Skip to main content

CWE archive

CWE-426 CVEs

Programmatic archive

655 CVEs tagged with CWE-42624 Critical, 536 High, 81 Medium, 13 Low, 1 Unrated.

CVE-2025-12819

Published Dec 3, 2025

Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to execute arbitrary SQL during authentication via a malicious…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-49642

Published Dec 1, 2025

Library loading on AIX Zabbix Agent builds can be hijacked by local users with write access to the /home/cecuser directory.

CVSS 5.9 · Medium

CVE-2024-21923

Published Nov 23, 2025

Incorrect default permissions in AMD StoreMI™ could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

CVSS 7.3 · High

CVE-2024-21922

Published Nov 23, 2025

A DLL hijacking vulnerability in AMD StoreMI™ could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

CVSS 7.3 · High

CVE-2025-13433

Published Nov 20, 2025

A security flaw has been discovered in Muse Group MuseHub 2.1.0.1567. The affected element is an unknown function of the file C:\Program Files\WindowsApps\Muse.MuseHub_2.1.0.1567_…

CVSS 7.3 · High

CVE-2025-43079

Published Nov 10, 2025

The Qualys Cloud Agent included a bundled uninstall script (qagent_uninstall.sh), specific to Mac and Linux supported versions that invoked multiple system commands without using…

CVSS 6.3 · Medium

CVE-2024-14012

Published Oct 29, 2025

Potential privilege escalation issue in Revenera InstallShield version 2023 R1 running a renamed Setup.exe on Windows. When a local administrator executes a renamed Setup.exe, the…

CVSS 7.3 · High

CVE-2025-12286

Published Oct 27, 2025

A weakness has been identified in VeePN up to 1.6.2. This affects an unknown function of the file C:\Program Files (x86)\VeePN\avservice\avservice.exe of the component AVService.…

CVSS 7.3 · High

CVE-2025-12247

Published Oct 27, 2025

A weakness has been identified in Hasleo Backup Suite up to 5.2. Impacted is an unknown function of the component HasleoImageMountService/HasleoBackupSuiteService. This manipulati…

CVSS 6.4 · Medium

CVE-2025-11940

Published Oct 19, 2025

A security vulnerability has been detected in LibreWolf up to 143.0.4-1 on Windows. This affects an unknown function of the file assets/setup.nsi of the component Installer. Such…

CVSS 7.3 · High

CVE-2025-9267

Published Sep 26, 2025

In Seagate Toolkit on Windows a vulnerability exists in the Toolkit Installer prior to versions 2.35.0.6 where it attempts to load DLLs from the current working directory without…

CVSS 7.0 · High

CVE-2025-9016

Published Aug 15, 2025

A vulnerability was identified in Mechrevo Control Center GX V2 5.56.51.48. This affects an unknown part of the file C:\Program Files\OEM\机械革命控制中心\AiStoneService\MyControlCenter\C…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-9000

Published Aug 15, 2025

A vulnerability was found in Mechrevo Control Center GX V2 5.56.51.48. Affected by this vulnerability is an unknown functionality of the component reg File Handler. The manipulati…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-23266

Published Jul 17, 2025

NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated pe…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2025-0141

Published Jul 9, 2025

An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on enables a locally authenticated non administrative user to escalate their privilege…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-49124

Published Jun 16, 2025

Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path.…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-5335

Published Jun 10, 2025

A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to an untrusted search path being utilized in the Autodesk Inst…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 76-100 of 655 CVEsPage 4 of 27