Vulnerabilities > Unquoted Search Path or Element

DATE CVE VULNERABILITY TITLE RISK
2023-11-08 CVE-2023-0392 Unquoted Search Path or Element vulnerability in Okta Ldap Agent
The LDAP Agent Update service with versions prior to 5.18 used an unquoted path, which could allow arbitrary code execution.
local
low complexity
okta CWE-428
6.7
2023-10-23 CVE-2021-26735 Unquoted Search Path or Element vulnerability in Zscaler Client Connector
The Zscaler Client Connector Installer and Unsintallers for Windows prior to 3.6 had an unquoted search path vulnerability.
local
low complexity
zscaler CWE-428
7.8
2023-10-17 CVE-2023-37537 Unquoted Search Path or Element vulnerability in Hcltech Appscan Presence 2.1.37
An unquoted service path vulnerability in HCL AppScan Presence, deployed as a Windows service in HCL AppScan on Cloud (ASoC), may allow a local attacker to gain elevated privileges.
local
low complexity
hcltech CWE-428
7.8
2023-09-15 CVE-2023-36658 Unquoted Search Path or Element vulnerability in Opswat Media Validation Agent and Metadefender Kiosk
An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996.
local
low complexity
opswat CWE-428
7.8
2023-07-26 CVE-2023-26911 Unquoted Search Path or Element vulnerability in Asus Armoury Crate and Setupasusservices
ASUS SetupAsusServices v1.0.5.1 in Asus Armoury Crate v5.3.4.0 contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.
local
low complexity
asus CWE-428
7.8
2023-07-20 CVE-2023-38408 Unquoted Search Path or Element vulnerability in multiple products
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system.
network
low complexity
openbsd fedoraproject CWE-428
critical
9.8
2023-07-03 CVE-2023-3438 Unquoted Search Path or Element vulnerability in Trellix Move
An unquoted Windows search path vulnerability existed in the install the MOVE 4.10.x and earlier Windows install service (mvagtsce.exe).
local
low complexity
trellix CWE-428
7.8
2023-05-23 CVE-2023-31747 Unquoted Search Path or Element vulnerability in Wondershare Filmora 12
Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the component NativePushService.
local
low complexity
wondershare CWE-428
7.8
2023-05-11 CVE-2023-2644 Unquoted Search Path or Element vulnerability in Digitalpersona Fpsensor Project Digitalpersona Fpsensor 1.0.0.1
A vulnerability, which was classified as problematic, has been found in DigitalPersona FPSensor 1.0.0.1.
7.8
2023-05-10 CVE-2022-34848 Unquoted Search Path or Element vulnerability in Intel NUC PRO Software Suite
Uncontrolled search path for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-428
7.8