Vulnerabilities > Unquoted Search Path or Element

DATE CVE VULNERABILITY TITLE RISK
2024-09-25 CVE-2024-8975 Unquoted Search Path or Element vulnerability in Grafana Alloy 1.4.0
Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Alloy: before 1.3.3, from 1.4.0-rc.0 through 1.4.0-rc.1.
local
low complexity
grafana CWE-428
7.8
2024-09-25 CVE-2024-8996 Unquoted Search Path or Element vulnerability in Grafana Agent
Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Agent Flow: before 0.43.2
local
low complexity
grafana CWE-428
7.8
2024-09-06 CVE-2022-27592 Unquoted Search Path or Element vulnerability in Qnap QVR Smart Client 2.4.0
An unquoted search path or element vulnerability has been reported to affect QVR Smart Client.
local
low complexity
qnap CWE-428
6.7
2024-07-31 CVE-2024-31201 Unquoted Search Path or Element vulnerability in Proges Thermoscan IP 20211103
A “CWE-428: Unquoted Search Path or Element” affects the ThermoscanIP_Scrutation service.
local
low complexity
proges CWE-428
6.7
2024-02-14 CVE-2023-24542 Unquoted Search Path or Element vulnerability in Intel Thunderbolt DCH Driver 1.41.1054.0/72
Unquoted search path or element in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
high complexity
intel CWE-428
6.7
2024-01-31 CVE-2023-7043 Unquoted Search Path or Element vulnerability in Eset products
Unquoted service path in ESET products allows to drop a prepared program to a specific location and run on boot with the NT AUTHORITY\NetworkService permissions.
local
low complexity
eset CWE-428
5.5
2024-01-08 CVE-2023-6631 Unquoted Search Path or Element vulnerability in Subnet Powersystem Center 2020
PowerSYSTEM Center versions 2020 Update 16 and prior contain a vulnerability that may allow an authorized local user to insert arbitrary code into the unquoted service path and escalate privileges.
local
low complexity
subnet CWE-428
7.8
2023-11-14 CVE-2023-25075 Unquoted Search Path or Element vulnerability in Intel Server Configuration Utility 16.0.7/16.0.8
Unquoted search path in the installer for some Intel Server Configuration Utility software before version 16.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-428
7.8
2023-11-14 CVE-2023-29165 Unquoted Search Path or Element vulnerability in Intel ARC a Graphics and Iris XE Graphics
Unquoted search path or element in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-428
7.3
2023-11-14 CVE-2023-32658 Unquoted Search Path or Element vulnerability in Intel Hdmi Firmware
Unquoted search path in some Intel(R) NUC Kits NUC7i3DN, NUC7i5DN, NUC7i7DN HDMI firmware update tool software before version 1.79.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-428
7.3