Vulnerabilities > Untrusted Search Path

DATE CVE VULNERABILITY TITLE RISK
2024-07-31 CVE-2024-6975 Untrusted Search Path vulnerability in Catonetworks Cato Client
Cato Networks Windows SDP Client Local Privilege Escalation via openssl configuration file. This issue affects SDP Client before 5.10.34.
local
low complexity
catonetworks CWE-426
8.8
2024-07-09 CVE-2024-34123 Premiere Pro versions 23.6.5, 24.4.1 and earlier are affected by an Untrusted Search Path vulnerability that could lead to arbitrary code execution.
local
high complexity
CWE-426
7.0
2024-06-17 CVE-2024-6080 Untrusted Search Path vulnerability in Intelbras Incontrol 2.21.56
A vulnerability classified as critical was found in Intelbras InControl 2.21.56.
local
low complexity
intelbras CWE-426
7.8
2024-05-14 CVE-2024-28133 A local low privileged attacker can use an untrusted search path in a CHARX system utility to gain root privileges. 
local
low complexity
CWE-426
7.8
2024-03-18 CVE-2024-20754 Lightroom Desktop versions 7.1.2 and earlier are affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user.
local
high complexity
CWE-426
7.5
2024-02-14 CVE-2024-24697 Untrusted Search Path vulnerability in Zoom products
Untrusted search path in some Zoom 32 bit Windows clients may allow an authenticated user to conduct an escalation of privilege via local access.
local
low complexity
zoom CWE-426
7.8
2024-02-07 CVE-2024-24810 Untrusted Search Path vulnerability in Firegiant WIX Toolset
WiX toolset lets developers create installers for Windows Installer, the Windows installation engine.
local
low complexity
firegiant CWE-426
7.8
2024-02-06 CVE-2024-23304 Untrusted Search Path vulnerability in Cybozu Kunai 3.0.20/3.0.21
Cybozu KUNAI for Android 3.0.20 to 3.0.21 allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition by performing certain operations.
network
low complexity
cybozu CWE-426
7.5
2024-02-04 CVE-2021-4435 Untrusted Search Path vulnerability in Yarnpkg Yarn
An untrusted search path vulnerability was found in Yarn.
local
low complexity
yarnpkg CWE-426
7.8
2024-01-17 CVE-2024-22410 Untrusted Search Path vulnerability in Gluwa Creditcoin
Creditcoin is a network that enables cross-blockchain credit transactions.
local
low complexity
gluwa CWE-426
7.8