Skip to main content

CWE archive

CWE-428 CVEs

Programmatic archive

451 CVEs tagged with CWE-4287 Critical, 361 High, 80 Medium, 3 Low, 0 Unrated.

CVE-2026-9128

Published Jul 14, 2026

A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the…

CVSS 7.3 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-8864

Published Jun 30, 2026

The HP Fan Control App might allow local escalation of privileges. An updated version of HP Fan Control App has been released to mitigate this potential vulnerabili…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-71326

Published Jun 19, 2026

AVAST Antivirus 25.11 contains an unquoted service path vulnerability in the SecureLine service that allows local non-privileged users to execute code with elevated SYSTEM privile…

CVSS 8.5 · High

CVE-2023-54353

Published Jun 19, 2026

Chromacam 4.0.3.0 contains an unquoted service path vulnerability in the PsyFrameGrabberService that allows local attackers to execute arbitrary code by placing malicious executab…

CVSS 8.5 · High

CVE-2022-50971

Published Jun 19, 2026

Malwarebytes 4.5 contains an unquoted service path vulnerability in the MBAMService executable that allows local attackers to escalate privileges by injecting malicious code into…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-47985

Published Jun 19, 2026

Brother SAPSprint 7.60 contains an unquoted service path vulnerability in the SAPSprint service binary that allows local attackers to escalate privileges. Attackers can place a ma…

CVSS 8.5 · High

CVE-2020-37254

Published Jun 19, 2026

Wondershare PDFelement 5.2.9 contains a privilege escalation vulnerability due to an unquoted service path in the WsAppService Windows service. Local attackers can place a malicio…

CVSS 8.5 · High

CVE-2020-37253

Published Jun 19, 2026

Winstep 18.06.0096 contains an unquoted service path vulnerability in the Winstep Xtreme Service that allows local attackers to escalate privileges. Attackers can place malicious…

CVSS 8.5 · High

CVE-2020-37252

Published Jun 19, 2026

Realtek Audio Service 1.0.0.55 contains an unquoted service path vulnerability in RtkAudioService64.exe that allows local attackers to escalate privileges by injecting malicious c…

CVSS 8.5 · High

CVE-2020-37251

Published Jun 19, 2026

RealTimes Desktop Service 18.1.4 contains an unquoted service path vulnerability in the rpdsvc.exe binary that allows local attackers to escalate privileges. Attackers can place m…

CVSS 8.5 · High

CVE-2020-37250

Published Jun 19, 2026

TFTP Broadband 4.3.0.1465 contains an unquoted service path vulnerability in the tftpt.exe service binary that allows local attackers to execute arbitrary code with system privile…

CVSS 8.5 · High

CVE-2019-25747

Published Jun 19, 2026

Network Inventory Advisor 5.0.26.0 installs the niaservice service with an unquoted binary path that allows local attackers to escalate privileges by placing malicious executables…

CVSS 8.5 · High

CVE-2016-20095

Published Jun 19, 2026

Matrix42 Remote Control Host 3.20.0031 contains an unquoted service path vulnerability in the FastViewerRemoteService and FastViewerRemoteProxy services that allows local users to…

CVSS 8.5 · High

CVE-2016-20094

Published Jun 19, 2026

AnyDesk 2.5.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the service installation. Atta…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-20093

Published Jun 19, 2026

Wise Care 365 4.27 and Wise Disk Cleaner 9.29 contain unquoted service path vulnerabilities in the WiseBootAssistant and SpyHunter 4 Service respectively, allowing local users to…

CVSS 8.5 · High

CVE-2016-20092

Published Jun 19, 2026

NetDrive 2.6.12 contains an unquoted service path vulnerability in the Netdrive2_Service_Netdrive2 service that allows local users to execute arbitrary code with SYSTEM privileges…

CVSS 8.5 · High

CVE-2016-20091

Published Jun 19, 2026

Windows Firewall Control 4.8.6.0 contains an unquoted service path vulnerability that allows local attackers to escalate privileges by inserting malicious executables in the servi…

CVSS 8.5 · High

CVE-2016-20090

Published Jun 19, 2026

Comodo Dragon Browser versions up to 52.15.25.663 contain a privilege escalation vulnerability in the DragonUpdater service due to an unquoted service path running with SYSTEM pri…

CVSS 8.5 · High

CVE-2016-20089

Published Jun 19, 2026

Iperius Remote 1.7.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the service installatio…

CVSS 8.5 · High

CVE-2016-20088

Published Jun 19, 2026

Comodo Chromodo Browser 52.15.25.664 contains an unquoted service path vulnerability in the ChromodoUpdater service that runs with SYSTEM privileges. A local attacker can insert a…

CVSS 8.5 · High

CVE-2016-20087

Published Jun 19, 2026

Fortitude HTTP 1.0.4.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated privileges by exploiting the service binary…

CVSS 8.5 · High

CVE-2016-20086

Published Jun 19, 2026

Vembu StoreGrid 4.0 contains an unquoted service path vulnerability in the RemoteBackup and RemoteBackup_webServer services that allows local attackers to escalate privileges. Att…

CVSS 8.5 · High

CVE-2016-20085

Published Jun 19, 2026

Realtek High Definition Audio Driver 6.0.1.6730 contains an unquoted service path vulnerability that allows local attackers to escalate privileges by placing a malicious executabl…

CVSS 8.5 · High

CVE-2026-25865

Published Jun 18, 2026

Punto Switcher through 4.5.0.583 contains an unquoted search path element vulnerability that allows local attackers to execute arbitrary code by exploiting the application's call…

CVSS 8.5 · High
evidence mentions
3
Buzz score
25.4

CVE-2021-47974

Published May 16, 2026

VX Search 13.5.28 contains an unquoted service path vulnerability in both VX Search Server and VX Search Enterprise services that allows local attackers to escalate privileges. At…

CVSS 8.5 · High
Showing 1-25 of 451 CVEsPage 1 of 19