Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
Unclassified MEDIUM 6.7
CVE-2023-39929

Uncontrolled search path in some Libva software maintained by Intel(R) before version 2.20.0 may allow an authenticated user to potentially enable es…

Mitigation only
Fix from $1,600 2024-05-16
Graphics Performance Analyzers Framework HIGH 7.8
CVE-2023-35192

Uncontrolled search path in some Intel(R) GPA Framework software before version 2023.3 may allow an authenticated user to potentially enable escalati…

Fix: 2023.3+
Fix from $1,950 2024-05-16
Network Services Orchestrator HIGH 7.8
CVE-2024-20366

A vulnerability in the Tail-f High Availability Cluster Communications (HCC) function pack of Cisco Crosswork Network Services Orchestrator (NSO) cou…

Fix: 5.0.5 / 6.0.2+
Fix from $1,950 2024-05-15
Automation Studio HIGH 7.2
CVE-2021-22280

Improper DLL loading algorithms in B&R Automation Studio versions >=4.0 and <4.12 may allow an authenticated local attacker to execute code in the co…

Fix: 4.12+
Fix from $1,950 2024-05-14
Unclassified HIGH 7.2
CVE-2024-2637

An Uncontrolled Search Path Element vulnerability in B&R Industrial Automation Scene Viewer, B&R Industrial Automation Automation Runtime, B&R Indust…

Mitigation only
Fix from $1,950 2024-05-14
Cobalt HIGH 7.8
CVE-2023-44437

Ashlar-Vellum Cobalt Uncontrolled Search Path Element Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

Fix: 12.0.1204.78+
Fix from $1,950 2024-05-03
Argon HIGH 8.8
CVE-2023-44438

Ashlar-Vellum Argon Uncontrolled Search Path Element Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbit…

Mitigation only
Fix from $1,950 2024-05-03
Xenon HIGH 8.8
CVE-2023-44439

Ashlar-Vellum Xenon Uncontrolled Search Path Element Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbit…

Mitigation only
Fix from $1,950 2024-05-03
Lithium HIGH 8.8
CVE-2023-44440

Ashlar-Vellum Lithium Uncontrolled Search Path Element Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arb…

Mitigation only
Fix from $1,950 2024-05-03
3cx HIGH 7.8
CVE-2023-27362

3CX Uncontrolled Search Path Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected i…

Fix: 18.0.8.917+
Fix from $1,950 2024-05-03
Rational Developer For I HIGH 7.8
CVE-2024-25050

IBM i 7.2, 7.3, 7.4, 7.5 and IBM Rational Development Studio for i 7.2, 7.3, 7.4, 7.5 networking and compiler infrastructure could allow a local user…

Mitigation only
Fix from $1,950 2024-04-28
Netbackup HIGH 7.1
CVE-2024-33672

An issue was discovered in Veritas NetBackup before 10.4. The Multi-Threaded Agent used in NetBackup can be leveraged to perform arbitrary file delet…

Fix: 10.4+
Fix from $1,950 2024-04-26
Vt Studio HIGH 7.8
CVE-2024-28099

VT STUDIO Ver.8.32 and earlier contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, …

Fix: after 8.32
Fix from $1,950 2024-04-15
Alienware Command Center HIGH 7.8
CVE-2024-22450

Dell Alienware Command Center, versions prior to 6.2.7.0, contain an uncontrolled search path element vulnerability. A local malicious user could pot…

Fix: 6.2.7.0+
Fix from $1,950 2024-04-10
Unclassified HIGH 7.8
CVE-2024-29734

Uncontrolled search path element issue exists in SonicDICOM Media Viewer 2.3.2 and earlier, which may lead to insecurely loading Dynamic Link Librari…

Mitigation only
Fix from $1,950 2024-04-03
Unclassified HIGH 7.1
CVE-2024-0980

The Auto-update service for Okta Verify for Windows is vulnerable to two flaws which in combination could be used to execute arbitrary code.

No fix yet
Fix from $1,950 2024-03-28
Unclassified HIGH 7.8
CVE-2024-28131

EasyRange Ver 1.41 contains an issue with the executable file search path when displaying an extracted file on Explorer, which may lead to loading an…

Mitigation only
Fix from $1,950 2024-03-26
Claris Pro HIGH 7.8
CVE-2023-42920

Claris International has fixed a dylib hijacking vulnerability in the FileMaker Pro.app and Claris Pro.app versions on macOS.

Fix: 20.2+
Fix from $1,950 2024-03-19
I HIGH 7.8
CVE-2024-22346

Db2 for IBM i 7.2, 7.3, 7.4, and 7.5 infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. A malici…

Patch available
Fix from $1,950 2024-03-14
Unclassified HIGH 7.9
CVE-2024-22167

A potential DLL hijacking vulnerability in the SanDisk PrivateAccess application for Windows that could lead to arbitrary code execution in the conte…

Mitigation only
Fix from $1,950 2024-03-13
Checkmk HIGH 7.8
CVE-2024-0670

Privilege escalation in windows agent plugin in Checkmk before 2.2.0p23, 2.1.0p40 and 2.0.0 (EOL) allows local user to escalate privileges

Fix: 2.1.0+
Fix from $1,950 2024-03-11
Electron Builder HIGH 7.3
CVE-2024-27303

electron-builder is a solution to package and build a ready for distribution Electron, Proton Native app for macOS, Windows and Linux. A vulnerabilit…

Fix: 24.13.2+
Fix from $1,950 2024-03-06
Secure Client HIGH 7.3
CVE-2024-20338

A vulnerability in the ISE Posture (System Scan) module of Cisco Secure Client for Linux could allow an authenticated, local attacker to elevate priv…

Fix: 5.1.2.42+
Fix from $1,950 2024-03-06
Update Package Framework HIGH 7.3
CVE-2023-39254

Dell Update Package (DUP), Versions prior to 4.9.10 contain an Uncontrolled Search Path vulnerability. A malicious user with local access to the syst…

Fix: 4.9.10+
Fix from $1,950 2024-03-01
Cncsoft B HIGH 7.8
CVE-2024-1595

Delta Electronics CNCSoft-B DOPSoft prior to v4.0.0.82 insecurely loads libraries, which may allow an attacker to use DLL hijacking and take over t…

Fix: 4.0.0.94+
Fix from $1,950 2024-02-29
Platform Common Services HIGH 7.8
CVE-2023-6132

The vulnerability, if exploited, could allow a malicious entity with access to the file system to achieve arbitrary code execution and privilege esca…

Mitigation only
Fix from $1,950 2024-02-29
Qognify Vms Client Viewer MEDIUM 6.7
CVE-2023-49114

A DLL hijacking vulnerability was identified in the Qognify VMS Client Viewer version 7.1 or higher, which allows local users to execute arbitrary co…

No fix yet
Fix from $1,600 2024-02-26
Mpi Library HIGH 7.8
CVE-2023-41091

Uncontrolled search path for some Intel(R) MPI Library Software before version 2021.11 may allow an authenticated user to potentially enable escalati…

Fix: 2021.11+
Fix from $1,950 2024-02-14
System Support Utility HIGH 7.8
CVE-2023-40156

Uncontrolled search path element in some Intel(R) SSU software before version 3.0.0.2 may allow an authenticated user to potentially enable escalatio…

Fix: 3.0.0.2+
Fix from $1,950 2024-02-14
System Usage Report For Gameplay MEDIUM 6.7
CVE-2023-39932

Uncontrolled search path in the Intel(R) SUR for Gameplay Software before version 2.0.1901 may allow a privillaged user to potentially enable escalat…

Fix: 2.0.1901+
Fix from $1,600 2024-02-14