Skip to main content

CWE archive

CWE-428 CVEs

Programmatic archive

451 CVEs tagged with CWE-4287 Critical, 361 High, 80 Medium, 3 Low, 0 Unrated.

CVE-2020-27645

Published Dec 29, 2020

The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.Metrics.exe. This may allow remote auth…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27644

Published Dec 29, 2020

The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.Metrics.exe. This may allow remote auth…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7331

Published Nov 12, 2020

Unquoted service executable path in McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows local users to cause a denial of service and malicious file executio…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15261

Published Oct 19, 2020

On Windows the Veyon Service before version 4.4.2 contains an unquoted service path vulnerability, allowing locally authenticated users with administrative privileges to run malic…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7316

Published Oct 7, 2020

Unquoted service path vulnerability in McAfee File and Removable Media Protection (FRP) prior to 5.3.0 allows local users to execute arbitrary code, with higher privileges, via ex…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10051

Published Sep 9, 2020

A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). Multiple services of the affected application are executed with SYSTEM privileges wh…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7382

Published Sep 3, 2020

Rapid7 Nexpose installer version prior to 6.6.40 contains an Unquoted Search Path which may allow an attacker on the local machine to insert an arbitrary file into the executable…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8326

Published Jul 24, 2020

An unquoted service path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevate…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7581

Published Jul 14, 2020

A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All vers…

CVSS 6.7 · Medium

CVE-2020-9292

Published Jun 4, 2020

An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated privileges via the AoWinAgt executable service path.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-7275

Published Apr 15, 2020

Accessing, modifying or executing executable files vulnerability in the uninstaller in McAfee Endpoint Security (ENS) for Windows Prior to 10.7.0 April 2020 Update allows local us…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8327

Published Apr 14, 2020

A privilege escalation vulnerability was reported in LenovoBatteryGaugePackage for Lenovo System Interface Foundation bundled in Lenovo Vantage prior to version 10.2003.10.0 that…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1988

Published Apr 8, 2020

An unquoted search path vulnerability in the Windows release of Global Protect Agent allows an authenticated local user with file creation privileges on the root of the OS disk (C…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-17658

Published Mar 12, 2020

An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an attacker to gain elevated privileges via the FortiCli…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-0507

Published Mar 12, 2020

Unquoted service path in Intel(R) Graphics Drivers before versions 15.33.49.5100, 15.36.38.5117, 15.40.44.5107, 15.45.30.5103, and 26.20.100.7212 may allow an authenticated user t…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-18915

Published Feb 13, 2020

A potential security vulnerability has been identified with certain versions of HP System Event Utility prior to version 1.4.33. This vulnerability may allow a local attacker to e…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-20357

Published Jan 18, 2020

A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an atta…

CVSS 7.8 · High
Showing 376-400 of 451 CVEsPage 16 of 19