Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
Advanced Installer HIGH 7.8
CVE-2022-4956

A vulnerability classified as critical has been found in Caphyon Advanced Installer 19.7. This affects an unknown part of the component WinSxS DLL Ha…

No fix yet
Fix from $1,950 2023-09-30
Memory Card \& Ufd Authentication HIGH 7.3
CVE-2023-41929

A DLL hijacking vulnerability in Samsung Memory Card & UFD Authentication Utility PC Software before 1.0.1 could allow a local attacker to escalate p…

Fix: 1.0.1+
Fix from $1,950 2023-09-18
Secureconnector HIGH 7.8
CVE-2023-39374

ForeScout NAC SecureConnector version 11.2 - CWE-427: Uncontrolled Search Path Element

Mitigation only
Fix from $1,950 2023-09-03
Splunk HIGH 8.8
CVE-2023-40596

In Splunk Enterprise versions earlier than 8.2.12, 9.0.6, and 9.1.1, a dynamic link library (DLL) that ships with Splunk Enterprise references an ins…

Fix: 8.2.12 / 9.0.6+
Fix from $1,950 2023-08-30
Nessus MEDIUM 6.5
CVE-2023-3252

An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges could alter logging variables to o…

Fix: 10.6.0+
Fix from $1,600 2023-08-29
Safe Connect HIGH 7.2
CVE-2023-40352

McAfee Safe Connect before 2.16.1.126 may allow an adversary with system privileges to achieve privilege escalation by loading arbitrary DLLs.

Fix: 2.16.1.126+
Fix from $1,950 2023-08-21
Universal Device Client HIGH 7.8
CVE-2023-3078

An uncontrolled search path vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local access to …

Fix: 23.4+
Fix from $1,950 2023-08-17
2zn49a Firmware HIGH 7.3
CVE-2022-4894

Certain HP and Samsung Printer software packages may potentially be vulnerable to elevation of privilege due to Uncontrolled Search Path Element.

Mitigation only
Fix from $1,950 2023-08-16
Integrated Bmc Video Driver HIGH 7.3
CVE-2023-34355

Uncontrolled search path element for some Intel(R) Server Board M10JNP2SB integrated BMC video drivers before version 3.0 for Microsoft Windows and b…

Fix: 1.13.4 / 3.0+
Fix from $1,950 2023-08-11
Platform Service Record Software Development Kit HIGH 7.8
CVE-2023-29151

Uncontrolled search path element in some Intel(R) PSR SDK before version 1.0.0.20 may allow an authenticated user to potentially enable escalation of…

Fix: 1.0.0.20+
Fix from $1,950 2023-08-11
Advisor For Oneapi HIGH 7.3
CVE-2023-28823

Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow an authenticated user t…

Fix: 1.19.1 / 2023.1+
Fix from $1,950 2023-08-11
Ai Hackathon HIGH 8.8
CVE-2023-28380

Uncontrolled search path for the Intel(R) AI Hackathon software before version 2.0.0 may allow an unauthenticated user to potentially enable escalati…

Fix: 2.0.0+
Fix from $1,950 2023-08-11
Openvino HIGH 7.8
CVE-2023-28405

Uncontrolled search path in the Intel(R) Distribution of OpenVINO(TM) Toolkit before version 2022.3.0 may allow an authenticated user to potentially …

Fix: 2022.3.0+
Fix from $1,950 2023-08-11
Vcust Tool HIGH 7.8
CVE-2023-25944

Uncontrolled search path element in some Intel(R) VCUST Tool software downloaded before February 3nd 2023 may allow an authenticated user to potentia…

Fix: 2023-02-03+
Fix from $1,950 2023-08-11
Ite Tech Consumer Infrared Driver HIGH 7.3
CVE-2023-23577

Uncontrolled search path element for some ITE Tech consumer infrared drivers before version 5.5.2.1 for Intel(R) NUC may allow an authenticated user …

Fix: 5.5.2.1+
Fix from $1,950 2023-08-11
Quartus Prime HIGH 7.3
CVE-2023-24016

Uncontrolled search path element in some Intel(R) Quartus(R) Prime Pro and Standard edition software for linux may allow an authenticated user to pot…

Fix: 22.1std / 22.4+
Fix from $1,950 2023-08-11
Unite HIGH 7.8
CVE-2023-25182

Uncontrolled search path element in the Intel(R) Unite(R) Client software for Mac before version 4.2.11 may allow an authenticated user to potentiall…

Fix: 4.2.11+
Fix from $1,950 2023-08-11
Server Firmware Update Utility HIGH 7.3
CVE-2023-22841

Unquoted search path in the software installer for the System Firmware Update Utility (SysFwUpdt) for some Intel(R) Server Boards and Intel(R) Server…

Fix: 16.0.7+
Fix from $1,950 2023-08-11
Rapid Storage Technology HIGH 7.8
CVE-2022-43456

Uncontrolled search path in some Intel(R) RST software before versions 16.8.5.1014.5, 17.11.3.1010.2, 18.7.6.1011.2 and 19.5.2.1049.5 may allow an au…

Fix: 16.8.5.1014.5 / 17.11.3.1010.2+
Fix from $1,950 2023-08-11
Oneapi Math Kernel Library HIGH 7.8
CVE-2022-25864

Uncontrolled search path in some Intel(R) oneMKL software before version 2022.0 may allow an authenticated user to potentially enable escalation of p…

Fix: 2022.0+
Fix from $1,950 2023-08-11
Service Studio HIGH 7.8
CVE-2022-47636

A DLL hijacking vulnerability has been discovered in OutSystems Service Studio 11 11.53.30 build 61739. When a user open a .oml file (OutSystems Mode…

No fix yet
Fix from $1,950 2023-08-10
Vynamic View HIGH 7.8
CVE-2023-36344

An issue in Diebold Nixdorf Vynamic View Console v.5.3.1 and before allows a local attacker to execute arbitrary code via not restricting the search …

Fix: after 5.3.1
Fix from $1,950 2023-08-08
Software Center HIGH 7.8
CVE-2021-41544

A vulnerability has been identified in Siemens Software Center (All versions < V3.0). A DLL Hijacking vulnerability could allow a local attacker to e…

Fix: 3.0+
Fix from $1,950 2023-08-08
Businessobjects Business Intelligence CRITICAL 9.0
CVE-2023-37490

SAP Business Objects Installer - versions 420, 430, allows an authenticated attacker within the network to overwrite an executable file created in a …

Mitigation only
Fix from $2,300 2023-08-08
Development System HIGH 7.3
CVE-2023-3662

In CODESYS Development System versions from 3.5.17.0 and prior to 3.5.19.20 a vulnerability allows for execution of binaries from the current working…

Fix: 3.5.19.20+
Fix from $1,950 2023-08-03
Arm Development Studio HIGH 7.8
CVE-2022-43703

An installer that loads or executes files using an unconstrained search path may be vulnerable to substitute files under control of an attacker being…

Fix: after 5.29.3
Fix from $1,950 2023-07-27
Geolocation Server HIGH 7.8
CVE-2023-36853

​In Keysight Geolocation Server v2.4.2 and prior, a low privileged attacker could create a local ZIP file containing a malicious script in any locati…

Fix: after 2.4.2
Fix from $1,950 2023-07-19
Panda Security Vpn MEDIUM 6.5
CVE-2023-37849

A DLL hijacking vulnerability in Panda Security VPN for Windows prior to version v15.14.8 allows attackers to execute arbitrary code via placing a cr…

Fix: 15.14.8+
Fix from $1,600 2023-07-13
Pipreqs CRITICAL 9.8
CVE-2023-31543

A dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted PyPI package to the chosen rep…

Fix: after 0.4.11
Fix from $2,300 2023-06-30
Antivirus\+ Security 2021 HIGH 7.8
CVE-2023-28929

Trend Micro Security 2021, 2022, and 2023 (Consumer) are vulnerable to a DLL Hijacking vulnerability which could allow an attacker to use a specific …

Fix: after 17.7.1476
Fix from $1,950 2023-06-26