VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
20,165 CVE recordsPage 611 of 1345 · EPSS data 2026.08.14
ReviewHigh
CVE-2021-47985

Brother SAPSprint

Brother SAPSprint 7.60 contains an unquoted service path vulnerability in the SAPSprint service binary that allows local attackers to escalate privileges. Attackers can place a malicious executable in the Program Files directory path to be executed with LocalSystem privileges when the service starts automatically.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2020-37254

Wondershare PDFelement

Wondershare PDFelement 5.2.9 contains a privilege escalation vulnerability due to an unquoted service path in the WsAppService Windows service. Local attackers can place a malicious executable in the service path and execute code with LocalSystem privileges upon service restart or system reboot.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2020-37253

Winstep

Winstep 18.06.0096 contains an unquoted service path vulnerability in the Winstep Xtreme Service that allows local attackers to escalate privileges. Attackers can place malicious executables in the Program Files directory to be executed with LocalSystem privileges when the service starts.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2020-37252

Realtek Realtek Audio Service

Realtek Audio Service 1.0.0.55 contains an unquoted service path vulnerability in RtkAudioService64.exe that allows local attackers to escalate privileges by injecting malicious code. Attackers can place executable files in the unquoted service path directory to execute arbitrary code with LocalSystem privileges during service startup or system reboot.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2020-37251

Real RealTimes Desktop Service

RealTimes Desktop Service 18.1.4 contains an unquoted service path vulnerability in the rpdsvc.exe binary that allows local attackers to escalate privileges. Attackers can place malicious executables in unquoted path directories to execute arbitrary code with LocalSystem privileges during service startup or system reboot.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2020-37250

Weird-Solutions TFTP Broadband

TFTP Broadband 4.3.0.1465 contains an unquoted service path vulnerability in the tftpt.exe service binary that allows local attackers to execute arbitrary code with system privileges. Attackers can place a malicious executable in the Program Files directory path that will be executed during service startup or system reboot with LocalSystem privileges.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2019-25747

Network-Inventory-Advisor Network Inventory Advisor

Network Inventory Advisor 5.0.26.0 installs the niaservice service with an unquoted binary path that allows local attackers to escalate privileges by placing malicious executables in intermediate directories. Attackers can exploit the unquoted path in the service configuration to execute arbitrary code with LocalSystem privileges when the service starts or restarts.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2016-20095

Matrix42 Matrix42 Remote Control Host

Matrix42 Remote Control Host 3.20.0031 contains an unquoted service path vulnerability in the FastViewerRemoteService and FastViewerRemoteProxy services that allows local users to execute arbitrary code with SYSTEM privileges. Attackers can place a malicious executable in the Program Files directory with a crafted name to be executed by the service during startup, gaining elevated privileges.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2016-20094

Anydesk AnyDesk, anydesk

AnyDesk 2.5.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the service installation. Attackers can insert malicious executables in the system root path that execute with elevated privileges during application startup or system reboot.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2016-20093

Wisecleaner Wise Care 365, Wise Disk Cleaner

Wise Care 365 4.27 and Wise Disk Cleaner 9.29 contain unquoted service path vulnerabilities in the WiseBootAssistant and SpyHunter 4 Service respectively, allowing local users to execute arbitrary code with SYSTEM privileges. Attackers can insert malicious executables in the system root path that execute during service startup or system reboot with elevated privileges.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2016-20092

Netdrive

NetDrive 2.6.12 contains an unquoted service path vulnerability in the Netdrive2_Service_Netdrive2 service that allows local users to execute arbitrary code with SYSTEM privileges. Attackers can insert malicious executables in the system root path that will be executed during service startup or system reboot, resulting in privilege escalation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2016-20091

Binisoft Windows Firewall Control

Windows Firewall Control 4.8.6.0 contains an unquoted service path vulnerability that allows local attackers to escalate privileges by inserting malicious executables in the service path. Attackers can place executable files in unquoted path directories that the wfcs.exe service will execute with LocalSystem privileges upon service restart or system reboot.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2016-20090

Comodo Dragon Browser

Comodo Dragon Browser versions up to 52.15.25.663 contain a privilege escalation vulnerability in the DragonUpdater service due to an unquoted service path running with SYSTEM privileges. A local attacker can insert a malicious executable in the service path and execute arbitrary code with elevated privileges upon service restart or system reboot.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2016-20089

Iperiusremote Iperius Remote

Iperius Remote 1.7.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the service installation path. When installed from directories containing spaces, attackers can place malicious executables in the path to be executed with elevated privileges during service startup or system reboot.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2016-20088

Comodo Chromodo Browser

Comodo Chromodo Browser 52.15.25.664 contains an unquoted service path vulnerability in the ChromodoUpdater service that runs with SYSTEM privileges. A local attacker can insert a malicious executable in the service path and execute arbitrary code with elevated privileges upon service restart or system reboot.

The CVSS severity warrants an early asset and exposure review.