Weaknesses of type CWE-427

897 results

Caminho de busca ou elemento não controlado

A aplicação procura por bibliotecas, configurações ou outros recursos em diretórios sem validar adequadamente quais caminhos ela está usando, permitindo que um atacante injete uma versão maliciosa em um local que será encontrado primeiro. Isso acontece porque a ordem ou composição do caminho de busca não é explicitamente controlada.

Example

Um programa Java com classpath que inclui o diretório atual (.) antes de caminhos do sistema; um atacante coloca uma classe maliciosa no diretório de trabalho e ela é carregada em vez da legítima. Ou um script que procura por um arquivo de configuração em múltiplas pastas sem especificar o caminho absoluto, sendo enganado por um arquivo plantado em /tmp.

How to mitigate

Use caminhos absolutos explícitos em vez de relativos; remova diretórios inseguros (como o atual) do caminho de busca; valide a origem e integridade de recursos carregados (checksums, assinaturas); implemente listas de permitidos para diretórios confiáveis.

CVE-2026-30896HIGHThe installer for Qsee Client versions 1.0.1 and prior insecurely load Dynamic Link Libraries (DLLs). When a user is directed to place some EPSS 0.2%CVE-2026-25656HIGHA vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3), User Management Component (UMC) (All versions < V2.15.2.1). The EPSS 0.2%CVE-2025-33231MEDIUMNVIDIA Nsight Systems for Windows contains a vulnerability in the application’s DLL loading mechanism where an attacker could cause an unconEPSS 0.2%CVE-2026-32679HIGHThe installers of LiveOn Meet Client for Windows (Downloader5Installer.exe and Downloader5InstallerForAdmin.exe) and the installers of CanonEPSS 0.2%CVE-2025-9330HIGHFoxit PDF Reader Update Service Uncontrolled Search Path Element Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2024-33580HIGHA DLL hijack vulnerability was reported in Lenovo Personal Cloud that could allow a local attacker to execute code with elevated privileges.EPSS 0.2%CVE-2023-27386MEDIUMUncontrolled search path in some Intel(R) Pathfinder for RISC-V software may allow an authenticated user to potentially enable escalation ofEPSS 0.2%CVE-2024-33581HIGHA DLL hijack vulnerability was reported in Lenovo PC Manager AI intelligent scenario that could allow a local attacker to execute code with EPSS 0.2%CVE-2024-33579HIGHA DLL hijack vulnerability was reported in Lenovo Baiying that could allow a local attacker to execute code with elevated privileges.EPSS 0.2%CVE-2025-1804HIGHBlizzard Battle.Net profapi.dll uncontrolled search pathEPSS 0.2%CVE-2024-33582HIGHA DLL hijack vulnerability was reported in Lenovo Service Framework that could allow a local attacker to execute code with elevated privilegEPSS 0.2%CVE-2025-23309HIGHNVIDIA Display Driver contains a vulnerability where an uncontrolled DLL loading path might lead to arbitrary denial of service, escalation EPSS 0.2%CVE-2022-27595HIGHQVPN Device ClientEPSS 0.2%CVE-2026-28760HIGHThe installer of RATOC RAID Monitoring Manager for Windows searches the current directory to load certain DLLs. If a user is directed to plaEPSS 0.2%CVE-2026-56437HIGHUncontrolled search path element issue exists in Pupsman versions prior to 3.9.0. If a crafted DLL file is placed in the same folder as the EPSS 0.2%CVE-2026-44612HIGHBytello Share (Windows Edition) installer executable provided by Bytello insecurely loads Dynamic Link Libraries. If there is a crafted DLL EPSS 0.2%CVE-2026-68955HIGHThe installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at tEPSS 0.2%CVE-2026-7373HIGHMetasploit Pro on Windows: Local Privilege Escalation via OpenSSL Configuration File LoadingEPSS 0.2%CVE-2026-23741NONEast_coredumper running as root sources ast_debug_tools.conf from /etc/asterisk; potentially leading to privilege escalationEPSS 0.2%CVE-2026-24502HIGHDell Command | Intel vPro Out of Band, versions prior to 4.7.0, contain an Uncontrolled Search Path Element vulnerability. A low privileged EPSS 0.2%