Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
Unclassified HIGH 7.8
CVE-2024-10068

A vulnerability was found in OpenSight Software FlashFXP 5.4.0.3970. It has been classified as critical. Affected is an unknown function in the libra…

Mitigation only
Fix from $1,950 2024-10-17
Cyber Files HIGH 7.3
CVE-2024-49390

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x…

Fix: 9.0+
Fix from $1,950 2024-10-17
Cyber Files HIGH 7.3
CVE-2024-49391

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x…

Fix: 9.0+
Fix from $1,950 2024-10-17
Solarwinds Platform HIGH 7.8
CVE-2024-45710

SolarWinds Platform is susceptible to an Uncontrolled Search Path Element Local Privilege Escalation vulnerability. This requires a low privilege acc…

Fix: 2024.4+
Fix from $1,950 2024-10-16
Bigfix Platform MEDIUM 5.3
CVE-2024-30117

A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file under some circumstances.

Fix: 9.5.25 / 10.0.12+
Fix from $1,600 2024-10-14
Starstudio HIGH 7.8
CVE-2024-9046

A DLL hijack vulnerability was reported in Lenovo stARstudio that could allow a local attacker to execute code with elevated privileges.

Fix: 2020.3.12.34806+
Fix from $1,950 2024-10-11
Emulator HIGH 7.8
CVE-2024-4131

A DLL hijack vulnerability was reported in Lenovo Emulator that could allow a local attacker to execute code with elevated privileges.

Fix: 9.1.6+
Fix from $1,950 2024-10-11
Lock Screen HIGH 7.8
CVE-2024-4132

A DLL hijack vulnerability was reported in Lenovo Lock Screen that could allow a local attacker to execute code with elevated privileges.

Fix: 9.0.18+
Fix from $1,950 2024-10-11
Superfile HIGH 7.8
CVE-2024-4089

A DLL hijack vulnerability was reported in Lenovo Super File that could allow a local attacker to execute code with elevated privileges.

Fix: 2.4+
Fix from $1,950 2024-10-11
App Store HIGH 7.8
CVE-2024-4130

A DLL hijack vulnerability was reported in Lenovo App Store that could allow a local attacker to execute code with elevated privileges.

Fix: 9.0.17+
Fix from $1,950 2024-10-11
Unclassified HIGH 7.8
CVE-2024-33582

A DLL hijack vulnerability was reported in Lenovo Service Framework that could allow a local attacker to execute code with elevated privileges.

Mitigation only
Fix from $1,950 2024-10-11
Unclassified HIGH 7.8
CVE-2024-33578

A DLL hijack vulnerability was reported in Lenovo Leyun that could allow a local attacker to execute code with elevated privileges.

Mitigation only
Fix from $1,950 2024-10-11
Unclassified HIGH 7.8
CVE-2024-33579

A DLL hijack vulnerability was reported in Lenovo Baiying that could allow a local attacker to execute code with elevated privileges.

Mitigation only
Fix from $1,950 2024-10-11
Unclassified HIGH 7.8
CVE-2024-33580

A DLL hijack vulnerability was reported in Lenovo Personal Cloud that could allow a local attacker to execute code with elevated privileges.

Mitigation only
Fix from $1,950 2024-10-11
Unclassified HIGH 7.8
CVE-2024-33581

A DLL hijack vulnerability was reported in Lenovo PC Manager AI intelligent scenario that could allow a local attacker to execute code with elevated …

Mitigation only
Fix from $1,950 2024-10-11
Modelsim HIGH 7.3
CVE-2024-47194

A vulnerability has been identified in ModelSim (All versions < V2024.3), Questa (All versions < V2024.3). vish2.exe in affected applications allows …

Fix: 2024.3+
Fix from $1,950 2024-10-08
Modelsim HIGH 7.3
CVE-2024-47195

A vulnerability has been identified in ModelSim (All versions < V2024.3), Questa (All versions < V2024.3). gdb.exe in affected applications allows a …

Fix: 2024.3+
Fix from $1,950 2024-10-08
Modelsim HIGH 7.3
CVE-2024-47196

A vulnerability has been identified in ModelSim (All versions < V2025.2), Questa (All versions < V2025.2). vsimk.exe in affected applications allows …

Fix: 2024.3+
Fix from $1,950 2024-10-08
Unclassified HIGH 7.3
CVE-2024-45246

Diebold Nixdorf – CWE-427: Uncontrolled Search Path Element

No fix yet
Fix from $1,950 2024-10-06
Unclassified MEDIUM 6.7
CVE-2024-6769

A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Microsoft Windows 10, Windows 11, Windows Server 2016,…

Mitigation only
Fix from $1,600 2024-09-26
macOS MEDIUM 5.5
CVE-2024-44168

A library injection issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7.…

Fix: 13.7 / 14.7+
Fix from $1,600 2024-09-17
Unclassified MEDIUM 6.7
CVE-2024-8766

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) befor…

Mitigation only
Fix from $1,600 2024-09-16
Unclassified MEDIUM 6.5
CVE-2024-34016

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) befor…

Mitigation only
Fix from $1,600 2024-09-16
Raid Web Console HIGH 7.8
CVE-2024-34153

Uncontrolled search path element in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable escalat…

Mitigation only
Fix from $1,950 2024-09-16
Mattermost Desktop HIGH 7.8
CVE-2024-39613

Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able …

Fix: 5.9.0+
Fix from $1,950 2024-09-16
Meraki Systems Manager HIGH 7.3
CVE-2024-20430

A vulnerability in Cisco Meraki Systems Manager (SM) Agent for Windows could allow an authenticated, local attacker to execute arbitrary code with el…

Fix: 4.2.0+
Fix from $1,950 2024-09-12
Internet Security HIGH 7.8
CVE-2024-6510

Local Privilege Escalation in AVG Internet Security v24 on Windows allows a local unprivileged user to escalate privileges to SYSTEM via COM-Hijackin…

Fix: 24.1+
Fix from $1,950 2024-09-12
Endpoint Manager MEDIUM 6.7
CVE-2024-8441

An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin…

Fix: 2022+
Fix from $1,600 2024-09-10
Workspace Control HIGH 7.8
CVE-2024-44107

DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escala…

Fix: 10.18.99.0+
Fix from $1,950 2024-09-10
Unclassified MEDIUM 6.0
CVE-2024-45405

`gix-path` is a crate of the `gitoxide` project (an implementation of `git` written in Rust) dealing paths and their conversions. Prior to version 0.…

Patch available
Fix from $1,600 2024-09-06