CWE-428

CWE-428 · 4 records · 0 with a public proof-of-concept

Records the NVD classes under CWE-428, highest CVSS first.

  1. HIGH 7.8CVE-2026-81469

    Dell Inventory Collector Client, versions prior to 15.0.0, contain an Unquoted Search Path or Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of Privileges

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.5CVE-2026-15358

    ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 were vulnerable to an unauthorized Path Traversal vulnerability.

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.3CVE-2026-18755

    A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search directory to execute arbitrary code. By placing a crafted dynamic-link library (DLL) file into the application search path prior to the legiti…

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 6.7CVE-2026-66839

    NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerability (CWE-428). An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges.

    AI risk analysis on Exploit-DB.ai →