CWE-428: Unquoted Search Path or Element
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.
336 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-8070 — Windows service registered with an unquoted ImagePath vulnerability in the system registry
- CVE-2025-12507 — Insecure service configuration – unquoted path
- CVE-2026-25866 — MobaXterm < 26.1 Notepad++ Unquoted Service Path
- CVE-2025-66575 — VeeVPN 1.6.1 - Unquoted Service Path Remote Code Execution
- CVE-2025-57714 — NetBak Replicator
- CVE-2025-41359 — Multiple vulnerabilities in Small HTTP server by Smallsrv
- CVE-2024-9325 — Intelbras InControl incontrol-service-watchdog.exe unquoted search path
- CVE-2017-20218 — Serviio PRO 1.8 Local Privilege Escalation via Unquoted Path
- CVE-2026-33253 — SANUPS SOFTWARE provided by SANYO DENKI CO., LTD. registers Windows services with unquoted file paths. A user with the w
- CVE-2026-26033 — UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Unquoted Search Path or Element (CWE-428) v
- CVE-2026-24466 — Products provided by Oki Electric Industry Co., Ltd. and its OEM products (Ricoh Co., Ltd., Murata Machinery, Ltd.) regi
- CVE-2025-66461 — FULLBACK Manager Pro provided by GS Yuasa International Ltd. registers two Windows services with unquoted file paths. A
- CVE-2025-66271 — Clone for Windows provided by ELECOM CO.,LTD. registers a Windows service with an unquoted file path. A user with the wr
- CVE-2025-64151 — Multiple Roboticsware products provided by Roboticsware PTE. LTD. register Windows services with unquoted file paths. A
- CVE-2025-62225 — Optical Disc Archive Software provided by Sony Corporation registers a Windows service with an unquoted file path. A use
- CVE-2025-61871 — NAS Navigator2 Windows version by BUFFALO INC. registers a Windows service with an unquoted file path. A user with the w
- CVE-2025-61865 — Multiple NAS management applications provided by I-O DATA DEVICE, INC. register Windows services with unquoted file path
- CVE-2025-59307 — RAID Manager provided by Century Corporation registers a Windows service with an unquoted file path. A user with the wri
- CVE-2025-58400 — RATOC RAID Monitoring Manager for Windows provided by RATOC Systems, Inc. registers a Windows service with an unquoted f
- CVE-2025-57699 — Western Digital Kitfox for Windows provided by Western Digital Corporation registers a Windows service with an unquoted
Recently published
- CVE-2026-77827 — Maono Link local privilege escalation
- CVE-2026-66839 — NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerabil
- CVE-2026-18755 — GV-ASManager DLL hijacking vulnerability
- CVE-2026-9128 — Studio 5000 Logix Designer® – Multiple Vulnerabilities
- CVE-2026-8864 — HP Fan Control App – Potential Escalation of Privilege
- CVE-2025-71326 — AVAST Antivirus 25.11 Unquoted Service Path Privilege Escalation
- CVE-2023-54353 — Chromacam 4.0.3.0 Unquoted Service Path Privilege Escalation
- CVE-2022-50971 — Malwarebytes 4.5 Unquoted Service Path Privilege Escalation
- CVE-2021-47985 — Brother SAPSprint 7.60 Unquoted Service Path Privilege Escalation
- CVE-2020-37254 — Wondershare PDFelement 5.2.9 Privilege Escalation via Unquoted Service Path
- CVE-2020-37253 — Winstep 18.06.0096 Unquoted Service Path Privilege Escalation
- CVE-2020-37252 — Realtek Audio Service 1.0.0.55 Unquoted Service Path Privilege Escalation
- CVE-2020-37251 — RealTimes Desktop Service 18.1.4 Unquoted Service Path Privilege Escalation
- CVE-2020-37250 — TFTP Broadband 4.3.0.1465 Unquoted Service Path Privilege Escalation
- CVE-2019-25747 — Network Inventory Advisor 5.0.26.0 Unquoted Service Path Privilege Escalation
- CVE-2016-20095 — Matrix42 Remote Control Host 3.20.0031 Unquoted Path Privilege Escalation
- CVE-2016-20094 — AnyDesk 2.5.0 Unquoted Service Path Elevation of Privilege
- CVE-2016-20093 — Wise Care 365 4.27 and Wise Disk Cleaner 9.29 Unquoted Service Path Privilege Escalation
- CVE-2016-20092 — NetDrive 2.6.12 Unquoted Service Path Elevation of Privilege
- CVE-2016-20091 — Windows Firewall Control 4.8.6.0 Unquoted Service Path Privilege Escalation