CWE-428: CWE-428

127
Total CVEs
2
Critical
107
High
7.7
Avg CVSS

Yearly Trend

2026
61
2025
26
2024
12
2023
8
2022
13

Top Affected Vendors

1 Sap 2
2 Akamai 1
3 Anytxt 1
4 Zscaler 1
5 Veepn 1
6 Rumble Mail Server Project 1
7 Proton 1
8 Windscribe 1
9 Vembu 1
10 Python 1

All CWE-428 CVEs (127)

CVE-2021-47825
7.8

CVE-2021-47825 is an unquoted service path vulnerability in Acer Updater Service that allows local attackers to execute arbitrary code with LocalSyste...

Jan 16, 2026
CVE-2021-47826
7.8

CVE-2021-47826 is an unquoted service path vulnerability in Acer Backup Manager's NTI IScheduleSvc service that allows local attackers to execute arbi...

Jan 16, 2026
CVE-2021-47828
7.8

CVE-2021-47828 is an unquoted service path vulnerability in BOOTP Turbo 2.0.0.1253 that allows attackers to execute arbitrary code with LocalSystem pr...

Jan 16, 2026
CVE-2021-47822
7.8

DiskBoss Service 12.2.18 has an unquoted service path vulnerability that allows local attackers to execute arbitrary code with SYSTEM privileges. Atta...

Jan 16, 2026
CVE-2021-47787
7.8

CVE-2021-47787 is an unquoted service path vulnerability in TotalAV antivirus software that allows attackers with local access to place malicious exec...

Jan 16, 2026
CVE-2021-47773
7.8

CVE-2021-47773 is an unquoted service path vulnerability in Dynojet Power Core 2.3.0 that allows local authenticated users to execute arbitrary code w...

Jan 15, 2026
CVE-2021-47767
7.8

This vulnerability allows local attackers to escalate privileges to SYSTEM level by exploiting an unquoted service path in 10-Strike Network Inventory...

Jan 15, 2026
CVE-2021-47762
7.8

HTTPDebuggerPro 9.11 has an unquoted service path vulnerability that allows local attackers to execute arbitrary code with SYSTEM privileges by placin...

Jan 15, 2026
CVE-2023-54331
7.8

CVE-2023-54331 is an unquoted service path vulnerability in Outline 1.6.0 that allows local attackers to execute arbitrary code with LocalSystem privi...

Jan 13, 2026
CVE-2022-50933
7.8

CVE-2022-50933 is an unquoted service path vulnerability in Cain & Abel 4.9.56 that allows local attackers to execute arbitrary code with elevated Loc...

Jan 13, 2026
CVE-2022-50928
7.8

BlueSoleilCS 5.4.277 has an unquoted service path vulnerability in its Windows service configuration. This allows local attackers with write access to...

Jan 13, 2026
CVE-2022-50923
7.8

CVE-2022-50923 is an unquoted service path vulnerability in Cobian Backup 0.9 that allows local attackers to execute arbitrary code with LocalSystem p...

Jan 13, 2026
CVE-2022-50917
7.8

CVE-2022-50917 is an unquoted service path vulnerability in ProtonVPN's WireGuard service that allows local attackers to execute arbitrary code with e...

Jan 13, 2026
CVE-2022-50921
7.8

CVE-2022-50921 is an unquoted service path vulnerability in WOW21 5.0.1.9 that allows local attackers to execute arbitrary code with SYSTEM privileges...

Jan 13, 2026
CVE-2022-50915
7.8

CVE-2022-50915 is an unquoted service path vulnerability in PTPublisher's PTProtect service that allows local attackers to execute arbitrary code with...

Jan 13, 2026
CVE-2024-58315
7.8

Tosibox Key Service 3.3.0 has an unquoted service path vulnerability that allows local non-privileged users to execute arbitrary code with SYSTEM priv...

Dec 30, 2025
CVE-2025-66575
7.8

CVE-2025-66575 is an unquoted service path vulnerability in VeeVPN 1.6.1 that allows attackers to execute arbitrary code with LocalSystem privileges d...

Dec 4, 2025
CVE-2025-57227
7.8

This vulnerability allows attackers to escalate privileges by exploiting an unquoted service path in Kingosoft Technology Ltd Kingo ROOT software. Att...

Oct 29, 2025
CVE-2025-57714
7.8

An unquoted search path vulnerability in NetBak Replicator allows local attackers with user accounts to execute arbitrary code by placing malicious ex...

Oct 3, 2025
CVE-2025-21107
7.8

This CVE describes an unquoted search path vulnerability in Dell NetWorker that allows local attackers with low privileges to execute arbitrary code. ...

Jan 30, 2025
CVE-2024-9287
7.8

This vulnerability in CPython's venv module allows command injection when creating virtual environments with attacker-controlled path names. Attackers...

Oct 22, 2024
CVE-2024-2747
7.8

CVE-2024-2747 is an unquoted search path vulnerability in Schneider Electric's Easergy Studio software that allows local authenticated users to escala...

Jun 12, 2024
CVE-2024-4461
7.8

This vulnerability allows a local attacker to escalate privileges on Windows systems running vulnerable SugarSync versions. By exploiting an unquoted ...

May 3, 2024
CVE-2024-1618
7.8

This CVE describes an unquoted search path vulnerability in Faronics Deep Freeze Server Standard that allows local attackers to hijack the DFServ.exe ...

Mar 12, 2024
CVE-2024-1201
7.8

This vulnerability in HDD Health allows local attackers to escalate privileges by placing malicious executables in unquoted search paths. It affects u...

Feb 2, 2024
CVE-2023-6631
7.8

This vulnerability in PowerSYSTEM Center allows a local user with existing system access to escalate privileges by inserting malicious code into an un...

Jan 8, 2024
CVE-2023-37537
7.8

This vulnerability allows a local attacker to gain elevated privileges on Windows systems running HCL AppScan Presence service. Attackers can exploit ...

Oct 17, 2023
CVE-2023-4991
7.8

CVE-2023-4991 is an unquoted search path vulnerability in NextBX QWAlerter 4.50 that allows local attackers to execute arbitrary code by placing malic...

Sep 15, 2023
CVE-2023-36658
7.8

CVE-2023-36658 is an unquoted service path vulnerability in OPSWAT MetaDefender KIOSK 4.6.1.9996 that allows local attackers to escalate privileges by...

Sep 15, 2023
CVE-2023-3842
7.8

This vulnerability in Pointware EasyInventory 1.0.12.0 involves an unquoted search path in the Easy2W.exe executable, allowing local attackers to exec...

Jul 23, 2023
CVE-2023-31747
7.8

Wondershare Filmora 12 contains an unquoted service path vulnerability in the NativePushService component. This allows attackers with local access to ...

May 23, 2023
CVE-2023-2331
7.8

This vulnerability allows attackers to execute arbitrary code with SYSTEM privileges on Windows systems running vulnerable versions of 42Gears Sureloc...

Apr 27, 2023
CVE-2023-24671
7.8

CVE-2023-24671 is an unquoted service path vulnerability in VX Search that allows attackers with local access to escalate privileges by placing a mali...

Mar 16, 2023
CVE-2022-35899
7.8

This CVE describes an unquoted service path vulnerability in ASUS Aura Ready Game SDK service (GameSDK.exe) version 1.0.0.4. It allows local attackers...

Jul 21, 2022
CVE-2022-31591
7.8

CVE-2022-31591 is an unquoted service path vulnerability in SAP BusinessObjects BW Publisher Service that allows local attackers to execute arbitrary ...

Jul 12, 2022
CVE-2022-29320
7.8

MiniTool Partition Wizard v12.0 has an unquoted service path vulnerability that allows attackers with local access to escalate privileges to SYSTEM le...

May 20, 2022
CVE-2022-27095
7.8

BattlEye anti-cheat software v0.9 contains an unquoted service path vulnerability that allows local attackers to escalate privileges to SYSTEM level b...

May 20, 2022
CVE-2022-27089
7.8

This vulnerability allows a local attacker to escalate privileges to SYSTEM level by exploiting an unquoted service path in Fujitsu PlugFree Network's...

Apr 11, 2022
CVE-2022-23909
7.8

This CVE describes an unquoted service path vulnerability in Sherpa Connector Service that allows local attackers to escalate privileges by placing a ...

Apr 5, 2022
CVE-2021-43460
7.8

This CVE describes an Unquoted Service Path vulnerability in System Explorer 7.0.0 that allows local attackers to escalate privileges by placing a mal...

Apr 4, 2022
CVE-2021-43463
7.8

This vulnerability allows local attackers to execute arbitrary code with SYSTEM privileges by placing a malicious executable in an unquoted service pa...

Apr 4, 2022
CVE-2021-43454
7.8

This CVE describes an Unquoted Service Path vulnerability in AnyTXT Searcher that allows local attackers to escalate privileges by placing a malicious...

Apr 4, 2022
CVE-2021-43456
7.8

CVE-2021-43456 is an unquoted service path vulnerability in Rumble Mail Server that allows local attackers to escalate privileges by placing a malicio...

Apr 4, 2022
CVE-2021-43458
7.8

CVE-2021-43458 is an unquoted service path vulnerability in Vembu BDR 4.2.0.1 that allows local attackers to escalate privileges by placing malicious ...

Apr 4, 2022
CVE-2022-27050
7.8

CVE-2022-27050 is an unquoted service path vulnerability in BitComet for Windows that allows local attackers to escalate privileges to SYSTEM level by...

Mar 31, 2022
CVE-2021-40683
7.8

This vulnerability in Akamai EAA Client involves an unquoted service path that could allow local attackers to escalate privileges by placing malicious...

Oct 4, 2021
CVE-2020-11632
7.8

This vulnerability in Zscaler Client Connector allows a local attacker to execute arbitrary code with SYSTEM privileges by exploiting an unquoted serv...

Jul 15, 2021
CVE-2021-35469
7.8

This vulnerability allows local attackers to escalate privileges on Windows systems running vulnerable Lexmark printer software. Attackers can exploit...

Jul 14, 2021
CVE-2020-22809
7.8

This vulnerability in Windscribe VPN client allows local attackers to escalate privileges by exploiting an unquoted service path in the WindscribeServ...

May 10, 2021
CVE-2021-31776
7.8

This vulnerability allows local privilege escalation to SYSTEM on Windows systems running vulnerable Aviatrix VPN Client versions. Attackers with loca...

Apr 29, 2021

About CWE-428 (CWE-428)

Our database tracks 127 CVEs classified as CWE-428, with 2 rated critical and 107 rated high severity. The average CVSS score for CWE-428 vulnerabilities is 7.7.

External reference: View CWE-428 on MITRE CWE →

Monitor CWE-428 Vulnerabilities

Get alerted when new CWE-428 CVEs affect your infrastructure.

Start Monitoring Free