Vulnerabilities (CVE)

Filtered by CWE-428
Total 440 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-27965 2 Microsoft, Netsarang 2 Windows, Xlpd 2026-06-17 6.9 MEDIUM 6.5 MEDIUM
Xlpd v7.0.0094 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.
CVE-2022-27964 2 Microsoft, Netsarang 2 Windows, Xmanager 2026-06-17 6.9 MEDIUM 6.5 MEDIUM
Xmanager v7.0.0096 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.
CVE-2022-27963 2 Microsoft, Netsarang 2 Windows, Xftp 2026-06-17 6.9 MEDIUM 6.5 MEDIUM
Xftp 7.0.0088p and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.
CVE-2022-27905 1 Controlup 1 Controlup 2026-06-17 9.0 HIGH 7.2 HIGH
In ControlUp Real-Time Agent before 8.6, an unquoted path can result in privilege escalation. An attacker would require write permissions to the root level of the OS drive (C:\) to exploit this.
CVE-2022-27592 1 Qnap 1 Qvr Smart Client 2026-06-17 N/A 6.7 MEDIUM
An unquoted search path or element vulnerability has been reported to affect QVR Smart Client. If exploited, the vulnerability could allow local authenticated administrators to execute unauthorized code or commands via unspecified vectors. We have already fixed the vulnerability in the following version: Windows 10 SP1, Windows 11, Mac OS, and Mac M1: QVR Smart Client 2.4.0.0570 and later
CVE-2022-27095 1 Battleye 1 Battleye 2026-06-17 7.2 HIGH 7.8 HIGH
BattlEye v0.9 contains an unquoted service path which allows attackers to escalate privileges to the system level.
CVE-2022-27094 1 Sony 1 Playmemories Home 2026-06-17 7.2 HIGH 6.7 MEDIUM
Sony PlayMemories Home v6.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.
CVE-2022-27089 1 Fujitsu 1 Plugfree Network 2026-06-17 7.2 HIGH 7.8 HIGH
In Fujitsu PlugFree Network <= 7.3.0.3, an Unquoted service path in PFNService.exe software allows a local attacker to potentially escalate privileges to system level.
CVE-2022-27088 1 Ivanti 1 Dsm Remote 2026-06-17 4.6 MEDIUM 7.8 HIGH
Ivanti DSM Remote <= 6.3.1.1862 is vulnerable to an unquoted service path allowing local users to launch processes with elevated privileges.
CVE-2022-27052 1 Freesshd 1 Freeftpd 2026-06-17 7.2 HIGH 7.8 HIGH
FreeFtpd version 1.0.13 and below contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.
CVE-2022-27050 2 Bitcomet, Microsoft 2 Bitcomet, Windows 2026-06-17 7.2 HIGH 7.8 HIGH
BitComet Service for Windows before version 1.8.6 contains an unquoted service path vulnerability which allows attackers to escalate privileges to the system level.
CVE-2022-26634 1 Hma 1 Hidemyass 2026-06-17 7.2 HIGH 7.8 HIGH
HMA VPN v5.3.5913.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.
CVE-2022-25031 1 Rdpsoft 1 Remote Desktop Commander Suite Agent 2026-06-17 6.9 MEDIUM 7.8 HIGH
Remote Desktop Commander Suite Agent before v4.8 contains an unquoted service path which allows attackers to escalate privileges to the system level.
CVE-2022-23909 2 Gimmal, Microsoft 2 Sherpa Connector Service, Windows 2026-06-17 7.2 HIGH 7.8 HIGH
There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might allow a local user to escalate privileges by creating a "C:\Program Files\Sherpa Software\Sherpa.exe" file.
CVE-2022-1697 1 Okta 1 Active Directory Agent 2026-06-17 N/A 3.9 LOW
Okta Active Directory Agent versions 3.8.0 through 3.11.0 installed the Okta AD Agent Update Service using an unquoted path. Note: To remediate this vulnerability, you must uninstall Okta Active Directory Agent and reinstall Okta Active Directory Agent 3.12.0 or greater per the documentation.
CVE-2022-0883 2 Microsoft, Snowsoftware 2 Windows, Snow License Manager 2026-06-17 4.6 MEDIUM 7.3 HIGH
SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue. All installations version 9.x.x prior to 9.20.1 should be patched.
CVE-2022-0357 1 Bitdefender 3 Antivirus Plus, Internet Security, Total Security 2026-06-17 N/A 6.7 MEDIUM
Unquoted Search Path or Element vulnerability in the Vulnerability Scan component of Bitdefender Total Security, Bitdefender Internet Security, and Bitdefender Antivirus Plus allows an attacker to elevate privileges to SYSTEM. This issue affects: Bitdefender Total Security versions prior to 26.0.10.45. Bitdefender Internet Security versions prior to 26.0.10.45. Bitdefender Antivirus Plus versions prior to 26.0.10.45.
CVE-2022-0237 1 Rapid7 1 Insight Agent 2026-06-17 7.2 HIGH 4.0 MEDIUM
Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker can hijack the flow of execution due to an unquoted argument to the runas.exe command used by the ir_agent.exe component, resulting in elevated rights and persistent access to the machine. This issue was fixed in Rapid7 Insight Agent version 3.1.3.80.
CVE-2021-47974 2026-06-17 N/A 7.8 HIGH
VX Search 13.5.28 contains an unquoted service path vulnerability in both VX Search Server and VX Search Enterprise services that allows local attackers to escalate privileges. Attackers can place malicious executables in unquoted path directories like C:\Program Files\VX Search to execute arbitrary code with LocalSystem privileges when services restart.
CVE-2021-47945 2026-06-17 N/A 7.8 HIGH
Argus Surveillance DVR 4.0 contains an unquoted service path vulnerability in the DVRWatchdog service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the Program Files directory to be executed with LocalSystem privileges when the service starts.