Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
Video Player HIGH 7.8
CVE-2023-47453

An Untrusted search path vulnerability in Sohu Video Player 7.0.15.0 allows local users to gain escalated privileges through the version.dll file in …

No fix yet
Fix from $1,950 2023-11-30
Cloudmusic HIGH 7.8
CVE-2023-47454

An Untrusted search path vulnerability in NetEase CloudMusic 2.10.4 for Windows allows local users to gain escalated privileges through the urlmon.dl…

No fix yet
Fix from $1,950 2023-11-30
Notepad\+\+ HIGH 7.8
CVE-2023-6401

A vulnerability classified as problematic was found in NotePad++ up to 8.1. Affected by this vulnerability is an unknown functionality of the file db…

Fix: after 8.1
Fix from $1,950 2023-11-30
4d HIGH 7.8
CVE-2023-4770

An uncontrolled search path element vulnerability has been found on 4D and 4D server Windows executables applications, affecting version 19 R8 100218…

Mitigation only
Fix from $1,950 2023-11-30
Plesk HIGH 7.8
CVE-2023-4931

Uncontrolled search path element vulnerability in Plesk Installer affects version 3.27.0.0. A local attacker could execute arbitrary code by injectin…

Mitigation only
Fix from $1,950 2023-11-27
Pandora Fms HIGH 7.5
CVE-2023-41787

Uncontrolled Search Path Element vulnerability in Pandora FMS on all allows Leveraging/Manipulating Configuration File Search Paths. This vulnerabili…

Fix: 773+
Fix from $1,950 2023-11-23
Pandora Fms CRITICAL 9.8
CVE-2023-41790

Uncontrolled Search Path Element vulnerability in Pandora FMS on all allows Leveraging/Manipulating Configuration File Search Paths. This vulnerabili…

Fix: after 773
Fix from $2,300 2023-11-23
Desktop Connector HIGH 7.8
CVE-2023-29069

A maliciously crafted DLL file can be forced to install onto a non-default location, and attacker can overwrite parts of the product with malicious D…

Fix: after 16.2.1.2016
Fix from $1,950 2023-11-22
Vlc Media Player HIGH 7.8
CVE-2023-46814

A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with …

Fix: 3.0.19+
Fix from $1,950 2023-11-22
Duet Display HIGH 7.8
CVE-2023-6235

An uncontrolled search path element vulnerability has been found in the Duet Display product, affecting version 2.5.9.1. An attacker could place an a…

Mitigation only
Fix from $1,950 2023-11-21
Sandisk Security Installer HIGH 7.8
CVE-2023-22818

Multiple DLL Search Order Hijack vulnerabilities were addressed in the SanDisk Security Installer for Windows that could allow attackers with local a…

Fix: 1.0.0.25+
Fix from $1,950 2023-11-15
Extreme Tuning Utility HIGH 7.8
CVE-2023-34350

Uncontrolled search path element in some Intel(R) XTU software before version 7.12.0.15 may allow an authenticated user to potentially enable escalat…

Fix: 7.12.0.15+
Fix from $1,950 2023-11-14
Battery Life Diagnostic Tool HIGH 7.8
CVE-2023-34430

Uncontrolled search path in some Intel Battery Life Diagnostic Tool software before version 2.2.1 may allow an authenticated user to potentially enab…

Fix: 2.2.1+
Fix from $1,950 2023-11-14
Hid Event Filter Driver HIGH 7.3
CVE-2023-33874

Uncontrolled search path in some Intel(R) NUC 12 Pro Kits & Mini PCs - NUC12WS Intel(R) HID Event Filter Driver installation software before version …

Fix: 2.2.2.1+
Fix from $1,950 2023-11-14
Thunderbolt 3 Controller Firmware HIGH 7.3
CVE-2023-32660

Uncontrolled search path in some Intel(R) NUC Kit NUC6i7KYK Thunderbolt(TM) 3 Firmware Update Tool installation software before version 46 may allow …

Fix: 46+
Fix from $1,950 2023-11-14
Realsense D400 Series Dynamic Calibration Tool HIGH 7.8
CVE-2023-29504

Uncontrolled search path element in some Intel(R) RealSense(TM) Dynamic Calibration software before version 2.13.1.0 may allow an authenticated user …

Fix: 2.13.1.0+
Fix from $1,950 2023-11-14
Quickassist Technology Library HIGH 7.8
CVE-2023-28740

Uncontrolled search path element in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to po…

Fix: 1.10 / 2.04+
Fix from $1,950 2023-11-14
One Boot Flash Update HIGH 7.8
CVE-2023-29161

Uncontrolled search path in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of pri…

Fix: 14.1.31+
Fix from $1,950 2023-11-14
Chipset Device Software HIGH 7.8
CVE-2023-28388

Uncontrolled search path element in some Intel(R) Chipset Device Software before version 10.1.19444.8378 may allow an authenticated user to potential…

Fix: 10.1.19444.8378+
Fix from $1,950 2023-11-14
Server Information Retrieval Utility HIGH 7.8
CVE-2023-27513

Uncontrolled search path element in some Intel(R) Server Information Retrieval Utility software before version 16.0.9 may allow an authenticated user…

Fix: 16.0.9+
Fix from $1,950 2023-11-14
System Update HIGH 7.8
CVE-2023-4632

An uncontrolled search path vulnerability was reported in Lenovo System Update that could allow an attacker with local access to execute code with el…

Fix: 5.08.02.25+
Fix from $1,950 2023-11-08
Bleachbit HIGH 7.3
CVE-2023-47113

BleachBit cleans files to free disk space and to maintain privacy. BleachBit for Windows up to version 4.4.2 is vulnerable to a DLL Hijacking vulnera…

Fix: after 4.4.2
Fix from $1,950 2023-11-08
Micom S1 Agile HIGH 7.3
CVE-2023-0898

General Electric MiCOM S1 Agile is vulnerable to an attacker achieving code execution by placing malicious DLL files in the directory of the applicat…

Mitigation only
Fix from $1,950 2023-11-07
Virtual Gpu HIGH 7.3
CVE-2023-31027

NVIDIA GPU Display Driver for Windows contains a vulnerability that allows Windows users with low levels of privilege to escalate privileges when an …

Fix: 13.9 / 15.4+
Fix from $1,950 2023-11-02
Virtual Gpu HIGH 7.8
CVE-2023-31016

NVIDIA GPU Display Driver for Windows contains a vulnerability where an uncontrolled search path element may allow an attacker to execute arbitrary c…

Fix: 13.9 / 15.4+
Fix from $1,950 2023-11-02
Netextender HIGH 7.3
CVE-2023-44220

SonicWall NetExtender Windows (32-bit and 64-bit) client 10.2.336 and earlier versions have a DLL Search Order Hijacking vulnerability in the start-u…

Fix: after 10.2.336
Fix from $1,950 2023-10-27
Displaylink MEDIUM 6.7
CVE-2023-4936

It is possible to sideload a compromised DLL during the installation at elevated privilege.

Fix: 11.2+
Fix from $1,600 2023-10-11
Xdppro HIGH 7.8
CVE-2023-5463

A vulnerability was found in XINJE XDPPro up to 3.7.17a. It has been rated as critical. Affected by this issue is some unknown functionality in the l…

Fix: after 3.7.17a
Fix from $1,950 2023-10-09
Agent HIGH 7.3
CVE-2023-45248

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) befor…

Mitigation only
Fix from $1,950 2023-10-09
Storage Protect HIGH 7.8
CVE-2023-35897

IBM Spectrum Protect Client and IBM Storage Protect for Virtual Environments 8.1.0.0 through 8.1.19.0 could allow a local user to execute arbitrary c…

Fix: after 8.1.19.0
Fix from $1,950 2023-10-06