Vulnerabilities > Uncontrolled Search Path Element

DATE CVE VULNERABILITY TITLE RISK
2023-11-30 CVE-2023-47454 Uncontrolled Search Path Element vulnerability in Netease Cloudmusic 2.10.4
An Untrusted search path vulnerability in NetEase CloudMusic 2.10.4 for Windows allows local users to gain escalated privileges through the urlmon.dll file in the current working directory.
local
low complexity
netease CWE-427
7.8
2023-11-30 CVE-2023-6401 Uncontrolled Search Path Element vulnerability in Notepad-Plus-Plus Notepad++
A vulnerability classified as problematic was found in NotePad++ up to 8.1.
local
low complexity
notepad-plus-plus CWE-427
7.8
2023-11-30 CVE-2023-4770 Uncontrolled Search Path Element vulnerability in 4D and Server
An uncontrolled search path element vulnerability has been found on 4D and 4D server Windows executables applications, affecting version 19 R8 100218.
local
low complexity
4d CWE-427
7.8
2023-11-27 CVE-2023-4931 Uncontrolled Search Path Element vulnerability in Plesk 3.27.0.0
Uncontrolled search path element vulnerability in Plesk Installer affects version 3.27.0.0.
local
low complexity
plesk CWE-427
7.8
2023-11-23 CVE-2023-41787 Uncontrolled Search Path Element vulnerability in Artica Pandora FMS
Uncontrolled Search Path Element vulnerability in Pandora FMS on all allows Leveraging/Manipulating Configuration File Search Paths.
network
low complexity
artica CWE-427
7.5
2023-11-23 CVE-2023-41790 Uncontrolled Search Path Element vulnerability in Artica Pandora FMS
Uncontrolled Search Path Element vulnerability in Pandora FMS on all allows Leveraging/Manipulating Configuration File Search Paths.
network
low complexity
artica CWE-427
critical
9.8
2023-11-22 CVE-2023-29069 Uncontrolled Search Path Element vulnerability in Autodesk Desktop Connector
A maliciously crafted DLL file can be forced to install onto a non-default location, and attacker can overwrite parts of the product with malicious DLLs.
local
low complexity
autodesk CWE-427
7.8
2023-11-22 CVE-2023-46814 Uncontrolled Search Path Element vulnerability in Videolan VLC Media Player
A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows.
local
low complexity
videolan CWE-427
7.8
2023-11-21 CVE-2023-6235 Uncontrolled Search Path Element vulnerability in Duetdisplay Duet Display 2.5.9.1
An uncontrolled search path element vulnerability has been found in the Duet Display product, affecting version 2.5.9.1.
local
low complexity
duetdisplay CWE-427
7.8
2023-11-15 CVE-2023-22818 Uncontrolled Search Path Element vulnerability in Westerndigital Sandisk Security Installer
Multiple DLL Search Order Hijack vulnerabilities were addressed in the SanDisk Security Installer for Windows that could allow attackers with local access to execute arbitrary code by executing the installer in the same folder as the malicious DLL. This can lead to the execution of arbitrary code with the privileges of the vulnerable application or obtain a certain level of persistence on the compromised host. 
local
low complexity
westerndigital CWE-427
7.8