Vulnerabilities > Unquoted Search Path or Element

DATE CVE VULNERABILITY TITLE RISK
2024-09-25 CVE-2024-8975 Unquoted Search Path or Element vulnerability in Grafana Alloy 1.4.0
Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Alloy: before 1.3.3, from 1.4.0-rc.0 through 1.4.0-rc.1.
local
low complexity
grafana CWE-428
7.8
2024-09-25 CVE-2024-8996 Unquoted Search Path or Element vulnerability in Grafana Agent
Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Agent Flow: before 0.43.2
local
low complexity
grafana CWE-428
7.8
2024-09-06 CVE-2022-27592 Unquoted Search Path or Element vulnerability in Qnap QVR Smart Client 2.4.0
An unquoted search path or element vulnerability has been reported to affect QVR Smart Client.
local
low complexity
qnap CWE-428
6.7
2024-07-31 CVE-2024-31201 Unquoted Search Path or Element vulnerability in Proges Thermoscan IP 20211103
A “CWE-428: Unquoted Search Path or Element” affects the ThermoscanIP_Scrutation service.
local
low complexity
proges CWE-428
6.7
2024-07-15 CVE-2024-5402 Unquoted Search Path or Element vulnerability in ABB Mint Workbench 5866/5868
Unquoted Search Path or Element vulnerability in ABB Mint Workbench. A local attacker who successfully exploited this vulnerability could gain elevated privileges by inserting an executable file in the path of the affected service. This issue affects Mint Workbench I versions: from 5866 before 5868.
local
low complexity
abb CWE-428
7.8
2024-06-12 CVE-2024-2747 Unquoted Search Path or Element vulnerability in Schneider-Electric Easergy Studio
CWE-428: Unquoted search path or element vulnerability exists in Easergy Studio, which could cause privilege escalation when a valid user replaces a trusted file name on the system and reboots the machine.
local
low complexity
schneider-electric CWE-428
7.8
2024-02-14 CVE-2023-24542 Unquoted Search Path or Element vulnerability in Intel Thunderbolt DCH Driver 1.41.1054.0/72
Unquoted search path or element in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
high complexity
intel CWE-428
6.7
2024-02-02 CVE-2024-1201 Unquoted Search Path or Element vulnerability in Panterasoft HDD Health 4.2.0.112
Search path or unquoted item vulnerability in HDD Health affecting versions 4.2.0.112 and earlier.
local
low complexity
panterasoft CWE-428
7.8
2024-02-02 CVE-2020-24682 Unquoted Search Path or Element vulnerability in Br-Automation Automation Studio
Unquoted Search Path or Element vulnerability in B&R Industrial Automation Automation Studio, B&R Industrial Automation NET/PVI allows Target Programs with Elevated Privileges.This issue affects Automation Studio: from 4.0 through 4.6, from 4.7.0 before 4.7.7 SP, from 4.8.0 before 4.8.6 SP, from 4.9.0 before 4.9.4 SP; NET/PVI: from 4.0 through 4.6, from 4.7.0 before 4.7.7, from 4.8.0 before 4.8.6, from 4.9.0 before 4.9.4.
local
low complexity
br-automation CWE-428
7.8
2024-01-31 CVE-2023-7043 Unquoted Search Path or Element vulnerability in Eset products
Unquoted service path in ESET products allows to drop a prepared program to a specific location and run on boot with the NT AUTHORITY\NetworkService permissions.
local
low complexity
eset CWE-428
5.5