CWE-427: CWE-427

401
Total CVEs
7
Critical
286
High
7.5
Avg CVSS

Yearly Trend

2026
36
2025
151
2024
88
2023
45
2022
26

Top Affected Vendors

1 Intel 37
2 Acronis 13
3 Dell 11
4 Mailenable 10
5 Lenovo 8
6 Microsoft 8
7 Adobe 8
8 Trendmicro 7
9 Siemens 7
10 Nvidia 6

All CWE-427 CVEs (401)

CVE-2024-34167
6.7

This vulnerability in Intel Server Board S2600ST Family BIOS/Firmware Update software allows authenticated local users to escalate privileges by manip...

Nov 13, 2024
CVE-2024-34164
6.7

This vulnerability in Intel MAS software allows authenticated local users to escalate privileges by manipulating the search path. It affects systems r...

Nov 13, 2024
CVE-2024-31407
6.7

This vulnerability allows an authenticated user with local access to potentially escalate privileges through an uncontrolled search path in Intel High...

Nov 13, 2024
CVE-2024-28952
6.7

This vulnerability in Intel IPP software for Windows allows authenticated local users to escalate privileges by manipulating the DLL search path. It a...

Nov 13, 2024
CVE-2024-23312
6.7

This vulnerability in Intel Binary Configuration Tool for Windows allows authenticated local users to escalate privileges by manipulating the DLL sear...

Nov 13, 2024
CVE-2024-47195
6.7

This vulnerability allows authenticated local attackers to execute arbitrary code with elevated privileges by placing a malicious executable in a dire...

Oct 8, 2024
CVE-2024-29015
6.7

This vulnerability in Intel VTune Profiler allows authenticated local users to escalate privileges by manipulating the software's search path. It affe...

Aug 14, 2024
CVE-2024-28172
6.7

This vulnerability in Intel Trace Analyzer and Collector allows authenticated local users to escalate privileges by manipulating the software's search...

Aug 14, 2024
CVE-2024-28887
6.7

This vulnerability in Intel IPP software allows authenticated local users to escalate privileges by exploiting an uncontrolled search path (DLL hijack...

Aug 14, 2024
CVE-2024-26027
6.7

This vulnerability in Intel Simics Package Manager allows authenticated local users to escalate privileges by manipulating the software's search path....

Aug 14, 2024
CVE-2024-28046
6.7

This vulnerability in Intel GPA software allows authenticated local users to escalate privileges by manipulating the software's search path. It affect...

Aug 14, 2024
CVE-2024-24977
6.7

This vulnerability in Intel License Manager for FLEXlm allows authenticated local users to escalate privileges by manipulating the software's search p...

Aug 14, 2024
CVE-2024-23909
6.7

This vulnerability in Intel FPGA SDK for OpenCL allows authenticated local users to escalate privileges by manipulating the search path for DLLs or sh...

Aug 14, 2024
CVE-2024-23907
6.7

This vulnerability in Intel High Level Synthesis Compiler allows authenticated local users to escalate privileges by manipulating the search path. It ...

Aug 14, 2024
CVE-2024-22376
6.7

This vulnerability in Intel Ethernet Adapter Driver Pack allows authenticated local users to escalate privileges by manipulating the software's search...

Aug 14, 2024
CVE-2024-23489
6.7

This vulnerability in Intel VROC software allows authenticated local users to escalate privileges by manipulating the software's search path. It affec...

Aug 14, 2024
CVE-2024-22184
6.7

This vulnerability in Intel Quartus Prime Pro Edition Design Software allows authenticated local users to escalate privileges by exploiting an uncontr...

Aug 14, 2024
CVE-2024-21766
6.7

This vulnerability in Intel oneAPI Math Kernel Library allows authenticated local users to escalate privileges by manipulating the library search path...

Aug 14, 2024
CVE-2024-21784
6.7

This vulnerability in Intel IPP Cryptography software allows authenticated local users to escalate privileges by manipulating the DLL search path. It ...

Aug 14, 2024
CVE-2024-21843
6.7

This vulnerability in Intel Computing Improvement Program software allows authenticated local users to escalate privileges by manipulating the search ...

May 16, 2024
CVE-2024-21862
6.7

This vulnerability in Intel Quartus Prime Standard Edition Design software allows authenticated local users to escalate privileges by exploiting an un...

May 16, 2024
CVE-2024-21831
6.7

This vulnerability in Intel Processor Diagnostic Tool allows authenticated local users to escalate privileges by exploiting an uncontrolled search pat...

May 16, 2024
CVE-2024-21837
6.7

This vulnerability in Intel Quartus Prime Lite Edition software allows authenticated local users to escalate privileges by exploiting an uncontrolled ...

May 16, 2024
CVE-2024-21818
6.7

This vulnerability in Intel PCM software allows authenticated local users to escalate privileges by manipulating the software's search path. It affect...

May 16, 2024
CVE-2024-21774
6.7

This vulnerability in Intel Processor Identification Utility software allows authenticated local users to escalate privileges by exploiting an uncontr...

May 16, 2024
CVE-2024-21788
6.7

This vulnerability in Intel GPA software allows authenticated local users to escalate privileges by manipulating the search path for DLLs or other fil...

May 16, 2024
CVE-2023-41961
6.7

This vulnerability in Intel GPA software allows authenticated local users to escalate privileges by manipulating the software's search path. It affect...

May 16, 2024
CVE-2023-40155
6.7

This vulnerability in Intel CST software allows authenticated local users to escalate privileges by manipulating the software's search path. It affect...

May 16, 2024
CVE-2025-11772
6.6

This vulnerability allows a local attacker to place a malicious DLL in the C:\ProgramData\Synaptics folder, which then gets executed with elevated pri...

Dec 1, 2025
CVE-2024-39820
6.6

An uncontrolled search path vulnerability in the Zoom Workplace Desktop App installer for macOS allows authenticated local users to cause denial of se...

Jul 15, 2024
CVE-2025-64994
6.5

A privilege escalation vulnerability in TeamViewer DEX (formerly 1E DEX) allows local attackers with write access to a PATH directory to execute arbit...

Dec 11, 2025
CVE-2025-64995
6.5

This CVE describes a local privilege escalation vulnerability in TeamViewer DEX (formerly 1E DEX) where attackers with local access during execution c...

Dec 11, 2025
CVE-2024-42191
6.5

HCL Traveler for Microsoft Outlook (HTMO) has a COM hijacking vulnerability that allows attackers to replace legitimate application components with ma...

May 30, 2025
CVE-2025-3051
6.5

This vulnerability in Linux::Statm::Tiny for Perl allows untrusted code from the current working directory to be loaded due to insecure module loading...

Apr 1, 2025
CVE-2025-30672
6.5

Mite for Perl before version 0.013000 includes the current working directory ('.') in Perl's @INC module search path, similar to CVE-2016-1238. This a...

Apr 1, 2025
CVE-2026-28712
6.3

This CVE describes a local privilege escalation vulnerability in Acronis Cyber Protect 17 for Windows due to DLL hijacking. Attackers with local acces...

Mar 6, 2026
CVE-2024-50583
6.3

This vulnerability in Whale browser Installer allows attackers to execute malicious DLL files in the user's environment due to improper permission set...

Oct 25, 2024
CVE-2024-2207
6.0

This vulnerability in HP PC audio drivers could allow attackers to escalate privileges on affected systems. It affects HP computers using specific Sou...

Nov 12, 2024
CVE-2025-7427
5.9

Arm Development Studio versions before 2025 contain a DLL hijacking vulnerability (CWE-427) where attackers can place malicious DLLs in directories se...

Jul 22, 2025
CVE-2026-26097
5.5

CVE-2026-26097 is an uncontrolled search path element vulnerability in Owl opds 2.2.0.4 that allows attackers to manipulate configuration file search ...

Feb 20, 2026
CVE-2026-26099
5.5

CVE-2026-26099 is a path traversal vulnerability in Owl opds 2.2.0.4 that allows attackers to manipulate configuration file search paths via crafted n...

Feb 20, 2026
CVE-2024-44168
5.5

This CVE describes a library injection vulnerability in macOS that allows applications to bypass file system protection mechanisms. An attacker could ...

Sep 17, 2024
CVE-2024-7193
5.3

This vulnerability in Mp3tag allows attackers to execute arbitrary code by placing a malicious DLL in a location where the application searches for de...

Jul 29, 2024
CVE-2025-48496
5.1

This vulnerability in Emerson ValveLink products allows attackers to manipulate the search path for resources, potentially leading to execution of mal...

Jul 11, 2025
CVE-2026-23740
0.0

This vulnerability in Asterisk allows local attackers to escalate privileges to root by exploiting insecure temporary file handling in the ast_coredum...

Feb 6, 2026
CVE-2026-23741
0.0

Asterisk's ast_coredumper script runs with root privileges and sources a configuration file that can be modified by the asterisk user. This allows an ...

Feb 6, 2026
CVE-2025-71178
N/A

This CVE describes a DLL preloading vulnerability in Crucial Storage Executive installer versions before 11.08.082025.00. When the installer runs with...

Jan 26, 2026
CVE-2025-5469
N/A

This CVE describes a Search Order Hijacking vulnerability in Yandex Messenger (Telemost) on macOS, where an attacker can place a malicious library in ...

Dec 9, 2025
CVE-2025-5470
N/A

This CVE describes a Search Order Hijacking vulnerability in Yandex Disk for macOS, where an attacker could place malicious files in locations that th...

Dec 9, 2025
CVE-2025-13051
N/A

This vulnerability allows attackers to achieve privilege escalation by planting malicious DLLs in writable service directories. When ABP or AES servic...

Nov 19, 2025

About CWE-427 (CWE-427)

Our database tracks 401 CVEs classified as CWE-427, with 7 rated critical and 286 rated high severity. The average CVSS score for CWE-427 vulnerabilities is 7.5.

External reference: View CWE-427 on MITRE CWE →

Monitor CWE-427 Vulnerabilities

Get alerted when new CWE-427 CVEs affect your infrastructure.

Start Monitoring Free