CWE-426: CWE-426

127
Total CVEs
10
Critical
106
High
7.6
Avg CVSS

Yearly Trend

2026
16
2025
43
2024
28
2023
25
2022
7

Top Affected Vendors

1 Microsoft 16
2 Wondershare 8
3 Zoom 7
4 Adobe 5
5 Autodesk 4
6 Netapp 2
7 Git For Windows Project 2
8 Fortinet 2
9 Sumatrapdfreader 2
10 Python 2

All CWE-426 CVEs (127)

CVE-2026-24051
7.0

OpenTelemetry-Go SDK versions v1.20.0 through v1.39.0 on macOS/Darwin systems are vulnerable to path hijacking attacks. An attacker with local access ...

Feb 2, 2026
CVE-2026-20943
7.0

This vulnerability allows an unauthorized attacker to execute arbitrary code on a local system by exploiting an untrusted search path in Microsoft Off...

Jan 13, 2026
CVE-2025-13433
7.0

This CVE describes an unquoted search path vulnerability in Muse Group MuseHub's Windows Service updater component. Attackers with local access could ...

Nov 20, 2025
CVE-2025-12286
7.0

CVE-2025-12286 is an unquoted search path vulnerability in VeePN's AVService component that allows local attackers to execute arbitrary code by placin...

Oct 27, 2025
CVE-2025-12247
7.0

This CVE describes an unquoted search path vulnerability in Hasleo Backup Suite services (HasleoImageMountService/HasleoBackupSuiteService) up to vers...

Oct 27, 2025
CVE-2025-11940
7.0

This vulnerability in LibreWolf's Windows installer allows local attackers to hijack the installation process through DLL search path manipulation. It...

Oct 19, 2025
CVE-2025-9016
7.0

This vulnerability in Mechrevo Control Center allows local attackers to exploit an uncontrolled search path (DLL hijacking) in the PowerShell Script H...

Aug 15, 2025
CVE-2025-5180
7.0

This is a critical uncontrolled search path vulnerability (DLL hijacking) in Wondershare Filmora's installer component. Attackers can exploit it by pl...

May 26, 2025
CVE-2025-4539
7.0

This CVE describes a critical privilege escalation vulnerability in ToDesk 4.7.6.3 where an uncontrolled search path in profapi.dll allows local attac...

May 11, 2025
CVE-2025-4532
7.0

This critical vulnerability in SunloginClient allows local attackers to exploit an uncontrolled search path (DLL hijacking) in the sunlogin_guard.exe ...

May 11, 2025
CVE-2025-4455
7.0

This CVE describes a critical uncontrolled search path vulnerability in Patch My PC Home Updater up to version 5.1.3.0, allowing local attackers to ex...

May 9, 2025
CVE-2025-1804
7.0

This vulnerability in Blizzard Battle.Net client involves an uncontrolled search path (DLL hijacking) in profapi.dll, allowing local attackers to exec...

Mar 1, 2025
CVE-2025-1353
7.0

This CVE describes a potential untrusted search path vulnerability in Kong Insomnia's profapi.dll library that could allow local attackers to execute ...

Feb 16, 2025
CVE-2024-45207
7.0

This vulnerability allows DLL injection in Veeam Agent for Windows when the system's PATH variable includes insecure directories. Attackers can place ...

Dec 4, 2024
CVE-2024-34123
7.0

This CVE describes an untrusted search path vulnerability in Adobe Premiere Pro that could allow arbitrary code execution. Attackers could exploit thi...

Jul 9, 2024
CVE-2022-26488
7.0

This CVE allows local Windows users to escalate privileges by hijacking the system search path. The Python installer on Windows can incorrectly add us...

Mar 10, 2022
CVE-2024-42439
6.5

This CVE describes an untrusted search path vulnerability in Zoom Workplace Desktop App and Zoom Meeting SDK for macOS. It allows a privileged user wi...

Aug 14, 2024
CVE-2025-43079
6.3

CVE-2025-43079 is a path injection vulnerability in Qualys Cloud Agent's uninstall script that allows local privilege escalation. When the script runs...

Nov 10, 2025
CVE-2025-24830
6.3

This CVE describes a local privilege escalation vulnerability in Acronis Cyber Protect Cloud Agent for Windows. Attackers can exploit DLL hijacking to...

Jan 31, 2025
CVE-2025-24828
6.3

This CVE describes a local privilege escalation vulnerability in Acronis Cyber Protect Cloud Agent for Windows. Attackers can exploit DLL hijacking to...

Jan 31, 2025
CVE-2025-49456
6.2

A race condition vulnerability in Zoom Client for Windows installers could allow an unauthenticated local attacker to compromise application integrity...

Aug 12, 2025
CVE-2025-13491
5.1

IBM App Connect Enterprise Certified Container versions up to 12.19.0 (Continuous Delivery) and 12.0 LTS (Long Term Support) contain an untrusted sear...

Feb 5, 2026
CVE-2025-0145
4.6

This CVE describes a local privilege escalation vulnerability in Zoom Workplace Apps for Windows installers. An authorized user with local access can ...

Jan 30, 2025
CVE-2025-0733
4.5

This vulnerability in Postman for Windows allows local attackers to execute arbitrary code via DLL hijacking in the profapi.dll library. It affects Po...

Jan 27, 2025
CVE-2025-0567
4.5

This vulnerability in Epic Games Launcher involves an untrusted search path issue in the profapi.dll library during installation. Attackers could pote...

Jan 19, 2025
CVE-2025-15321
2.7

An improper input validation vulnerability in Tanium Appliance could allow attackers to cause unexpected behavior or denial of service. This affects o...

Feb 5, 2026
CVE-2025-65078
N/A

An untrusted search path vulnerability in Lexmark's Embedded Solutions Framework allows attackers to execute arbitrary code by manipulating the search...

Feb 3, 2026

About CWE-426 (CWE-426)

Our database tracks 127 CVEs classified as CWE-426, with 10 rated critical and 106 rated high severity. The average CVSS score for CWE-426 vulnerabilities is 7.6.

External reference: View CWE-426 on MITRE CWE →

Monitor CWE-426 Vulnerabilities

Get alerted when new CWE-426 CVEs affect your infrastructure.

Start Monitoring Free