Weaknesses of type CWE-427

897 results

Caminho de busca ou elemento não controlado

A aplicação procura por bibliotecas, configurações ou outros recursos em diretórios sem validar adequadamente quais caminhos ela está usando, permitindo que um atacante injete uma versão maliciosa em um local que será encontrado primeiro. Isso acontece porque a ordem ou composição do caminho de busca não é explicitamente controlada.

Example

Um programa Java com classpath que inclui o diretório atual (.) antes de caminhos do sistema; um atacante coloca uma classe maliciosa no diretório de trabalho e ela é carregada em vez da legítima. Ou um script que procura por um arquivo de configuração em múltiplas pastas sem especificar o caminho absoluto, sendo enganado por um arquivo plantado em /tmp.

How to mitigate

Use caminhos absolutos explícitos em vez de relativos; remova diretórios inseguros (como o atual) do caminho de busca; valide a origem e integridade de recursos carregados (checksums, assinaturas); implemente listas de permitidos para diretórios confiáveis.

CVE-2022-34900HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.3 (39313) Agent. An attacEPSS 0.4%CVE-2025-30672MEDIUMMite for Perl generates code with an untrusted search path vulnerabilityEPSS 0.4%CVE-2025-33208HIGHNVIDIA TAO contains a vulnerability where an attacker may cause a resource to be loaded via an uncontrolled search path. A successful exploiEPSS 0.4%CVE-2019-25268HIGHNREL BEopt 2.8.0 Insecure Library Loading Arbitrary Code ExecutionEPSS 0.4%CVE-2025-30673MEDIUMSub::HandlesVia for Perl allows untrusted code to be included from the current working directoryEPSS 0.4%CVE-2025-3051MEDIUMLinux::Statm::Tiny for Perl allows untrusted code to be included from the current working directoryEPSS 0.4%CVE-2019-6564—GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to place malicious files within the installer file directorEPSS 0.4%CVE-2021-36216—LINE for Windows 6.2.1.2289 and before allows arbitrary code execution via malicious DLL injection.EPSS 0.4%CVE-2026-54916HIGHNetBox Device Type Library: Module Shadowing Bypass of prior pickle fix - RCE via missing `tests/__init__.py` + SSRF via unfixed `NETBOX_DT_LIBRARY_URL` → Cloud Metadata credential theftEPSS 0.4%CVE-2025-33122HIGHIBM i privilege escalationEPSS 0.4%CVE-2020-6654HIGHDLL HijackingEPSS 0.4%CVE-2024-30376HIGHFamatech Advanced IP Scanner Uncontrolled Search Path Element Local Privilege Escalation VulnerabilityEPSS 0.4%CVE-2022-29580HIGHPath Traversal in Android Google Search AppEPSS 0.4%CVE-2017-11158—Multiple untrusted search path vulnerabilities in the installer in Synology Cloud Station Drive before 4.2.5-4396 on Windows allow local attEPSS 0.4%CVE-2026-28456HIGHOpenClaw 2026.1.5 < 2026.2.14 - Arbitrary Code Execution via Unsafe Hook Module Path HandlingEPSS 0.4%CVE-2023-0247HIGHUncontrolled Search Path Element in bits-and-blooms/bloomEPSS 0.4%CVE-2023-26266HIGHIn AFL++ 4.05c, the CmpLog component uses the current working directory to resolve and execute unprefixed fuzzing targets, allowing code exeEPSS 0.4%CVE-2023-30237HIGHCyberGhostVPN Windows Client before v8.3.10.10015 was discovered to contain a DLL injection vulnerability via the component Dashboard.exe.EPSS 0.4%CVE-2025-22458HIGHDLL hijacking in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an authenticated attacker to escalate to EPSS 0.4%CVE-2021-1237HIGHCisco AnyConnect Secure Mobility Client for Windows DLL Injection VulnerabilityEPSS 0.4%