Falhas do tipo CWE-426

282 resultados
CVE-2024-21923HIGHIncorrect default permissions in AMD StoreMI™ could allow an attacker to achieve privilege escalation potentially resulting in arbitrary codEPSS 0.1%CVE-2026-53858HIGHOpenClaw < 2026.5.2 - Arbitrary Runtime Dependency Loading via STATE_DIRECTORY Environment VariableEPSS 0.1%CVE-2022-4987HIGHHirschmann Industrial HiVision External Application Path Hijacking Leading to Arbitrary Code ExecutionEPSS 0.1%CVE-2026-32016HIGHOpenClaw < 2026.2.22 - Path Traversal via Basename-Only Allowlist Matching on macOSEPSS 0.1%CVE-2024-14012HIGHPotential Privilege Escalation in Revenera InstallShield 2023 R1EPSS 0.1%CVE-2025-13433HIGHMuse Group MuseHub Windows Service Muse.Updater.exe unquoted search pathEPSS 0.1%CVE-2025-39666CRITICALomd: Local privilege escalation when executing omd commands as rootEPSS 0.1%CVE-2026-3780HIGHFoxit PDF Editor/Reader Installer Uncontrolled Search Path Privilege EscalationEPSS 0.1%CVE-2026-53865HIGHOpenClaw < 2026.5.2 - Arbitrary Command Execution via Workspace-Derived Service PATHEPSS 0.1%CVE-2026-30906HIGHUntrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user to enable an escalatiEPSS 0.1%CVE-2026-53846HIGHOpenClaw < 2026.4.29 - Arbitrary Package Manager Execution via Workspace .env npm_execpathEPSS 0.1%CVE-2025-30407MEDIUMLocal privilege escalation due to a binary hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (EPSS 0.1%CVE-2026-2516HIGHUnidocs ezPDF DRM Reader/ezPDF Reader SHFOLDER.dll uncontrolled search pathEPSS 0.1%CVE-2025-12793HIGHAn uncontrolled DLL loading path vulnerability exists in AsusSoftwareManagerAgent. A local attacker may influence the application to load a EPSS 0.1%CVE-2025-15569HIGHArtifex MuPDF win_main.c get_system_dpi uncontrolled search pathEPSS 0.1%CVE-2025-67722MEDIUMAuthenticated amportal search for ‘freepbx_engine’ in non root writeable directories leads to potential privilege escalationEPSS 0.1%CVE-2026-35603MEDIUMClaude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on WindowsEPSS 0.1%CVE-2025-49642MEDIUMAgent builds for AIX vulnerable to library loading hijackingEPSS 0.1%CVE-2026-2998HIGHeAI Technologies|ERP - DLL HijackingEPSS 0.1%CVE-2025-49456MEDIUMZoom Clients for Windows- Race ConditionEPSS 0.1%