CWE-426: CWE-426
Yearly Trend
Top Affected Vendors
All CWE-426 CVEs (127)
OpenTelemetry-Go SDK versions v1.20.0 through v1.39.0 on macOS/Darwin systems are vulnerable to path hijacking attacks. An attacker with local access ...
Feb 2, 2026This vulnerability allows an unauthorized attacker to execute arbitrary code on a local system by exploiting an untrusted search path in Microsoft Off...
Jan 13, 2026This CVE describes an unquoted search path vulnerability in Muse Group MuseHub's Windows Service updater component. Attackers with local access could ...
Nov 20, 2025CVE-2025-12286 is an unquoted search path vulnerability in VeePN's AVService component that allows local attackers to execute arbitrary code by placin...
Oct 27, 2025This CVE describes an unquoted search path vulnerability in Hasleo Backup Suite services (HasleoImageMountService/HasleoBackupSuiteService) up to vers...
Oct 27, 2025This vulnerability in LibreWolf's Windows installer allows local attackers to hijack the installation process through DLL search path manipulation. It...
Oct 19, 2025This vulnerability in Mechrevo Control Center allows local attackers to exploit an uncontrolled search path (DLL hijacking) in the PowerShell Script H...
Aug 15, 2025This is a critical uncontrolled search path vulnerability (DLL hijacking) in Wondershare Filmora's installer component. Attackers can exploit it by pl...
May 26, 2025This CVE describes a critical privilege escalation vulnerability in ToDesk 4.7.6.3 where an uncontrolled search path in profapi.dll allows local attac...
May 11, 2025This critical vulnerability in SunloginClient allows local attackers to exploit an uncontrolled search path (DLL hijacking) in the sunlogin_guard.exe ...
May 11, 2025This CVE describes a critical uncontrolled search path vulnerability in Patch My PC Home Updater up to version 5.1.3.0, allowing local attackers to ex...
May 9, 2025This vulnerability in Blizzard Battle.Net client involves an uncontrolled search path (DLL hijacking) in profapi.dll, allowing local attackers to exec...
Mar 1, 2025This CVE describes a potential untrusted search path vulnerability in Kong Insomnia's profapi.dll library that could allow local attackers to execute ...
Feb 16, 2025This vulnerability allows DLL injection in Veeam Agent for Windows when the system's PATH variable includes insecure directories. Attackers can place ...
Dec 4, 2024This CVE describes an untrusted search path vulnerability in Adobe Premiere Pro that could allow arbitrary code execution. Attackers could exploit thi...
Jul 9, 2024This CVE allows local Windows users to escalate privileges by hijacking the system search path. The Python installer on Windows can incorrectly add us...
Mar 10, 2022This CVE describes an untrusted search path vulnerability in Zoom Workplace Desktop App and Zoom Meeting SDK for macOS. It allows a privileged user wi...
Aug 14, 2024CVE-2025-43079 is a path injection vulnerability in Qualys Cloud Agent's uninstall script that allows local privilege escalation. When the script runs...
Nov 10, 2025This CVE describes a local privilege escalation vulnerability in Acronis Cyber Protect Cloud Agent for Windows. Attackers can exploit DLL hijacking to...
Jan 31, 2025This CVE describes a local privilege escalation vulnerability in Acronis Cyber Protect Cloud Agent for Windows. Attackers can exploit DLL hijacking to...
Jan 31, 2025A race condition vulnerability in Zoom Client for Windows installers could allow an unauthenticated local attacker to compromise application integrity...
Aug 12, 2025IBM App Connect Enterprise Certified Container versions up to 12.19.0 (Continuous Delivery) and 12.0 LTS (Long Term Support) contain an untrusted sear...
Feb 5, 2026This CVE describes a local privilege escalation vulnerability in Zoom Workplace Apps for Windows installers. An authorized user with local access can ...
Jan 30, 2025This vulnerability in Postman for Windows allows local attackers to execute arbitrary code via DLL hijacking in the profapi.dll library. It affects Po...
Jan 27, 2025This vulnerability in Epic Games Launcher involves an untrusted search path issue in the profapi.dll library during installation. Attackers could pote...
Jan 19, 2025An improper input validation vulnerability in Tanium Appliance could allow attackers to cause unexpected behavior or denial of service. This affects o...
Feb 5, 2026An untrusted search path vulnerability in Lexmark's Embedded Solutions Framework allows attackers to execute arbitrary code by manipulating the search...
Feb 3, 2026About CWE-426 (CWE-426)
Our database tracks 127 CVEs classified as CWE-426, with 10 rated critical and 106 rated high severity. The average CVSS score for CWE-426 vulnerabilities is 7.6.
External reference: View CWE-426 on MITRE CWE →
Monitor CWE-426 Vulnerabilities
Get alerted when new CWE-426 CVEs affect your infrastructure.
Start Monitoring Free