Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
Unclassified HIGH 7.7
CVE-2025-53394

Paramount Macrium Reflect through 2025-06-26 allows attackers to execute arbitrary code with administrator privileges via a crafted .mrimgx or .mrbax…

Mitigation only
Fix from $1,950 2025-08-04
Unclassified HIGH 7.0
CVE-2025-0712

An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions. The vulnerability …

Mitigation only
Fix from $1,950 2025-07-30
Unclassified HIGH 7.0
CVE-2025-25011

An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions. The vulnerability …

Mitigation only
Fix from $1,950 2025-07-30
Unclassified MEDIUM 5.4
CVE-2025-7676

DLL hijacking of all PE32 executables when run on Windows for ARM64 CPU architecture. This allows an attacker to execute code, if the attacker can pl…

Mitigation only
Fix from $1,600 2025-07-28
Unclassified HIGH 8.5
CVE-2024-13976

A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During the installation of maintenance…

Mitigation only
Fix from $1,950 2025-07-25
Arm Development Studio MEDIUM 5.9
CVE-2025-7427

Uncontrolled Search Path Element in Arm Development Studio before 2025 may allow an attacker to perform a DLL hijacking attack. Successful exploitati…

Fix: 2025.0+
Fix from $1,600 2025-07-22
Unclassified HIGH 7.0
CVE-2025-1700

A DLL hijacking vulnerability was reported in the Motorola Software Fix (Rescue and Smart Assistant) installer that could allow a local attacker to e…

Mitigation only
Fix from $1,950 2025-07-17
Unclassified MEDIUM 6.7
CVE-2025-1729

A DLL hijacking vulnerability was reported in TrackPoint Quick Menu software that, under certain conditions, could allow a local attacker to escalate…

Mitigation only
Fix from $1,600 2025-07-17
Unclassified HIGH 7.5
CVE-2025-7472

A local privilege escalation vulnerability in the Intercept X for Windows installer prior version 1.22 can lead to a local user gaining system level …

Mitigation only
Fix from $1,950 2025-07-17
Unclassified HIGH 8.5
CVE-2025-34109

PSEvents.exe in multiple Panda Security products runs hourly with SYSTEM privileges and loads DLL files from a user-writable directory without proper…

No fix yet
Fix from $1,950 2025-07-15
Unclassified MEDIUM 5.1
CVE-2025-48496

Emerson ValveLink products use a fixed or controlled search path to find resources, but one or more locations in that path can be under the control…

Mitigation only
Fix from $1,600 2025-07-11
I HIGH 8.8
CVE-2025-36004

IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user to gain elevated privileges due to an unqualified library call in IBM Facsimile Support for i. A mali…

Mitigation only
Fix from $1,950 2025-06-25
Unclassified HIGH 7.3
CVE-2025-49144

Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.…

Patch available
Fix from $1,950 2025-06-23
Mattermost Server CRITICAL 9.9
CVE-2025-4981

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sanitize filenames in the archi…

Fix: 9.11.16 / 10.5.6+
Fix from $2,300 2025-06-20
Smartconsole HIGH 7.8
CVE-2024-24916

Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution with the installer's privileg…

Mitigation only
Fix from $1,950 2025-06-19
Osv Scalibr MEDIUM 6.5
CVE-2025-5981

Arbitrary file write as the OSV-SCALIBR user on the host system via a path traversal vulnerability when using OSV-SCALIBR's unpack() function for con…

Fix: 0.1.8+
Fix from $1,600 2025-06-18
Worry Free Business Security Services MEDIUM 6.8
CVE-2025-49487

An uncontrolled search path vulnerability in the Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an attacker with …

Fix: 6.7.3954 / 14.3.1299+
Fix from $1,600 2025-06-17
Apex One HIGH 8.8
CVE-2025-49155

An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacker to inject malicious code le…

Fix: 14.0.0.14002 / 14.0.14492+
Fix from $1,950 2025-06-17
Apex One HIGH 7.8
CVE-2025-49158

An uncontrolled search path vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalation privileges on affecte…

Fix: 14.0.0.14002 / 14.0.14492+
Fix from $1,950 2025-06-17
I HIGH 7.5
CVE-2025-33122

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 could allow a user to gain elevated privileges due to an unqualified library call in IBM Advanced Job Scheduler for…

Mitigation only
Fix from $1,950 2025-06-17
Unclassified HIGH 7.3
CVE-2025-49148

ClipShare is a lightweight and cross-platform tool for clipboard sharing. Prior to 3.8.5, ClipShare Server for Windows uses the default Windows DLL s…

Mitigation only
Fix from $1,950 2025-06-11
Agent HIGH 7.8
CVE-2025-5480

Action1 Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges o…

Fix: 5.218.620.1+
Fix from $1,950 2025-06-06
Jupyter Core HIGH 7.3
CVE-2025-30167

Jupyter Core is a package for the core common functionality of Jupyter projects. When using Jupyter Core prior to version 5.8.0 on Windows, the share…

Fix: 5.8.0+
Fix from $1,950 2025-06-03
Traveler For Microsoft Outlook CRITICAL 9.8
CVE-2024-42190

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the appl…

Fix: 3.0.12+
Fix from $2,300 2025-05-30
Traveler For Microsoft Outlook CRITICAL 9.8
CVE-2024-42191

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the appl…

Fix: 3.0.12+
Fix from $2,300 2025-05-30
Filmora HIGH 7.3
CVE-2025-5180

A vulnerability, which was classified as critical, has been found in Wondershare Filmora 14.5.16. Affected by this issue is some unknown functionalit…

No fix yet
Fix from $1,950 2025-05-26
Atrust MEDIUM 6.3
CVE-2025-5129

A vulnerability has been found in Sangfor 零信任访问控制系统 aTrust 2.3.10.60 and classified as critical. Affected by this vulnerability is an unknow…

No fix yet
Fix from $1,600 2025-05-24
Unclassified MEDIUM 6.8
CVE-2024-13946

DLL's are not digitally signed when loaded in ASPECT's configuration toolset exposing the application to binary planting during device commissioning.…

Mitigation only
Fix from $1,600 2025-05-22
Unclassified HIGH 7.0
CVE-2025-2272

Uncontrolled Search Path Element vulnerability in Forcepoint FIE Endpoint allows Privilege Escalation, Code Injection, Hijacking a privileged process…

Mitigation only
Fix from $1,950 2025-05-22
Battle.net HIGH 8.4
CVE-2025-27997

An issue in Blizzard Battle.net v2.40.0.15267 allows attackers to escalate privileges via placing a crafted shell script or executable into the C:\Pr…

Mitigation only
Fix from $1,950 2025-05-21