CWE-428: CWE-428

127
Total CVEs
2
Critical
107
High
7.7
Avg CVSS

Yearly Trend

2026
61
2025
26
2024
12
2023
8
2022
13

Top Affected Vendors

1 Sap 2
2 Akamai 1
3 Anytxt 1
4 Zscaler 1
5 Veepn 1
6 Rumble Mail Server Project 1
7 Proton 1
8 Windscribe 1
9 Vembu 1
10 Python 1

All CWE-428 CVEs (127)

CVE-2021-27608
7.5

CVE-2021-27608 is an unquoted service path vulnerability in SAPSetup version 9.0 that allows local attackers to escalate privileges during installatio...

Apr 14, 2021
CVE-2025-14018
7.3

This CVE describes an unquoted search path vulnerability in NetBT Consulting Services Inc.'s E-Fatura software. Attackers can manipulate configuration...

Dec 22, 2025
CVE-2025-0035
7.3

This vulnerability allows a local attacker to escalate privileges by exploiting an unquoted search path in AMD Cloud Manageability Service. Attackers ...

May 13, 2025
CVE-2024-36321
7.3

This vulnerability in AMD's AIM-T Manageability Service allows local attackers to escalate privileges by exploiting an unquoted search path. Attackers...

May 13, 2025
CVE-2024-57276
7.3

This CVE describes an unquoted service path vulnerability in Electronic Arts Dragon Age Origins 1.05's DAUpdaterSVC service. Attackers with local acce...

Jan 27, 2025
CVE-2024-8975
7.3

This vulnerability allows local Windows users to escalate privileges to SYSTEM by exploiting an unquoted search path in Grafana Alloy. It affects Wind...

Sep 25, 2024
CVE-2024-22437
7.3

This vulnerability in HPE MSA storage products allows attackers to gain elevated system privileges through the VSS Provider and CAPI Proxy software. I...

Apr 15, 2024
CVE-2021-0112
7.3

This vulnerability allows an authenticated Windows user to escalate privileges by exploiting an unquoted service path in Intel Unite Client. Attackers...

Jun 9, 2021
CVE-2023-0887
7.0

This vulnerability in TFTPD64-SE 4.64 involves an unquoted search path issue in the tftpd64_svc.exe service. It allows local attackers to potentially ...

Feb 17, 2023
CVE-2026-26033
6.7

This vulnerability allows attackers with write access to a directory on the system drive to execute arbitrary code with SYSTEM privileges by exploitin...

Mar 5, 2026
CVE-2026-24466
6.7

This vulnerability allows local attackers to escalate privileges to SYSTEM on Windows systems by exploiting unquoted service paths in Oki Electric Ind...

Feb 9, 2026
CVE-2025-59888
6.7

This vulnerability allows attackers with file system access to execute arbitrary code through improper quotation in search paths in Eaton UPS Companio...

Dec 26, 2025
CVE-2025-66271
6.7

This vulnerability in ELECOM Clone for Windows allows local privilege escalation through an unquoted service path. Attackers with write access to the ...

Dec 9, 2025
CVE-2025-66461
6.7

CVE-2025-66461 is an unquoted service path vulnerability in GS Yuasa's FULLBACK Manager Pro software that allows local users with write permissions to...

Dec 8, 2025
CVE-2025-32449
6.7

This CVE describes an unquoted search path vulnerability in PRI Driver software that could allow local authenticated attackers to escalate privileges....

Nov 11, 2025
CVE-2025-62225
6.7

Sony Optical Disc Archive Software registers a Windows service with an unquoted file path, allowing local attackers with write permissions on the syst...

Nov 5, 2025
CVE-2025-64151
6.7

This vulnerability allows local attackers with write permissions on the system drive root directory to escalate privileges to SYSTEM level by exploiti...

Nov 5, 2025
CVE-2025-60320
6.7

This CVE describes an unquoted service path vulnerability in memoQ's Auto Update Service that allows local users to escalate privileges to SYSTEM leve...

Oct 29, 2025
CVE-2025-61865
6.7

This vulnerability allows local attackers with write permissions on the system drive root directory to escalate privileges to SYSTEM level by exploiti...

Oct 23, 2025
CVE-2025-61871
6.7

NAS Navigator2 Windows service has an unquoted file path vulnerability that allows local users with write permissions on the system drive root directo...

Oct 10, 2025
CVE-2024-31201
6.5

This vulnerability involves an unquoted search path in the ThermoscanIP_Scrutation service, allowing attackers to execute arbitrary code by placing ma...

Jul 31, 2024
CVE-2023-53912
6.2

CVE-2023-53912 is an unquoted service path vulnerability in USB Flash Drives Control 4.1.0.0 that allows local attackers to execute arbitrary code wit...

Dec 17, 2025
CVE-2024-31226
4.9

This vulnerability in Sunshine game streaming software allows path interception attacks when terminating the service on Windows. Attackers can place m...

May 16, 2024
CVE-2025-34499
N/A

This CVE describes an unquoted service path vulnerability in AnyDesk that allows local non-privileged users to escalate privileges to SYSTEM level. At...

Dec 11, 2025
CVE-2024-58288
N/A

CVE-2024-58288 is an unquoted service path vulnerability in Genexus Protection Server 9.7.2.10 that allows local attackers to escalate privileges to L...

Dec 11, 2025
CVE-2025-66269
N/A

This vulnerability allows local attackers with write permissions to directories preceding the UPSilon 2000 service executables to perform path interce...

Nov 26, 2025
CVE-2025-66264
N/A

This vulnerability allows local attackers with filesystem write access to escalate privileges to SYSTEM level by exploiting an unquoted service path i...

Nov 26, 2025

About CWE-428 (CWE-428)

Our database tracks 127 CVEs classified as CWE-428, with 2 rated critical and 107 rated high severity. The average CVSS score for CWE-428 vulnerabilities is 7.7.

External reference: View CWE-428 on MITRE CWE →

Monitor CWE-428 Vulnerabilities

Get alerted when new CWE-428 CVEs affect your infrastructure.

Start Monitoring Free