The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.
Volume of CVEs assigned to CWE-428 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
451 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-38408CRITICAL The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-con | Jul 20, 2023 | 9.8 | 77 | NO | NO |
CVE-2020-15261MEDIUM On Windows the Veyon Service before version 4.4.2 contains an unquoted service path vulnerability, allowing locally authenticated users with administrative privileges to run malici | Oct 19, 2020 | 6.7 | 38 | NO | YES |
CVE-2025-14018HIGH Unquoted Search Path or Element vulnerability in NetBT Consulting Services Inc. E-Fatura allows Leveraging/Manipulating Configuration File Search Paths, Redirect Access to Librarie | Dec 22, 2025 | 7.3 | 37 | NO | YES |
CVE-2022-23909HIGH There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might allow a local user to escalate privileges by creating a "C: | Apr 5, 2022 | 7.8 | 37 | NO | YES |
CVE-2023-31747HIGH Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the component NativePushService. This vulnerability allows attackers | May 23, 2023 | 7.8 | 36 | NO | YES |
CVE-2022-37197HIGH IOBit IOTransfer V4 is vulnerable to Unquoted Service Path. | Nov 18, 2022 | 7.8 | 36 | NO | YES |
CVE-2022-35899HIGH There is an unquoted service path in ASUSTeK Aura Ready Game SDK service (GameSDK.exe) 1.0.0.4. This might allow a local user to escalate privileges by creating a %PROGRAMFILES(X86 | Jul 21, 2022 | 7.8 | 36 | NO | YES |
CVE-2017-3141HIGH The BIND installer on Windows uses an unquoted service path which can enable a local user to achieve privilege escalation if the host file system permissions allow this. Affects BI | Jan 16, 2019 | 7.8 | 36 | NO | YES |
CVE-2019-18915HIGH A potential security vulnerability has been identified with certain versions of HP System Event Utility prior to version 1.4.33. This vulnerability may allow a local attacker to ex | Feb 13, 2020 | 7.8 | 35 | NO | YES |
CVE-2017-7180HIGH Net Monitor for Employees Pro through 5.3.4 has an unquoted service path, which allows a Security Feature Bypass of its documented "Block applications" design goal. The local attac | Jun 8, 2017 | 7.3 | 34 | NO | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.