CWE-426
Untrusted Search Path
MITRENo catalog description on file. The MITRE CWE site has the canonical reference.
Recent CVEs
showing 9 of 9- CVE-2026-54055Medium· 5.0EPSS 0%18 h ago
Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalation vulnerability exists in kitty's file transmission protocol where a child process running in the terminal can write to arbitrary files on
- CVE-2026-53819High· 8.8EPSS 0%18 h ago
OpenClaw before 2026.5.27 contains an arbitrary code execution vulnerability in skill install flows where workspace .env files can override the Homebrew executable selection. Attackers with access to trusted operator workspaces can execute
- CVE-2022-22047High· 7.8KEVEPSS 1%21 h ago
Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability
- CVE-2012-1854High· 7.8KEVEPSS 3%21 h ago
Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability
- CVE-2026-11401—EPSS 0%1 d ago
AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance
go - CVE-2026-47648High· 7.0EPSS 0%2 d ago
Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.
- CVE-2026-24064High· 7.8EPSS 0%2 d ago
Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability. A trusted XPC client component included with the product is signed with hardened runtime entitlements that permit dynamic library inj
- CVE-2026-48565High· 7.8EPSS 0%4 d ago
ZDI-26-339: Microsoft Windows Narrator Braille Support brlapi Exposed Dangerous Function Local Privilege Escalation Vulnerability
- CVE-2026-11400High· 8.0EPSS 0%7 d ago
An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL will allow a remote authenticated low-privilege actor to escalate privileges to those of another Amazon RDS user, inclu
CWE catalog data sourced from MITRE. CVE associations come from NVD weakness mappings; some CVEs carry multiple CWEs.