Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
Acuant Acufill Sdk MEDIUM 6.7
CVE-2022-48223

An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. During SDK repair, certutil.exe is called by the Acuant installer to repair certifi…

Fix: 10.22.02.03+
Fix from $1,600 2023-04-04
Acuant Acufill Sdk HIGH 7.3
CVE-2022-48224

An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. It is installed with insecure permissions (full write access within Program Files).…

Fix: 10.22.02.03+
Fix from $1,950 2023-04-04
Acuant Acufill Sdk HIGH 7.3
CVE-2022-48225

An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. It is used to install drivers from several different vendors. The Gemalto Document …

Fix: 10.22.02.03+
Fix from $1,950 2023-04-04
Kmplayer HIGH 7.8
CVE-2023-1745

A vulnerability, which was classified as problematic, has been found in KMPlayer 4.2.2.73. This issue affects some unknown processing in the library …

No fix yet
Fix from $1,950 2023-03-30
Aveva Edge HIGH 7.8
CVE-2022-28686

This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). U…

Fix: 2020.2.00.40+
Fix from $1,950 2023-03-29
Aveva Edge HIGH 7.8
CVE-2022-28687

This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). U…

Fix: 2020.2.00.40+
Fix from $1,950 2023-03-29
Aveva Edge HIGH 7.8
CVE-2022-28688

This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). U…

Fix: 2020.2.00.40+
Fix from $1,950 2023-03-29
M Files HIGH 7.8
CVE-2023-0213

Elevation of privilege issue in M-Files Installer versions before 22.6 on Windows allows user to gain SYSTEM privileges via DLL hijacking.

Fix: 22.6+
Fix from $1,950 2023-03-29
Meetings HIGH 7.8
CVE-2023-28596

Zoom Client for IT Admin macOS installers before version 5.13.5 contain a local privilege escalation vulnerability. A local low-privileged user could…

Fix: 5.13.5+
Fix from $1,950 2023-03-27
Openoffice HIGH 7.8
CVE-2022-38745

Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code fro…

Fix: 4.1.14+
Fix from $1,950 2023-03-24
Netbackup HIGH 7.8
CVE-2023-28759

An issue was discovered in Veritas NetBackup before 10.0 on Windows. A vulnerability in the way the client validates the path to a DLL prior to loadi…

Fix: 10.0+
Fix from $1,950 2023-03-23
Document Server HIGH 7.8
CVE-2022-48422

ONLYOFFICE Docs through 7.3 on certain Linux distributions allows local users to gain privileges via a Trojan horse libgcc_s.so.1 in the current work…

Fix: after 7.3.0
Fix from $1,950 2023-03-19
Uwamp HIGH 7.8
CVE-2021-31637

An issue found in UwAmp v.1.1, 1.2, 1.3, 2.0, 2.1, 2.2, 2.2.1, 3.0.0, 3.0.1, 3.0.2 allows a remote attacker to execute arbitrary code via a crafted D…

Fix: after 3.0.2
Fix from $1,950 2023-03-16
Nessus HIGH 8.8
CVE-2022-4313

A vulnerability was reported where through modifying the scan variables, an authenticated user in Tenable products, that has Scan Policy Configuratio…

Fix: 10.4.2 / 202212081952+
Fix from $1,950 2023-03-15
Total Protection MEDIUM 5.5
CVE-2023-24578

McAfee Total Protection prior to 16.0.49 allows attackers to elevate user privileges due to DLL sideloading. This could enable a user with lower priv…

Fix: 16.0.49+
Fix from $1,600 2023-03-13
Apex One MEDIUM 6.7
CVE-2023-25147

An issue in the Trend Micro Apex One agent could allow an attacker who has previously acquired administrative rights via other means to bypass the pr…

Fix: 14.0.11960+
Fix from $1,600 2023-03-10
Apex One CRITICAL 9.8
CVE-2023-25143

An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker to achieve a remote code execu…

Fix: 14.0.11960+
Fix from $2,300 2023-03-10
Pg Ivm HIGH 8.8
CVE-2023-23554

Uncontrolled search path element vulnerability exists in pg_ivm versions prior to 1.5.1. When refreshing an IMMV, pg_ivm executes functions without s…

Fix: 1.5.1+
Fix from $1,950 2023-03-07
Afl\+\+ HIGH 7.3
CVE-2023-26266

In AFL++ 4.05c, the CmpLog component uses the current working directory to resolve and execute unprefixed fuzzing targets, allowing code execution.

Patch available
Fix from $1,950 2023-02-21
Bloxone Endpoint HIGH 7.8
CVE-2022-32972

Infoblox BloxOne Endpoint for Windows through 2.2.7 allows DLL injection that can result in local privilege escalation.

Fix: 2.3.3+
Fix from $1,950 2023-02-17
Quickassist Technology HIGH 7.3
CVE-2022-37340

Uncontrolled search path in some Intel(R) QAT drivers for Windows before version 1.6 may allow an authenticated user to potentially enable escalation…

Fix: 1.6 / 4.17+
Fix from $1,950 2023-02-16
Administrative Tools For Intel Network Adapters HIGH 7.8
CVE-2022-41314

Uncontrolled search path in some Intel(R) Network Adapter installer software may allow an authenticated user to potentially enable escalation of priv…

Fix: 4.01 / 27.3+
Fix from $1,950 2023-02-16
Fpga Software Development Kit HIGH 7.3
CVE-2022-37329

Uncontrolled search path in some Intel(R) Quartus(R) Prime Pro and Standard Edition software may allow an authenticated user to potentially enable es…

Fix: 21.1 / 21.3+
Fix from $1,950 2023-02-16
Battery Life Diagnostic Tool HIGH 7.8
CVE-2022-36398

Uncontrolled search path in the Intel(R) Battery Life Diagnostic Tool software before version 2.2.0 may allow an authenticated user to potentially en…

Mitigation only
Fix from $1,950 2023-02-16
Openmp HIGH 7.3
CVE-2022-26345

Uncontrolled search path element in the Intel(R) oneAPI Toolkit OpenMP before version 2022.1 may allow an authenticated user to potentially enable es…

Fix: 2022.1+
Fix from $1,950 2023-02-16
Oneapi Dpc\+\+\/c\+\+ Compiler Runtime HIGH 7.3
CVE-2022-26421

Uncontrolled search path element in the Intel(R) oneAPI DPC++/C++ Compiler Runtime before version 2022.0 may allow an authenticated user to potential…

Fix: 2022.0+
Fix from $1,950 2023-02-16
Oneapi Collective Communications Library HIGH 7.3
CVE-2022-26425

Uncontrolled search path element in the Intel(R) oneAPI Collective Communications Library (oneCCL) before version 2021.6 for Intel(R) oneAPI Base Too…

Fix: 2021.6+
Fix from $1,950 2023-02-16
Fpga Add On HIGH 7.3
CVE-2022-26512

Uncontrolled search path element in the Intel(R) FPGA Add-on for Intel(R) oneAPI Base Toolkit before version 2022.2 may allow an authenticated user t…

Fix: 2022.2+
Fix from $1,950 2023-02-16
Oneapi Data Analytics Library HIGH 7.3
CVE-2022-25905

Uncontrolled search path element in the Intel(R) oneAPI Data Analytics Library (oneDAL) before version 2021.5 for Intel(R) oneAPI Base Toolkit may al…

Fix: 2021.5+
Fix from $1,950 2023-02-16
Distribution For Python HIGH 7.3
CVE-2022-26032

Uncontrolled search path element in the Intel(R) Distribution for Python programming language before version 2022.1 for Intel(R) oneAPI Toolkits may …

Fix: 2022.1+
Fix from $1,950 2023-02-16