Threats Tagged 'cwe-428'
View all threats tagged with 'cwe-428'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-428'
Click on any threat for detailed analysis and mitigation recommendations
0 ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 were vulnerable to an unauthorized Path Traversal vulnerability. Join the discussion | CVE Database V5 | 09/23/2026, 11:36:25 UTC Added: 09/23/2026, 11:48:36 UTC |
0 Dell Inventory Collector Client versions prior to 15.0.0 contain an unquoted search path vulnerability (CWE-428). This flaw allows a low privileged local attacker to potentially execute code and elevate privileges on the affected system. The vulnerability has a high severity rating with a CVSS score of 7.8. Join the discussion | CVE Database V5 | 09/21/2026, 19:26:29 UTC Added: 09/21/2026, 19:32:11 UTC |
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, the Windows service installation and parameter-update logic in src/win32-service.c can pass an unquoted service ImagePath to CreateServiceA. When Suricata is installed below a path containing spaces and an earlier path component is writable by a local low-privileged attacker, Windows can execute an attacker-controlled program as LocalSystem, resulting in local privilege escalation. This issue is fixed in versions 8.0.6 and 7.0.17. Join the discussion | CVE Database V5 | 09/18/2026, 20:23:28 UTC Added: 09/18/2026, 20:47:24 UTC |
Maono Link 3.8.13 MaonoAiServices Windows service allows local privilege escalation for a standard user account via improper write privileges in 'C:\ProgramData\Maono'. Fixed in 4.0.80. Join the discussion | CVE Database V5 | 09/08/2026, 20:22:29 UTC Added: 09/08/2026, 20:38:15 UTC |
0 CVE-2026-18755 is a DLL hijacking vulnerability in GeoVision Inc.'s GV-ASManager version 6.3.0. It allows a local attacker with write access to an unsafe search directory to execute arbitrary code by placing a malicious DLL earlier in the search path. The malicious code runs with the privileges of the GV-ASManager process. The vulnerability has a high severity score of 7.3 and requires local privileges with user interaction to exploit. Join the discussion | CVE Database V5 | 08/04/2026, 07:09:50 UTC Added: 08/04/2026, 07:33:45 UTC |
0 A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to unintended executables placed earlier in the search order. If exploited, an attacker could plant a malicious executable in a location within the search path, resulting in arbitrary code execution with the same permissions of the user running the application. Join the discussion | CVE Database V5 | 07/14/2026, 15:12:49 UTC Added: 07/14/2026, 15:48:15 UTC |
The HP Fan Control App might allow local escalation of privileges. An updated version of HP Fan Control App has been released to mitigate this potential vulnerability. Join the discussion | CVE Database V5 | 06/30/2026, 16:21:10 UTC Added: 06/30/2026, 16:52:02 UTC |
AVACAST developed by eMPIA Technology has a Unquoted Service Path vulnerability, allowing privileged local attackers to place a malicious executable file in a specific directory, resulting in arbitrary code execution with system privileges when the AVACAST service starts. Join the discussion | CVE Database V5 | 04/28/2026, 09:46:52 UTC Added: 04/28/2026, 10:06:58 UTC |
Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable located at 'C:\Program Files (x86)\shttps_mg\http.exe service'. This misconfiguration allows a local attacker to place a malicious executable with the same name in a higher priority directory, causing the service to execute the malicious file instead of the legitimate one. Exploiting this flaw could allow arbitrary code execution, unauthorized access to the system, or service disruption. To mitigate the risk, the service path must be properly quoted, and systems must be kept up to date with security patches, while restricting physical and network access. Join the discussion | CVE Database V5 | 03/26/2026, 12:20:03 UTC Added: 03/26/2026, 12:46:39 UTC |
MobaXterm versions prior to 26.1 contain an uncontrolled search path element vulnerability. The application calls WinExec to execute Notepad++ without a fully qualified executable path when opening remote files. An attacker can exploit the search path behavior by placing a malicious executable earlier in the search order, resulting in arbitrary code execution in the context of the affected user. Join the discussion | CVE Database V5 | 03/09/2026, 15:24:47 UTC Added: 03/09/2026, 15:52:44 UTC |
Showing 1 to 10 of 32 results