CWE-428: CWE-428

127
Total CVEs
2
Critical
107
High
7.7
Avg CVSS

Yearly Trend

2026
61
2025
26
2024
12
2023
8
2022
13

Top Affected Vendors

1 Sap 2
2 Akamai 1
3 Anytxt 1
4 Zscaler 1
5 Veepn 1
6 Rumble Mail Server Project 1
7 Proton 1
8 Windscribe 1
9 Vembu 1
10 Python 1

All CWE-428 CVEs (127)

CVE-2022-50935
9.8

CVE-2022-50935 is an unquoted service path vulnerability in the Flame II HSPA USB Modem software for Windows. Attackers can exploit this to execute ar...

Jan 13, 2026
CVE-2024-24722
9.1

An unquoted service path vulnerability in 12d Synergy Server and File Replication Server allows attackers with local access to place malicious executa...

Feb 19, 2024
CVE-2025-36384
8.4

This vulnerability allows a local user with filesystem access to escalate privileges on IBM Db2 for Windows systems due to an unquoted search path ele...

Jan 30, 2026
CVE-2023-54336
8.4

CVE-2023-54336 is an unquoted service path vulnerability in Mediconta 3.7.27 that allows local attackers to execute arbitrary code with LocalSystem pr...

Jan 13, 2026
CVE-2023-54338
8.4

CVE-2023-54338 is an unquoted service path vulnerability in Tftpd32 SE 4.60 that allows local attackers to execute arbitrary code with SYSTEM privileg...

Jan 13, 2026
CVE-2022-50938
8.4

CVE-2022-50938 is an unquoted service path vulnerability in CONTPAQi AdminPAQ 14.0.0 that allows attackers to inject malicious code into the service b...

Jan 13, 2026
CVE-2023-53984
8.4

CVE-2023-53984 is an unquoted service path vulnerability in Clevo HotKey Clipboard 2.1.0.6 that allows local non-privileged users to escalate privileg...

Jan 13, 2026
CVE-2022-50929
8.4

CVE-2022-50929 is an unquoted service path vulnerability in Connectify Hotspot 2018 that allows local attackers to execute arbitrary code with elevate...

Jan 13, 2026
CVE-2022-50930
8.4

CVE-2022-50930 is an unquoted service path vulnerability in Emerson PAC Machine Edition 9.80's TrapiServer service that allows local attackers to exec...

Jan 13, 2026
CVE-2022-50924
8.4

CVE-2022-50924 is an unquoted service path vulnerability in Private Internet Access VPN client version 3.3 that allows local attackers to execute arbi...

Jan 13, 2026
CVE-2022-50918
8.4

CVE-2022-50918 is an unquoted service path vulnerability in VIVE Runtime Service that allows local attackers to execute arbitrary code with SYSTEM pri...

Jan 13, 2026
CVE-2022-50920
8.4

CVE-2022-50920 is an unquoted service path vulnerability in Sandboxie-Plus's SbieSvc Windows service. This allows local attackers to place malicious e...

Jan 13, 2026
CVE-2022-50913
8.4

CVE-2022-50913 is an unquoted service path vulnerability in ITeC ITeCProteccioAppServer that allows local attackers to execute arbitrary code with SYS...

Jan 13, 2026
CVE-2022-50914
8.4

CVE-2022-50914 is an unquoted service path vulnerability in EaseUS Data Recovery 15.1.0.0 that allows attackers to place malicious executables in the ...

Jan 13, 2026
CVE-2023-53965
8.4

CVE-2023-53965 is an unquoted service path vulnerability in SOUND4 Server Service 4.1.102 that allows local non-privileged users to escalate privilege...

Dec 22, 2025
CVE-2022-50688
8.4

CVE-2022-50688 is an unquoted service path vulnerability in Cobian Backup Gravity that allows local attackers to execute arbitrary code with SYSTEM pr...

Dec 22, 2025
CVE-2025-10714
8.4

CVE-2025-10714 is an unquoted search path vulnerability in AXIS Optimizer software that allows local attackers with administrative privileges to escal...

Nov 11, 2025
CVE-2020-14521
8.3

This vulnerability in Mitsubishi Electric Factory Automation engineering software allows malicious code execution, enabling attackers to steal data, m...

Feb 11, 2022
CVE-2024-34010
8.2

This CVE describes a local privilege escalation vulnerability in Acronis Windows products due to an unquoted search path issue. Attackers with local a...

Apr 29, 2024
CVE-2019-25345
7.8

CVE-2019-25345 is an unquoted service path vulnerability in Realtek IIS Codec Service that allows local attackers to execute arbitrary code with eleva...

Feb 12, 2026
CVE-2019-25306
7.8

CVE-2019-25306 is an unquoted service path vulnerability in BlackMoon FTP Server that allows local attackers to execute arbitrary code with LocalSyste...

Feb 11, 2026
CVE-2019-25308
7.8

CVE-2019-25308 is an unquoted service path vulnerability in Mikogo's Windows service that allows attackers with local access to execute arbitrary code...

Feb 11, 2026
CVE-2019-25310
7.8

ActiveFax Server 6.92 Build 0316 has an unquoted service path vulnerability in its ActiveFaxServiceNT service. This allows local attackers with write ...

Feb 11, 2026
CVE-2021-47898
7.8

Epson USB Display 1.6.0.0 contains an unquoted service path vulnerability in the EMP_UDSA service, which runs with LocalSystem privileges. Attackers c...

Jan 23, 2026
CVE-2021-47896
7.8

CVE-2021-47896 is an unquoted service path vulnerability in PDF Complete Corporate Edition's pdfcDispatcher service. Local attackers can exploit this ...

Jan 23, 2026
CVE-2021-47889
7.8

Softros LAN Messenger 9.6.4 contains an unquoted service path vulnerability in the SoftrosSpellChecker service that allows local attackers to execute ...

Jan 23, 2026
CVE-2021-47890
7.8

LogonExpert 8.1 contains an unquoted service path vulnerability in the LogonExpertSvc service. Attackers can place malicious executables in intermedia...

Jan 23, 2026
CVE-2021-47887
7.8

CVE-2021-47887 is an unquoted service path vulnerability in OKI Print Job Accounting 4.4.10 that allows local attackers to execute arbitrary code with...

Jan 21, 2026
CVE-2021-47882
7.8

FreeLAN 2.2 on Windows contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with LocalSystem privileg...

Jan 21, 2026
CVE-2021-47883
7.8

CVE-2021-47883 is an unquoted service path vulnerability in Sandboxie Plus's SbieSvc service that allows local attackers to execute arbitrary code wit...

Jan 21, 2026
CVE-2021-47884
7.8

CVE-2021-47884 is an unquoted service path vulnerability in OKI Configuration Tool 1.6.53 that allows local attackers to execute arbitrary code with e...

Jan 21, 2026
CVE-2021-47886
7.8

CVE-2021-47886 is an unquoted service path vulnerability in Pingzapper 2.3.1 that allows local attackers to execute arbitrary code with elevated privi...

Jan 21, 2026
CVE-2021-47879
7.8

CVE-2021-47879 is an unquoted service path vulnerability in eBeam Interactive Suite 3.6's eBeam Stylus Driver service. Local attackers can place malic...

Jan 21, 2026
CVE-2021-47880
7.8

CVE-2021-47880 is an unquoted service path vulnerability in Realtek Wireless LAN Utility that allows local attackers to execute arbitrary code with SY...

Jan 21, 2026
CVE-2021-47878
7.8

CVE-2021-47878 is an unquoted service path vulnerability in eBeam Education Suite's Device Service that allows local attackers to execute arbitrary co...

Jan 21, 2026
CVE-2021-47874
7.8

CVE-2021-47874 is an unquoted service path vulnerability in VFS for Git's GVFS.Service Windows service that allows local attackers to execute arbitrar...

Jan 21, 2026
CVE-2021-47868
7.8

CVE-2021-47868 is an unquoted service path vulnerability in WIN-PACK PRO 4.8's WPCommandFileService that allows local attackers to execute arbitrary c...

Jan 21, 2026
CVE-2021-47869
7.8

CVE-2021-47869 is an unquoted service path vulnerability in Brother BRAdmin Professional 3.75's BRA_Scheduler service. This allows local attackers to ...

Jan 21, 2026
CVE-2021-47864
7.8

CVE-2021-47864 is an unquoted service path vulnerability in OSAS Traverse Extension 11's TravExtensionHostSvc service. Attackers with local access can...

Jan 21, 2026
CVE-2021-47866
7.8

WIN-PACK PRO 4.8 contains an unquoted service path vulnerability in GuardTourService that allows local attackers to execute arbitrary code with SYSTEM...

Jan 21, 2026
CVE-2021-47867
7.8

CVE-2021-47867 is an unquoted service path vulnerability in WIN-PACK PRO 4.8's ScheduleService that allows local attackers to execute arbitrary code w...

Jan 21, 2026
CVE-2021-47861
7.8

Event Log Explorer 4.9.3 has an unquoted service path vulnerability that allows local attackers to execute arbitrary code with SYSTEM privileges. Atta...

Jan 21, 2026
CVE-2021-47862
7.8

CVE-2021-47862 is an unquoted service path vulnerability in Hi-Rez Studios' HiPatchService that allows local attackers to execute arbitrary code with ...

Jan 21, 2026
CVE-2021-47863
7.8

CVE-2021-47863 is an unquoted service path vulnerability in MacPaw Encrypto that allows local attackers to execute arbitrary code with elevated privil...

Jan 21, 2026
CVE-2021-47859
7.8

CVE-2021-47859 is an unquoted service path vulnerability in ActivIdentity 8.2's ac.sharedstore service that allows local attackers to execute arbitrar...

Jan 21, 2026
CVE-2021-47845
7.8

CVE-2021-47845 is an unquoted service path vulnerability in Spy Emergency 25.0.650 that allows local attackers to execute arbitrary code with SYSTEM p...

Jan 16, 2026
CVE-2021-47847
7.8

Disk Sorter Server 13.6.12 has an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated privileges. ...

Jan 16, 2026
CVE-2021-47829
7.8

This vulnerability allows local attackers to execute arbitrary code with SYSTEM privileges by exploiting an unquoted service path in DHCP Broadband. A...

Jan 16, 2026
CVE-2021-47833
7.8

CVE-2021-47833 is an unquoted service path vulnerability in WifiHotSpot 1.0.0.0 that allows local attackers to execute arbitrary code with LocalSystem...

Jan 16, 2026
CVE-2021-47823
7.8

CVE-2021-47823 is an unquoted service path vulnerability in Acer ePowerSvc that allows local attackers to execute arbitrary code with LocalSystem priv...

Jan 16, 2026

About CWE-428 (CWE-428)

Our database tracks 127 CVEs classified as CWE-428, with 2 rated critical and 107 rated high severity. The average CVSS score for CWE-428 vulnerabilities is 7.7.

External reference: View CWE-428 on MITRE CWE →

Monitor CWE-428 Vulnerabilities

Get alerted when new CWE-428 CVEs affect your infrastructure.

Start Monitoring Free