CWE-428 未经引用的搜索路径或元素 类弱点 303 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-428 是未加引号搜索路径或元素漏洞,属于路径处理缺陷。当路径元素含空格且未加引号时,系统可能解析错误,导致访问父目录资源。攻击者可通过在父目录放置恶意文件(如 Program.exe)诱导特权程序执行,从而提升权限。开发者应避免使用含空格的路径,或对路径元素严格加引号,确保解析准确,防止路径遍历和权限提升风险。
UINT errCode = WinExec( "C:\\Program Files\\Foo\\Bar", SW_SHOW );| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2021-47974 | Flexense VX Search 代码问题漏洞 — VX Search | 7.8 | High | 2026-05-16 |
| CVE-2020-37247 | Kite 代码问题漏洞 — Kite | 7.8 | High | 2026-05-16 |
| CVE-2020-37232 | IObit Advanced SystemCare Service 代码问题漏洞 — Advanced System Care Service | 7.8 | High | 2026-05-16 |
| CVE-2020-37231 | Cybertron Privacy Drive 代码问题漏洞 — Privacy Drive | 7.8 | High | 2026-05-16 |
| CVE-2020-37230 | Syncplify Server 代码问题漏洞 — Syncplify.me Server! | 7.8 | High | 2026-05-16 |
| CVE-2020-37229 | OKI sPSV Port Manager 代码问题漏洞 — OKI sPSV Port Manager | 7.8 | High | 2026-05-16 |
| CVE-2020-37223 | IObit Uninstaller 代码问题漏洞 — IObit Uninstaller | 7.8 | High | 2026-05-13 |
| CVE-2021-47945 | Argus Surveillance Dvr 代码问题漏洞 — Argus Surveillance DVR | 7.8 | High | 2026-05-10 |
| CVE-2026-7280 | eMPIA AVACAST 代码问题漏洞 — AVACAST | 6.7 | Medium | 2026-04-28 |
| CVE-2026-5789 | CivetWeb 代码问题漏洞 — CivetWeb | 8.4AI | HighAI | 2026-04-21 |
| CVE-2016-20061 | sheed AntiVirus 代码问题漏洞 — sheed AntiVirus | 7.8 | High | 2026-04-04 |
| CVE-2016-20060 | Pango Hotspot Shield 代码问题漏洞 — Hotspot Shield | 7.8 | High | 2026-04-04 |
| CVE-2016-20059 | IOBit Malware Fighter 代码问题漏洞 — IObit Malware Fighter | 7.8 | High | 2026-04-04 |
| CVE-2016-20058 | NETGATE Amiti Antivirus 代码问题漏洞 — NETGATE AMITI Antivirus | 7.8 | High | 2026-04-04 |
| CVE-2016-20057 | NETGATE Registry Cleaner 代码问题漏洞 — NETGATE Registry Cleaner | 7.8 | High | 2026-04-04 |
| CVE-2016-20056 | NETGATE Spy Emergency 代码问题漏洞 — Spy Emergency | 7.8 | High | 2026-04-04 |
| CVE-2016-20055 | IOBit IObit Advanced SystemCare 代码问题漏洞 — IObit Advanced SystemCare | 7.8 | High | 2026-04-04 |
| CVE-2026-34768 | Electron 代码问题漏洞 — electron | 3.9 | Low | 2026-04-03 |
| CVE-2025-41359 | Small Http Server 代码问题漏洞 — Small HTTP | 7.8 | - | 2026-03-26 |
| CVE-2026-33253 | SANYO DENKI SANUPS SOFTWARE 代码问题漏洞 — SANUPS SOFTWARE STANDALONE | 7.8 | - | 2026-03-25 |
| CVE-2017-20218 | Serviio PRO 代码问题漏洞 — Serviio PRO | 7.8 | High | 2026-03-15 |
| CVE-2026-25866 | Mobatek MobaXterm 代码问题漏洞 — MobaXterm | 7.8 | High | 2026-03-09 |
| CVE-2026-26033 | Dell UPS Multi-UPS Management Console 代码问题漏洞 — UPS Multi-UPS Management Console (MUMC) | 7.8 | - | 2026-03-05 |
| CVE-2026-1585 | Canon IJ Scan Utility 安全漏洞 — IJ Scan Utility | 6.7 | Medium | 2026-02-26 |
| CVE-2026-2542 | Total VPN 代码问题漏洞 — Total VPN | 7.0 | High | 2026-02-16 |
| CVE-2019-25345 | Realtek IIS Codec Service 代码问题漏洞 — RTK IIS Codec Service | 7.8 | High | 2026-02-12 |
| CVE-2019-25309 | Zilab Remote Console Server 代码问题漏洞 — Zilab Remote Console Server | 7.8 | High | 2026-02-11 |
| CVE-2019-25310 | ActFax ActiveFax Server 代码问题漏洞 — ActiveFax Server | 7.8 | High | 2026-02-11 |
| CVE-2019-25308 | Mikogo 代码问题漏洞 — Mikogo | 7.8 | High | 2026-02-11 |
| CVE-2019-25307 | Softalk WorkgroupMail 代码问题漏洞 — WorkgroupMail | 7.8 | High | 2026-02-11 |
CWE-428(未经引用的搜索路径或元素) 是常见的弱点类别,本平台收录该类弱点关联的 303 条 CVE 漏洞。