Threats Tagged 'cwe-427'
View all threats tagged with 'cwe-427'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-427'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-13133: CWE-427 in LY Corporation LINE for WindowsCVE-2026-13133 0 A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, allowing a malicious DLL placed in the installer's directory to be loaded ahead of the legitimate System32 copy. Join the discussion | CVE Database V5 | 08/10/2026, 06:00:12 UTC Added: 08/10/2026, 06:41:46 UTC |
CVE-2026-9169: CWE-427 in LUCID Vision Labs Arena SDKCVE-2026-9169 0 DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by placing a malicious DLL in a user-controlled directory listed in the PATH environment variable, which the SDK traverses when a required dependency is not found locally. Join the discussion | CVE Database V5 | 08/07/2026, 08:47:13 UTC Added: 08/07/2026, 12:51:50 UTC |
CVE-2026-18657: CWE-427: Uncontrolled Search Path Element in Amazon Kiro CLICVE-2026-18657 0 An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user starts Kiro CLI in the directory. To remediate this issue, users should upgrade to version 2.10.0 or higher. Join the discussion | CVE Database V5 | 08/04/2026, 19:38:23 UTC Added: 08/04/2026, 20:12:01 UTC |
CVE-2026-18656 & CVE-2026-18657 - Issue with Kiro IDE and CLI - Executable Resolution from Untrusted Project Directory on WindowsCVE-2026-18656 0 Bulletin ID: 2026-074-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/04/2026 12:30 PM PDT Description: Kiro is an agentic IDE and command-line interface users install on their desktop. We identified CVE-2026-18656 and CVE-2026-18657, an issue where an uncontrolled search path element on Windows might allow an actor to execute arbitrary code via a maliciously crafted project directory containing a planted executable that is resolved before the system PATH when a local user opens the directory. Impacted versions: - Kiro IDE for Windows between versions 1.0.0 through 1.0.212 - Kiro CLI for Windows prior to v2.10.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin. Join the discussion | AWS Security Bulletins | 08/04/2026, 19:43:11 UTC Added: 08/04/2026, 19:45:17 UTC |
A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a… (CVE-2026-9593)CVE-2026-9593 0 CVE-2026-9593 is a vulnerability in the iDTM FDI software that allows an attacker with elevated privileges and host system access to enable the debug interface by placing a crafted file in the application directory. This can lead to unauthorized access to connected devices and potential exposure, modification, or disruption of device data or operations. The vulnerability has a CVSS 3.1 base score of 6.7, indicating a high severity level. No affected versions or patches are currently specified. Join the discussion | GCVE Database | 08/03/2026, 09:32:37 UTC Added: 08/03/2026, 21:22:06 UTC |
CVE-2026-48388: CWE-427: Uncontrolled Search Path Element in Adobe Adobe Photoshop InstallerCVE-2026-48388 0 Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could have exploited this vulnerability by placing a malicious library in a directory searched by the installer. Exploitation of this issue required user interaction in that a victim must have been running the installer. Scope is changed. Join the discussion | CVE Database V5 | 07/28/2026, 17:46:26 UTC Added: 07/28/2026, 17:52:41 UTC |
CVE-2026-8164: CWE-427 Uncontrolled Search Path Element in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desktop ClientCVE-2026-8164 0 Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desktop Client allows Search Order Hijacking. This issue affects ArkSigner Desktop Client: from v2.2.16.10 through 17062026. Join the discussion | CVE Database V5 | 07/28/2026, 14:01:02 UTC Added: 07/28/2026, 14:37:47 UTC |
CVE-2026-16519: CWE-427: Uncontrolled Search Path Element (DLL Search Order Hijacking / DLL Side-Loading) in GeoVision Inc. GV-IP Device UtilityCVE-2026-16519 0 A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location. Join the discussion | CVE Database V5 | 07/24/2026, 07:05:02 UTC Added: 07/24/2026, 07:37:46 UTC |
CVE-2026-21770: CWE-427 Uncontrolled Search Path Element in HCLSoftware HCL Traveler for Microsoft Outlook (HTMO)CVE-2026-21770 0 HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content. Join the discussion | CVE Database V5 | 07/17/2026, 04:42:54 UTC Added: 07/17/2026, 04:48:08 UTC |
CVE-2026-48272: Uncontrolled Search Path Element (CWE-427) in Adobe Creative Cloud DesktopCVE-2026-48272 0 Adobe Creative Cloud Desktop has an Uncontrolled Search Path Element vulnerability (CWE-427) that may allow arbitrary code execution with the privileges of the current user. Exploitation does not require user interaction but depends on external conditions outside the attacker's control. The vulnerability has a high severity rating with a CVSS score of 7.8. No affected versions or patch information are currently provided. Join the discussion | CVE Database V5 | 07/15/2026, 05:00:00 UTC Added: 07/14/2026, 20:33:33 UTC |
Showing 1 to 10 of 13 results