Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-427

Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

1,188
Assigned CVEs
45th
Commonality Rank
7.5
Avg CVSS
0.2%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-427 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2005
21 years ago
Most Recent CVE
Jul 17, 2026
7 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

1,188 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-27955CRITICAL
Git LFS 2.12.0 allows Remote Code Execution.
Nov 5, 20209.883NOYES
CVE-2020-3153MEDIUM
A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system
Feb 19, 20206.580YESYES
CVE-2020-3433HIGH
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL
Aug 17, 20207.875YESYES
CVE-2017-6517CRITICAL
Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists
Mar 23, 20179.855NONO
CVE-2024-48990HIGH
Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an
Nov 19, 20247.848NOYES
CVE-2019-9491HIGH
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially le
Oct 21, 20197.844NOYES
CVE-2022-2334HIGH
The application searches for a library dll that is not found. If an attacker can place a dll with this name, then the attacker can leverage it to execute arbitrary code on the targ
Aug 17, 20227.239NOYES
CVE-2026-5674HIGH
A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio comp
Jul 16, 20268.838NONO
CVE-2026-48363HIGH
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of th
Jul 13, 20268.237NONO
CVE-2026-48364HIGH
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of th
Jul 13, 20268.237NONO
View all 1,188 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
19%
5.0-5.9
14%
16%
6.0-6.9
73%
26%
7.0-7.9
11%
8.0-8.9
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
2 CVEs
0.2% of CVEs· 81st percentile
Metasploit
6 CVEs
0.5% of CVEs· 83rd percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
8 CVEs
0.7% of CVEs· 78th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products