Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
Unclassified HIGH 7.8
CVE-2026-56437

Uncontrolled search path element issue exists in Pupsman versions prior to 3.9.0. If a crafted DLL file is placed in the same folder as the affected …

Mitigation only
Fix from $1,950 2026-07-08
Notepad3 HIGH 7.8
CVE-2026-38972

Notepad3 through 6.25.822.1 contains a DLL search-order hijacking vulnerability in the About-dialog code path in src/Notepad3.c. The application call…

Fix: after 6.25.822.1
Fix from $1,950 2026-07-02
Electron Builder HIGH 7.8
CVE-2026-54672

electron-updater allows for automatic updates for Electron apps. Prior to 26.15.0, AppImage targets built by app-builder-lib could use an empty path …

Patch available
Fix from $1,950 2026-06-30
Vllm HIGH 8.8
CVE-2026-54232

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.1, the vLLM Dockerfile is vulnerable to a dependency confusio…

Fix: 0.22.1+
Fix from $1,950 2026-06-22
Angular Language Service HIGH 8.8
CVE-2026-49241

The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. Prior to 21.2.4, the client-side Angular Lan…

Fix: 21.2.4+
Fix from $1,950 2026-06-22
Unclassified HIGH 7.3
CVE-2026-6645

An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows. The appli…

Mitigation only
Fix from $1,950 2026-06-22
Unclassified HIGH 7.3
CVE-2026-11958

Local privilege escalation by loading DLLs from a shared temporary directory in ANSSI’s DFIR-ORC, versions 10.2.7 and prior. An attacker with prior a…

Mitigation only
Fix from $1,950 2026-06-18
Unclassified MEDIUM 5.3
CVE-2026-12003

To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and us…

Patch available
Fix from $1,600 2026-06-16
Peripheral Manager MEDIUM 6.7
CVE-2024-22451

Dell Peripheral Manager, versions from 1.5.1 to 1.7.2, contain an uncontrolled search path element vulnerability. An attacker could potentially explo…

Fix: 1.7.3+
Fix from $1,600 2026-06-16
Peripheral Manager HIGH 7.8
CVE-2024-22447

Dell Peripheral Manager, versions prior to 1.7.3, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit th…

Fix: 1.7.3+
Fix from $1,950 2026-06-16
Unclassified HIGH 8.5
CVE-2026-5064

Potential security vulnerabilities have been identified in the HP One Agent for certain HP PC products, which might allow for escalat…

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 7.8
CVE-2026-50100

Multiple printer drivers provided by Ricoh Company, Ltd. and KONICA MINOLTA JAPAN, INC. contain a privilege escalation vulnerability. If this vulnera…

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 8.5
CVE-2026-11967

MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading a malicious DLL located in the sa…

Mitigation only
Fix from $1,950 2026-06-12
Unclassified HIGH 8.5
CVE-2026-11879

MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading malicious DLLs from a temporary d…

Mitigation only
Fix from $1,950 2026-06-12
Openclaw HIGH 7.8
CVE-2026-53813

OpenClaw before 2026.4.25 contains a path traversal vulnerability in memory-core artifact loading where workspace state influences local package root…

Fix: 2026.4.25+
Fix from $1,950 2026-06-11
I HIGH 8.8
CVE-2026-7870

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-co…

Mitigation only
Fix from $1,950 2026-06-11
Unclassified HIGH 7.8
CVE-2026-10847

A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated local user may be able to execu…

Mitigation only
Fix from $1,950 2026-06-11
Unclassified HIGH 7.8
CVE-2026-8637

A potential uncontrolled search path vulnerability was reported in the LanSchool Classic client application that could allow a local authenticated us…

Mitigation only
Fix from $1,950 2026-06-10
Acrobat Dc HIGH 7.7
CVE-2026-47937

Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in…

Fix: 24.001.30383 / 26.001.21662+
Fix from $1,950 2026-06-09
Unclassified HIGH 7.2
CVE-2026-41567

Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is upl…

Mitigation only
Fix from $1,950 2026-06-05
Unclassified HIGH 7.3
CVE-2026-44609

Local privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0…

Mitigation only
Fix from $1,950 2026-06-03
Unclassified HIGH 7.3
CVE-2026-44682

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0…

Mitigation only
Fix from $1,950 2026-06-03
Unclassified HIGH 7.3
CVE-2026-50033

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0…

Mitigation only
Fix from $1,950 2026-06-03
Unclassified HIGH 7.8
CVE-2026-36574

A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escalate privileges and execute arbitrary code via a c…

Mitigation only
Fix from $1,950 2026-06-03
Unclassified HIGH 8.2
CVE-2026-44358

Espressif Shared GitHub DangerJS is a reusable GitHub Action CI DangerJS workflow for Espressif GitHub projects. Prior to 1.0.1, the action's entrypo…

Patch available
Fix from $1,950 2026-05-28
Unclassified MEDIUM 6.3
CVE-2026-47274

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, multiple pam_usb helper tools resolved external bi…

Patch available
Fix from $1,600 2026-05-27
Beedrive HIGH 7.8
CVE-2023-52945

Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to exe…

Fix: 1.3.2-13814+
Fix from $1,950 2026-05-27
Unclassified HIGH 7.8
CVE-2025-41670

A local user with low privileges may be able to influence the behavior of a privileged system service by manipulating configuration or application-re…

Mitigation only
Fix from $1,950 2026-05-27
Mullvad Vpn HIGH 7.8
CVE-2026-32323

Mullvad VPN is a VPN client app for desktop and mobile. When using macOS with versions 2026.1 and below, Mullvad VPN may allow local privilege escala…

Fix: 2026.2+
Fix from $1,950 2026-05-19
Claude Hud HIGH 7.8
CVE-2026-47092

Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attackers to execute arbitrary com…

Fix: after 0.0.12
Fix from $1,950 2026-05-18