Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
Mpi Library HIGH 7.3
CVE-2022-26052

Uncontrolled search path element in the Intel(R) MPI Library before version 2021.6 for Intel(R) oneAPI HPC Toolkit may allow an authenticated user to…

Fix: 2021.6+
Fix from $1,950 2023-02-16
Trace Analyzer And Collector HIGH 7.3
CVE-2022-26062

Uncontrolled search path element in the Intel(R) Trace Analyzer and Collector before version 2021.6 for Intel(R) oneAPI HPC Toolkit may allow an auth…

Fix: 2021.6+
Fix from $1,950 2023-02-16
Oneapi Deep Neural Network HIGH 7.3
CVE-2022-26076

Uncontrolled search path element in the Intel(R) oneAPI Deep Neural Network (oneDNN) before version 2022.1 may allow an authenticated user to potenti…

Fix: 2022.1+
Fix from $1,950 2023-02-16
Genymotion Desktop HIGH 7.8
CVE-2022-48077

Genymotion Desktop v3.3.2 was discovered to contain a DLL hijacking vulnerability that allows attackers to escalate privileges and execute arbitrary …

Mitigation only
Fix from $1,950 2023-02-13
Checkmk HIGH 7.8
CVE-2022-43440

Uncontrolled Search Path Element in Checkmk Agent in Tribe29 Checkmk before 2.1.0p1, before 2.0.0p25 and before 1.6.0p29 on a Checkmk server allows t…

Fix: 1.6.0+
Fix from $1,950 2023-02-09
Geforce Experience HIGH 7.3
CVE-2022-31611

NVIDIA GeForce Experience contains an uncontrolled search path vulnerability in all its client installers, where an attacker with user level privileg…

Fix: 3.27.0.112+
Fix from $1,950 2023-02-07
Oneapi Dpc\+\+\/c\+\+ Compiler HIGH 7.3
CVE-2022-38136

Uncontrolled search path in the Intel(R) oneAPI DPC++/C++ Compiler for Windows and Intel Fortran Compiler for Windows before version 2022.2.1 for som…

Fix: 2022.2.1+
Fix from $1,950 2023-02-06
Data Loss Prevention HIGH 8.2
CVE-2023-0400

The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local user to bypass DLP controls when …

Fix: 11.10.0+
Fix from $1,950 2023-02-02
Big Ip Access Policy Manager HIGH 7.8
CVE-2023-22358

In versions beginning with 7.2.2 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client Windows Installer. Note: Software…

Fix: 7.2.3.1 / 17.0.0.2+
Fix from $1,950 2023-02-01
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2023-22283

On versions beginning in 7.1.5 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client for Windows. User interaction and ad…

Fix: 7.2.3.1 / 17.0.0.2+
Fix from $1,600 2023-02-01
Openmanage Server Administrator HIGH 7.8
CVE-2022-34396

Dell OpenManage Server Administrator (OMSA) version 10.3.0.0 and earlier contains a DLL Injection Vulnerability. A local low privileged authenticated…

Fix: after 10.3.0.0
Fix from $1,950 2023-02-01
Synapse MEDIUM 6.8
CVE-2022-47632

Razer Synapse before 3.7.0830.081906 allows privilege escalation due to an unsafe installation path, improper privilege management, and improper cert…

Fix: 3.7.0830.081906+
Fix from $1,600 2023-01-27
Windscribe HIGH 7.8
CVE-2022-41141

This vulnerability allows local attackers to escalate privileges on affected installations of Windscribe. An attacker must first obtain the ability t…

Mitigation only
Fix from $1,950 2023-01-26
Endpoint Detection And Response HIGH 7.8
CVE-2020-25502

Cybereason EDR version 19.1.282 and above, 19.2.182 and above, 20.1.343 and above, and 20.2.X and above has a DLL hijacking vulnerability, which coul…

Fix: 19.1.282 / 19.2.182+
Fix from $1,950 2023-01-20
Bloom HIGH 7.8
CVE-2023-0247

Uncontrolled Search Path Element in GitHub repository bits-and-blooms/bloom prior to 3.3.1.

Fix: 3.3.1+
Fix from $1,950 2023-01-12
Service Provider HIGH 7.3
CVE-2023-22947

Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an unprivileged local attacker to…

Fix: 3.4.1+
Fix from $1,950 2023-01-11
Rooms HIGH 7.8
CVE-2022-36930

Zoom Rooms for Windows installers before version 5.13.0 contain a local privilege escalation vulnerability. A local low-privileged user could exploit…

Fix: 5.13.0+
Fix from $1,950 2023-01-09
Easy Chat Server HIGH 7.8
CVE-2022-44939

Efs Software Easy Chat Server Version 3.1 was discovered to contain a DLL hijacking vulnerability via the component TextShaping.dll. This vulnerabili…

No fix yet
Fix from $1,950 2023-01-06
Firefox MEDIUM 5.5
CVE-2022-36314

When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from…

Fix: 102.1 / 103.0+
Fix from $1,600 2022-12-22
Firefox HIGH 7.0
CVE-2022-22736

If Firefox was installed to a world-writable directory, a local privilege escalation could occur when Firefox searched the current directory for syst…

Fix: 96.0+
Fix from $1,950 2022-12-22
Baidunetdisk MEDIUM 6.7
CVE-2021-36631

Untrusted search path vulnerability in Baidunetdisk Version 7.4.3 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unsp…

Fix: after 7.4.3
Fix from $1,600 2022-12-22
Squirrel.windows HIGH 7.8
CVE-2022-46330

Squirrel.Windows is both a toolset and a library that provides installation and update functionality for Windows desktop applications. Installers gen…

Fix: after 2.0.1
Fix from $1,950 2022-12-21
Dwg Trueview HIGH 7.8
CVE-2022-42945

DWG TrueViewTM 2023 version has a DLL Search Order Hijacking vulnerability. Successful exploitation by a malicious attacker could result in remote co…

Mitigation only
Fix from $1,950 2022-12-19
Sicam Pas\/pqs HIGH 7.8
CVE-2022-43722

A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0). Affected software does not properly secure a folder containing library fi…

Fix: 7.0+
Fix from $1,950 2022-12-13
Google Search HIGH 7.8
CVE-2022-29580

There exists a path traversal vulnerability in the Android Google Search app. This is caused by the incorrect usage of uri.getLastPathSegment. A symb…

Fix: 13.41+
Fix from $1,950 2022-12-13
Fusion HIGH 7.8
CVE-2022-38395

HP Support Assistant uses HP Performance Tune-up as a diagnostic tool. HP Support Assistant uses Fusion to launch HP Performance Tune-up. It is possi…

Fix: 1.38.2601.0 / 9.11+
Fix from $1,950 2022-12-12
Agent MEDIUM 6.7
CVE-2022-3859

An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8. This allows an attacker with admin ac…

Fix: 5.7.8+
Fix from $1,600 2022-11-30
Total Protection HIGH 7.8
CVE-2022-43751

McAfee Total Protection prior to version 16.0.49 contains an uncontrolled search path element vulnerability due to the use of a variable pointing to …

Fix: 16.0.49+
Fix from $1,950 2022-11-23
I Access Client Solutions MEDIUM 6.7
CVE-2022-40746

IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the syste…

Fix: after 1.1.9.0
Fix from $1,600 2022-11-21
Smart Share HIGH 7.8
CVE-2022-45422

When LG SmartShare is installed, local privilege escalation is possible through DLL Hijacking attack. The LG ID is LVE-HOT-220005.

No fix yet
Fix from $1,950 2022-11-21