Weaknesses of type CWE-427

897 results

Caminho de busca ou elemento não controlado

A aplicação procura por bibliotecas, configurações ou outros recursos em diretórios sem validar adequadamente quais caminhos ela está usando, permitindo que um atacante injete uma versão maliciosa em um local que será encontrado primeiro. Isso acontece porque a ordem ou composição do caminho de busca não é explicitamente controlada.

Example

Um programa Java com classpath que inclui o diretório atual (.) antes de caminhos do sistema; um atacante coloca uma classe maliciosa no diretório de trabalho e ela é carregada em vez da legítima. Ou um script que procura por um arquivo de configuração em múltiplas pastas sem especificar o caminho absoluto, sendo enganado por um arquivo plantado em /tmp.

How to mitigate

Use caminhos absolutos explícitos em vez de relativos; remova diretórios inseguros (como o atual) do caminho de busca; valide a origem e integridade de recursos carregados (checksums, assinaturas); implemente listas de permitidos para diretórios confiáveis.

CVE-2026-34175MEDIUMUncontrolled search path for some Hardware-Aware-Automated-MachineLearning NA before version 45cd723 within Ring 3: User Applications may alEPSS 0.2%CVE-2026-15515HIGHTencent PC Manager QMUDisk Driver qmudisk64.sys uncontrolled search pathEPSS 0.2%CVE-2026-18605HIGHCheckMAL AppCheck Pro Kernel Mini-Filter Driver AppCheckD.sys uncontrolled search pathEPSS 0.2%CVE-2024-36253MEDIUMUncontrolled search path in the Intel(R) SDP Tool for Windows software all version may allow an authenticated user to potentially enable escEPSS 0.2%CVE-2024-38383MEDIUMUncontrolled search path for some Intel(R) Quartus(R) Prime Pro Edition software for Windows before version 24.2 may allow an authenticated EPSS 0.2%CVE-2024-38668MEDIUMUncontrolled search path for some Intel(R) Quartus(R) Prime Standard Edition software for Windows before version 23.1.1 may allow an authentEPSS 0.2%CVE-2026-6421HIGHMobatek MobaXterm Home Edition msimg32.dll uncontrolled search pathEPSS 0.2%CVE-2022-43456MEDIUMUncontrolled search path in some Intel(R) RST software before versions 16.8.5.1014.5, 17.11.3.1010.2, 18.7.6.1011.2 and 19.5.2.1049.5 may alEPSS 0.2%CVE-2023-28405MEDIUMUncontrolled search path in the Intel(R) Distribution of OpenVINO(TM) Toolkit before version 2022.3.0 may allow an authenticated user to potEPSS 0.2%CVE-2023-29151MEDIUMUncontrolled search path element in some Intel(R) PSR SDK before version 1.0.0.20 may allow an authenticated user to potentially enable escaEPSS 0.2%CVE-2022-25864MEDIUMUncontrolled search path in some Intel(R) oneMKL software before version 2022.0 may allow an authenticated user to potentially enable escalaEPSS 0.2%CVE-2023-25944MEDIUMUncontrolled search path element in some Intel(R) VCUST Tool software downloaded before February 3nd 2023 may allow an authenticated user toEPSS 0.2%CVE-2023-31197MEDIUMUncontrolled search path in the Intel(R) Trace Analyzer and Collector before version 2020 update 3 may allow an authenticated user to potentEPSS 0.2%CVE-2026-26097HIGHUncontrolled Search Path Element in Owl opdsEPSS 0.2%CVE-2026-8164HIGHSearch Order Hijacking in ArkSigner's ArkSigner Desktop ClientEPSS 0.2%CVE-2024-39820MEDIUMZoom Workplace Desktop App for macOS - Uncontrolled Search Path ElementEPSS 0.2%CVE-2025-8087HIGHA DLL hijacking vulnerability in AMD Power Design Manager could allow a malicious local attacker to escalate privileges during the uninstallEPSS 0.2%CVE-2025-54512HIGHA DLL hijacking vulnerability within the AMD Ryzen Master installation could allow a local user-privileged attacker to escalate privileges, EPSS 0.2%CVE-2026-26099HIGHUncontrolled Search Path Element in Owl opdsEPSS 0.2%CVE-2026-24016HIGHThe installer of ServerView Agents for Windows provided by Fsas Technologies Inc. may insecurely load Dynamic Link Libraries. Arbitrary codeEPSS 0.2%