Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
Nessus HIGH 8.8
CVE-2023-2005

Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugin Feed ID #202306261202 ; Nes…

Mitigation only
Fix from $1,950 2023-06-26
Installer HIGH 7.8
CVE-2023-27908

A maliciously crafted DLL file can be forced to write beyond allocated boundaries in the Autodesk installer when parsing the DLL files and could lead…

Fix: 1.39.0.216+
Fix from $1,950 2023-06-23
Diskstation Manager Unified Controller HIGH 8.1
CVE-2023-0142

Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-4…

Fix: 1.3.1-9346 / 7.1-42661+
Fix from $1,950 2023-06-13
Agent HIGH 7.8
CVE-2023-0976

A command Injection Vulnerability in TA for mac-OS prior to version 5.7.9 allows local users to place an arbitrary file into the /Library/Trellix/Age…

Fix: 5.7.9+
Fix from $1,950 2023-06-07
Captura HIGH 7.8
CVE-2023-3091

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Captura up to 8.0.0. It has been declared as critical. This vulnerability affects unknow…

Fix: after 8.0.0
Fix from $1,950 2023-06-04
Powerpath HIGH 7.3
CVE-2023-28080

PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains DLL Hijacking Vulnerabilities. A regular user (non-admin) can exploit these issues to potenti…

Patch available
Fix from $1,950 2023-05-30
Infraworks HIGH 7.8
CVE-2023-25005

A maliciously crafted DLL file can be forced to read beyond allocated boundaries in Autodesk InfraWorks 2023, and 2021 when parsing the DLL files cou…

Fix: 2021.2 / 2023.1+
Fix from $1,950 2023-05-12
Free Password Manager HIGH 7.8
CVE-2023-25428

A DLL Hijacking issue discovered in Soft-o Free Password Manager 1.1.20 allows attackers to create arbitrary DLLs leading to code execution.

No fix yet
Fix from $1,950 2023-05-12
Trace Analyzer And Collector HIGH 7.8
CVE-2023-31197

Uncontrolled search path in the Intel(R) Trace Analyzer and Collector before version 2020 update 3 may allow an authenticated user to potentially ena…

Fix: 2020+
Fix from $1,950 2023-05-12
Wake Up Latency Tracer HIGH 8.8
CVE-2023-27298

Uncontrolled search path in the WULT software maintained by Intel(R) before version 1.0.0 (commit id 592300b) may allow an unauthenticated user to po…

Fix: 1.0.0+
Fix from $1,950 2023-05-10
Pathfinder For Risc V HIGH 7.3
CVE-2023-27386

Uncontrolled search path in some Intel(R) Pathfinder for RISC-V software may allow an authenticated user to potentially enable escalation of privileg…

Mitigation only
Fix from $1,950 2023-05-10
Advisor HIGH 7.8
CVE-2023-22355

Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user t…

Fix: 1.18.1 / 2023.0+
Fix from $1,950 2023-05-10
Dsp Builder HIGH 7.8
CVE-2022-43474

Uncontrolled search path for the DSP Builder software installer before version 22.4 for Intel(R) FPGAs Pro Edition may allow an authenticated user to…

Fix: 22.4+
Fix from $1,950 2023-05-10
Vtune Profiler HIGH 7.8
CVE-2022-41982

Uncontrolled search path element in the Intel(R) VTune(TM) Profiler software before version 2023.0 may allow an authenticated user to potentially ena…

Fix: 2023.0+
Fix from $1,950 2023-05-10
Data Center Manager HIGH 7.8
CVE-2022-41998

Uncontrolled search path in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privileg…

Fix: 5.1+
Fix from $1,950 2023-05-10
Quartus Prime HIGH 7.8
CVE-2022-41693

Uncontrolled search path in the Intel(R) Quartus(R) Prime Pro edition software before version 22.3 may allow an authenticated user to potentially ena…

Fix: 22.3+
Fix from $1,950 2023-05-10
Nuc P14e Laptop Element HIGH 7.8
CVE-2022-41628

Uncontrolled search path element in the HotKey Services for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.1.44 may a…

Fix: 1.1.44+
Fix from $1,950 2023-05-10
Nuc Pro Software Suite HIGH 7.8
CVE-2022-34848

Uncontrolled search path for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalat…

Fix: 2.0.0.3+
Fix from $1,950 2023-05-10
Iflashv HIGH 7.8
CVE-2022-38101

Uncontrolled search path in some Intel(R) NUC Chaco Canyon BIOS update software before version iFlashV Windows 5.13.00.2105 may allow an authenticate…

Fix: 5.13.00.2105+
Fix from $1,950 2023-05-10
Maccpuid HIGH 7.8
CVE-2022-27180

Uncontrolled search path in the Intel(R) MacCPUID software before version 3.2 may allow an authenticated user to potentially enable escalation of pri…

Fix: 3.2+
Fix from $1,950 2023-05-10
Unite HIGH 7.8
CVE-2022-32576

Uncontrolled search path in the Intel(R) Unite(R) Plugin SDK before version 4.2 may allow an authenticated user to potentially enable escalation of p…

Fix: 4.2+
Fix from $1,950 2023-05-10
Nuc Hdmi Firmware Update Tool HIGH 7.3
CVE-2022-21162

Uncontrolled search path for the Intel(R) HDMI Firmware Update tool for NUC before version 1.79.1.1 may allow an authenticated user to potentially en…

Fix: 1.79.1.1+
Fix from $1,950 2023-05-10
Cyberghost HIGH 7.8
CVE-2023-30237

CyberGhostVPN Windows Client before v8.3.10.10015 was discovered to contain a DLL injection vulnerability via the component Dashboard.exe.

Fix: 8.3.10.10015+
Fix from $1,950 2023-05-09
Snap Deploy HIGH 7.8
CVE-2023-2355

Local privilege escalation due to a DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 3900.

Fix: 6+
Fix from $1,950 2023-04-27
Git For Windows HIGH 7.8
CVE-2023-29011

Git for Windows, the Windows port of Git, ships with an executable called `connect.exe`, which implements a SOCKS5 proxy that can be used to connect …

Fix: 2.40.1+
Fix from $1,950 2023-04-25
Git For Windows HIGH 7.8
CVE-2023-29012

Git for Windows is the Windows port of Git. Prior to version 2.40.1, any user of Git CMD who starts the command in an untrusted directory is impacted…

Fix: 2.40.1+
Fix from $1,950 2023-04-25
Easergy Builder Installer MEDIUM 6.7
CVE-2022-34755

A CWE-427 - Uncontrolled Search Path Element vulnerability exists that could allow an attacker with a local privileged account to place a specially c…

Fix: after 1.7.23
Fix from $1,600 2023-04-18
Cloud Agent HIGH 7.0
CVE-2023-28140

An Executable Hijacking condition exists in the Qualys Cloud Agent for Windows platform in versions before 4.5.3.1. Attackers may load a malicious co…

Fix: 4.5.3.1+
Fix from $1,950 2023-04-18
Sapsetup MEDIUM 6.7
CVE-2023-29187

A Windows user with basic user authorization can exploit a DLL hijacking attack in SapSetup (Software Installation Program) - version 9.0, resulting …

Mitigation only
Fix from $1,600 2023-04-11
Acuant Acufill Sdk HIGH 7.8
CVE-2022-48222

An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. During SDK installation, certutil.exe is called by the Acuant installer to install …

Fix: 10.22.02.03+
Fix from $1,950 2023-04-04