VulnSea

CWE-426

CVEs classified under CWE-426, newest first.

52 CVEsRSS

CVE-2026-12003High· 7.8
3mo ago

To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local

To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark i…

▾ TwilightRed Hat · Red Hat Hardened ImagesEPSS 0.15%via NVD
GHSA-9fr2-p65v-gqxqHigh· 7.1
3mo ago

Duplicate Advisory: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution

Duplicate Advisory: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution

▾ Twilightopenclaw · openclawvia GHSA
GHSA-qp5j-jr73-m2pwHigh· 7.1
3mo ago

Duplicate Advisory: Workspace .env npm_execpath could influence bundled runtime dependency install

Duplicate Advisory: Workspace .env npm_execpath could influence bundled runtime dependency install

▾ Twilightopenclaw · openclawvia GHSA
GHSA-4qgr-57jq-93vhHigh· 7.1
3mo ago

Duplicate Advisory: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots

Duplicate Advisory: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots

▾ Twilightopenclaw · openclawvia GHSA
GHSA-2w22-3f6x-3hf4High· 7.1
3mo ago

Duplicate Advisory: Workspace-derived service PATH could influence trash command selection

Duplicate Advisory: Workspace-derived service PATH could influence trash command selection

▾ Twilightopenclaw · openclawvia GHSA
GHSA-gv7w-rqvm-qjhrHigh· 8.1
3mo ago

Withdrawn Advisory: esbuild: Missing binary integrity verification in Deno module enables remote code execution via NPM_CONFIG_REGISTRY

Withdrawn Advisory: esbuild: Missing binary integrity verification in Deno module enables remote code execution via NPM_CONFIG_REGISTRY

▾ Twilightesbuild · esbuildvia GHSA
CVE-2026-11401High· 8.0
3mo ago

AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance

AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance

▾ Twilightaws · github.com/aws/aws-advanced-go-wrapper/awssql/v2EPSS 0.30%via GHSA
CVE-2026-47648High· 7.0
3mo ago

Windows Storage Elevation of Privilege Vulnerability

Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.28%via CVEORG
CVE-2026-48565High· 7.8
3mo ago

Windows Narrator Braille Elevation of Privilege Vulnerability

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows Narrator BrailleEPSS 0.36%via CVEORG
CVE-2026-27290High· 8.6
5mo ago

Adobe Framemaker versions 2022.8 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user

Adobe Framemaker versions 2022.8 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the application uses a search path to locate …

▾ Twilightadobe · framemakerEPSS 0.29%via NVD
CVE-2026-39883High· 7.0
5mo ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PAT…

▾ Twilightopentelemetry · opentelemetryEPSS 0.21%via NVD
CVE-2022-4987High· 7.3
5mo ago

Hirschmann Industrial HiVision version 08.1.03 prior to 08.1.04 and 08.2.00 contains a vulnerability in the execution of user-configured external applications that allows a local attacker to execute arbitrary binaries

Hirschmann Industrial HiVision version 08.1.03 prior to 08.1.04 and 08.2.00 contains a vulnerability in the execution of user-configured external applications that allows a local attacker to execute arbitrary binaries. Due to insufficien…

▾ TwilightEPSS 0.12%via NVD
CVE-2026-21333High· 8.6
6mo ago

Illustrator versions 29.8.4, 30.1 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user

Illustrator versions 29.8.4, 30.1 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. Exploitation of this issue requires user intera…

▾ Twilightadobe · illustratorEPSS 0.16%via NVD
CVE-2026-2998High· 7.8
7mo ago

ERP developed by eAI Technologies has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a crafted DLL file in the same directory as the program, thereby executing arbitrary code.

ERP developed by eAI Technologies has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a crafted DLL file in the same directory as the program, thereby executing arbitrary code.

▾ TwilightEPSS 0.17%via NVD
CVE-2026-21280High· 8.6
8mo ago

Illustrator versions 29.8.3, 30.0 and earlier are affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user

Illustrator versions 29.8.3, 30.0 and earlier are affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. If the application uses a search path to locate critic…

▾ Twilightadobe · illustratorEPSS 0.25%via NVD
CVE-2025-64785High· 7.8
9mo ago

Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the cu…

Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the cu…

▾ Twilightadobe · acrobatEPSS 0.48%via NVD
CVE-2024-21923High· 7.3
10mo ago

Incorrect default permissions in AMD StoreMI™ could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

Incorrect default permissions in AMD StoreMI™ could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

▾ TwilightEPSS 0.14%via NVD
CVE-2024-21922High· 7.3
10mo ago

A DLL hijacking vulnerability in AMD StoreMI™ could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

A DLL hijacking vulnerability in AMD StoreMI™ could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

▾ TwilightEPSS 0.14%via NVD
CVE-2024-53866Critical· 9.8
1y ago

The package manager pnpm prior to version 9.15.0 seems to mishandle overrides and global cache: Overrides from one workspace leak into npm metadata saved in global cache; npm metadata from global cache affects other workspaces; and insta…

The package manager pnpm prior to version 9.15.0 seems to mishandle overrides and global cache: Overrides from one workspace leak into npm metadata saved in global cache; npm metadata from global cache affects other workspaces; and insta…

▾ MidnightEPSS 0.98%via NVD
CVE-2024-35260High· 8.0
2y ago

An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.

An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.

▾ Twilightmicrosoft · power_platformEPSS 0.83%via NVD
CVE-2023-4736High· 7.8
3y ago

Untrusted Search Path in GitHub repository vim/vim prior to 9.0.1833.

Untrusted Search Path in GitHub repository vim/vim prior to 9.0.1833.

▾ Twilightvim · vimEPSS 0.51%via NVD
CVE-2021-36666High· 7.8
4y ago

An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privileges via the inSyncDecommission.

An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privileges via the inSyncDecommission.

▾ Twilightdruva · insync_clientEPSS 0.46%via NVD
CWE-426 vulnerabilities (CVEs) — page 2 · VulnSea