Cyber Posture

CWE · MITRE source

CWE-428Unquoted Search Path or Element

Abstraction: Base · CVEs in our corpus: 418

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

If a malicious individual has access to the file system, it is possible to elevate privileges by inserting such a file as "C:\Program.exe" to be run by a privileged program making use of WinExec.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (0)AI

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2023-384085.89.80.64352023-07-20
CVE-2020-152612.18.00.08062020-10-19
CVE-2019-84592.09.80.00502019-06-20
CVE-2019-176582.09.80.00392020-03-12
CVE-2020-92922.09.80.00502020-06-04
CVE-2022-363442.09.80.00712022-08-16
CVE-2022-509352.09.80.00062026-01-13
CVE-2016-57931.88.80.00052016-09-24
CVE-2020-276441.88.80.00662020-12-29
CVE-2020-276451.88.80.00662020-12-29
CVE-2023-272981.88.80.00392023-05-10
CVE-2024-247221.89.10.00162024-02-19
CVE-2025-125071.88.80.00022025-10-31
CVE-2020-55691.78.40.00162020-04-20
CVE-2020-145211.78.30.00582022-02-11
CVE-2024-434571.77.80.02662024-09-10
CVE-2025-107141.78.40.00022025-11-11
CVE-2023-539461.78.40.00032025-12-19
CVE-2023-539471.78.40.00022025-12-19
CVE-2022-506881.78.40.00022025-12-22
CVE-2023-539651.78.40.00032025-12-22
CVE-2021-477391.78.40.00012025-12-23
CVE-2020-369031.78.40.00022025-12-31
CVE-2019-252311.78.40.00022026-01-08
CVE-2022-506931.78.40.00022026-01-13