-2026-8864

The HP Fan Control App might allow local escalation of privileges. An updated version of HP Fan Control App has been rel

8.8
CVE-2025-12507

The service Bizerba Communication Server (BCS) has an unquoted service path. Due to the way Windows searches the executa

8.4
CVE-2025-10714

AXIS Optimizer was vulnerable to an unquoted search path vulnerability, which could potentially lead to privilege escala

8.4
CVE-2023-53946

Arcsoft PhotoStudio 6.0.0.172 contains an unquoted service path vulnerability in the ArcSoft Exchange Service that allow

8.4
CVE-2023-53947

OCS Inventory NG 2.3.0.0 contains an unquoted service path vulnerability that allows local attackers to escalate privile

8.4
CVE-2022-50688

Cobian Backup Gravity 11.2.0.582 contains an unquoted service path vulnerability that allows local users to potentially

8.4
CVE-2023-53965

SOUND4 Server Service 4.1.102 contains an unquoted service path vulnerability that allows local non-privileged users to

8.4
CVE-2021-47739

Epic Games Easy Anti-Cheat 4.0 contains an unquoted service path vulnerability that allows local non-privileged users to

8.4
CVE-2020-36903

Selea CarPlateServer 4.0.1.6 contains an unquoted service path vulnerability in the Windows service configuration that a

7.8
CVE-2025-21107

Dell NetWorker, version(s) prior to 19.11.0.3, all versions of 19.10 & prior versions contain(s) an Unquoted Search Path

7.8
CVE-2025-10199

A local privilege escalation vulnerability exists in Sunshine for Windows (version v2025.122.141614 and likely prior ver

7.8
CVE-2025-43993

Dell Wireless 5932e and Qualcomm Snapdragon X62 Firmware and GNSS/GPS Driver, versions prior to 3.2.0.22 contain an Unqu

7.8
CVE-2025-57714

An unquoted search path or element vulnerability has been reported to affect NetBak Replicator. If a local attacker gain

7.8
CVE-2025-57227

An unquoted service path in Kingosoft Technology Ltd Kingo ROOT v1.5.8.3353 allows attackers to escalate privileges via

7.8
CVE-2025-66575

VeeVPN 1.6.1 contains an unquoted service path vulnerability in the VeePNService that allows remote attackers to execute

7.8
CVE-2024-58315

Tosibox Key Service 3.3.0 contains an unquoted service path vulnerability that allows local non-privileged users to pote

7.3
CVE-2024-57276

In Electronic Arts Dragon Age Origins 1.05, the DAUpdaterSVC service contains an unquoted service path vulnerability. Th

7.3
CVE-2024-36321

Unquoted search path within AIM-T Manageability Service can allow a local attacker to escalate privileges, potentially r

7.3
CVE-2025-0035

Unquoted search path within AMD Cloud Manageability Service can allow a local attacker to escalate privileges, potential

7.3
CVE-2025-14018

Unquoted Search Path or Element vulnerability in NetBT Consulting Services Inc. E-Fatura allows Leveraging/Manipulating

7.0
CVE-2025-4540

A vulnerability was found in MTSoftware C-Lodop 6.6.1.1 on Windows. It has been rated as critical. This issue affects so

7.0
CVE-2025-12247

A weakness has been identified in Hasleo Backup Suite up to 5.2. Impacted is an unknown function of the component Hasleo

7.0
CVE-2025-12286

A weakness has been identified in VeePN up to 1.6.2. This affects an unknown function of the file C:\Program Files (x86)

7.0
CVE-2025-13433

A security flaw has been discovered in Muse Group MuseHub 2.1.0.1567. The affected element is an unknown function of the

6.7
CVE-2025-57699

Western Digital Kitfox for Windows provided by Western Digital Corporation registers a Windows service with an unquoted

6.7
CVE-2025-58400

RATOC RAID Monitoring Manager for Windows provided by RATOC Systems, Inc. registers a Windows service with an unquoted f

6.7
CVE-2025-59307

RAID Manager provided by Century Corporation registers a Windows service with an unquoted file path. A user with the wri

6.7
CVE-2025-9818

A vulnerability (CWE-428) has been identified in the Uninterruptible Power Supply (UPS) management application provided

6.7
CVE-2025-54081

Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineS

6.7
CVE-2025-61871

NAS Navigator2 Windows version by BUFFALO INC. registers a Windows service with an unquoted file path. A user with the w

6.7
CVE-2025-61865

Multiple NAS management applications provided by I-O DATA DEVICE, INC. register Windows services with unquoted file path

6.7
CVE-2025-60320

memoQ 10.1.13.ef1b2b52aae and earlier contains an unquoted service path vulnerability in the memoQ Auto Update Service (

6.7
CVE-2025-62225

Optical Disc Archive Software provided by Sony Corporation registers a Windows service with an unquoted file path. A use

6.7
CVE-2025-64151

Multiple Roboticsware products provided by Roboticsware PTE. LTD. register Windows services with unquoted file paths. A

6.7
CVE-2025-32449

Unquoted search path for some PRI Driver software before version 03.03.1002 within Ring 3: User Applications may allow a

6.7
CVE-2025-66461

FULLBACK Manager Pro provided by GS Yuasa International Ltd. registers two Windows services with unquoted file paths. A

6.7
CVE-2025-66271

Clone for Windows provided by ELECOM CO.,LTD. registers a Windows service with an unquoted file path. A user with the wr

6.7
CVE-2025-59888

Improper quotation in search paths in the Eaton UPS Companion software installer could lead to arbitrary code execution

6.6
CVE-2025-24831

Local privilege escalation due to unquoted search path vulnerability. The following products are affected: Acronis Cyber

6.2
CVE-2023-53912

USB Flash Drives Control 4.1.0.0 contains an unquoted service path vulnerability in its service configuration that allow

6.2
CVE-2023-53954

ActFax 10.10 contains an unquoted service path vulnerability that allows local attackers to potentially escalate privile

5.3
CVE-2025-39246

There is an Unquoted Service Path Vulnerability in some HikCentral FocSign versions. This could allow an authenticated u

5.2
CVE-2025-1984

Xerox Desktop Print Experience application contains a Local Privilege Escalation (LPE) vulnerability, which allows a low

CVE-2025-0884

Unquoted Search Path or Element vulnerability in OpenText™ Service Manager.  The vulnerability could allow a user to ga

CVE-2025-8070

The Windows service configuration of ABP and AES contains an unquoted ImagePath registry value vulnerability. This allow

CVE-2025-9043

The service executable path in Seagate Toolkit on Versions prior to 2.34.0.33 on Windows allows an attacker with Admin p

CVE-2025-5191

An Unquoted Search Path vulnerability has been identified in the utility for Moxa’s industrial computers (Windows). Due

Frequently Asked Questions

What is CWE-428?

CWE-428 (CWE-428) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-428?

There are 510 CVE records associated with CWE-428 in our database. Of these, 7 are critical severity, 337 are high severity, and 89 are medium severity.

How can I protect against CWE-428 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-428 using AI-powered security agents.

Detect CWE-428 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-428 vulnerabilities across your infrastructure.

Get Started