Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
Premiere Elements HIGH 7.8
CVE-2022-34235

Adobe Premiere Elements version 2020v20 (and earlier) is affected by an Uncontrolled Search Path Element which could lead to Privilege Escalation. An…

Fix: after 2020.20
Fix from $1,950 2022-08-11
Update HIGH 7.8
CVE-2022-36840

DLL hijacking vulnerability in Samsung Update Setup prior to version 2.2.9.50 allows attackers to execute arbitrary code.

Fix: 2.2.9.50+
Fix from $1,950 2022-08-05
Batch Management HIGH 7.8
CVE-2021-38410

AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled …

Mitigation only
Fix from $1,950 2022-07-27
Agent HIGH 7.3
CVE-2022-2313

A DLL hijacking vulnerability in the MA Smart Installer for Windows prior to 5.7.7, which allows local users to execute arbitrary code and obtain hig…

Fix: 5.7.7+
Fix from $1,950 2022-07-27
Beyond Compare HIGH 7.8
CVE-2022-36415

A DLL hijacking vulnerability exists in the uninstaller in Scooter Beyond Compare 1.8a through 4.4.2 before 4.4.3 when installed via the EXE installe…

Fix: 4.4.3+
Fix from $1,950 2022-07-23
Powerstore Command Line Interface HIGH 7.8
CVE-2022-32498

Dell EMC PowerStore, Versions prior to v3.0.0.0 contain a DLL Hijacking vulnerability in PSTCLI. A local attacker can potentially exploit this vulner…

Fix: 3.0.0.0-1732745+
Fix from $1,950 2022-07-21
Parallels Access HIGH 7.8
CVE-2022-34900

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.3 (39313) Agent. An attacker must …

Mitigation only
Fix from $1,950 2022-07-18
Parallels Access HIGH 7.8
CVE-2022-34901

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent. An attacker must …

Mitigation only
Fix from $1,950 2022-07-18
Parallels Access HIGH 7.8
CVE-2022-34902

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent. An attacker must …

Mitigation only
Fix from $1,950 2022-07-18
Showmypc HIGH 7.3
CVE-2021-42923

ShowMyPC 3606 on Windows suffers from a DLL hijack vulnerability. If an attacker overwrites the file %temp%\ShowMyPC\-ShowMyPC3606\wodVPN.dll, it wil…

Mitigation only
Fix from $1,950 2022-07-18
Node.js MEDIUM 5.3
CVE-2022-32222

A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default path for openssl.cnf that might…

Fix: 1.0 / 18.5.0+
Fix from $1,600 2022-07-14
Node.js HIGH 7.3
CVE-2022-32223

Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under certain conditions on Windows platforms.This vulnerability can be exploited if th…

Fix: 14.20.0 / 16.16.0+
Fix from $1,950 2022-07-14
Git HIGH 7.8
CVE-2022-29187

Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable…

Fix: 2.30.5 / 2.31.4+
Fix from $1,950 2022-07-12
Viscosity HIGH 7.8
CVE-2017-20123

A vulnerability was found in Viscosity 1.6.7. It has been classified as critical. This affects an unknown part of the component DLL Handler. The mani…

No fix yet
Fix from $1,950 2022-06-30
Xlpd HIGH 7.8
CVE-2022-33035

XLPD v7.0.0094 and below contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.

Fix: 7.0.0103+
Fix from $1,950 2022-06-29
Dev C\+\+ HIGH 7.8
CVE-2022-33036

A binary hijack in Embarcadero Dev-CPP v6.3 allows attackers to execute arbitrary code via a crafted .exe file.

No fix yet
Fix from $1,950 2022-06-29
Orwell Dev Cpp HIGH 7.8
CVE-2022-33037

A binary hijack in Orwell-Dev-Cpp v5.11 allows attackers to execute arbitrary code via a crafted .exe file.

Fix: after 5.11
Fix from $1,950 2022-06-29
Consumer Product Removal Tool HIGH 8.2
CVE-2022-1824

An uncontrolled search path vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local attacker to perform a…

Fix: 10.4.128+
Fix from $1,950 2022-06-20
Inno Setup HIGH 7.8
CVE-2017-20051

A vulnerability was found in InnoSetup Installer. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. Th…

No fix yet
Fix from $1,950 2022-06-16
Meetings HIGH 7.8
CVE-2022-22788

The Zoom Opener installer is downloaded by a user from the Launch meeting page, when attempting to join a meeting without having the Zoom Meeting Cli…

Fix: 5.10.3+
Fix from $1,950 2022-06-15
Cloud Explorer HIGH 7.8
CVE-2022-24077

Naver Cloud Explorer Beta allows the attacker to execute arbitrary code as System privilege via malicious DLL injection.

Mitigation only
Fix from $1,950 2022-06-13
Supportassist For Business Pcs HIGH 7.8
CVE-2022-29092

Dell SupportAssist Client Consumer versions (3.11.0 and versions prior) and Dell SupportAssist Client Commercial versions (3.2.0 and versions prior) …

Fix: after 3.11.0
Fix from $1,950 2022-06-10
Xampp HIGH 7.8
CVE-2017-20018

A vulnerability was found in XAMPP 7.1.1-0-VC14. It has been classified as problematic. Affected is an unknown function of the component Installer. T…

No fix yet
Fix from $1,950 2022-06-09
Kies HIGH 7.8
CVE-2022-30744

DLL hijacking vulnerability in KiesWrapper in Samsung Kies prior to version 2.6.4.22043_1 allows attacker to execute arbitrary code.

Fix: 2.6.4.22043_1+
Fix from $1,950 2022-06-07
Password Manager HIGH 7.8
CVE-2022-28394

EOL Product CVE - Installer of Trend Micro Password Manager (Consumer) versions 3.7.0.1223 and below provided by Trend Micro Incorporated contains an…

Fix: 3.7.0.1223+
Fix from $1,950 2022-05-27
Apex One HIGH 7.8
CVE-2022-30701

An uncontrolled search path element vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to craft a special c…

Fix: 14.0.10349+
Fix from $1,950 2022-05-27
Manageengine Applications Manager HIGH 7.2
CVE-2022-23050

ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the 'working…

Fix: 15.5+
Fix from $1,950 2022-05-24
Total Security HIGH 7.3
CVE-2022-31467

A DLL hijacking vulnerability in the installed for Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalati…

Fix: 12.1.1.27+
Fix from $1,950 2022-05-23
Premium Security MEDIUM 6.5
CVE-2022-28965

Multiple DLL hijacking vulnerabilities via the components instup.exe and wsc_proxy.exe in Avast Premium Security before v21.11.2500 allows attackers …

Fix: 21.11.2500+
Fix from $1,600 2022-05-20
Snap Deploy HIGH 7.8
CVE-2022-30696

Local privilege escalation due to a DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 3640

Fix: 6+
Fix from $1,950 2022-05-16