The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Volume of CVEs assigned to CWE-427 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
1,188 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-27955CRITICAL Git LFS 2.12.0 allows Remote Code Execution. | Nov 5, 2020 | 9.8 | 83 | NO | YES |
CVE-2020-3153MEDIUM A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system | Feb 19, 2020 | 6.5 | 80 | YES | YES |
CVE-2020-3433HIGH A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL | Aug 17, 2020 | 7.8 | 75 | YES | YES |
CVE-2017-6517CRITICAL Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists | Mar 23, 2017 | 9.8 | 55 | NO | NO |
CVE-2024-48990HIGH Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an | Nov 19, 2024 | 7.8 | 48 | NO | YES |
CVE-2019-9491HIGH Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially le | Oct 21, 2019 | 7.8 | 44 | NO | YES |
CVE-2022-2334HIGH The application searches for a library dll that is not found. If an attacker can place a dll with this name, then the attacker can leverage it to execute arbitrary code on the targ | Aug 17, 2022 | 7.2 | 39 | NO | YES |
CVE-2026-5674HIGH A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio comp | Jul 16, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-48363HIGH ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of th | Jul 13, 2026 | 8.2 | 37 | NO | NO |
CVE-2026-48364HIGH ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of th | Jul 13, 2026 | 8.2 | 37 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.