Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
Snap Deploy HIGH 7.8
CVE-2022-30697

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 3640

Fix: 6+
Fix from $1,950 2022-05-16
Extreme Tuning Utility HIGH 7.3
CVE-2022-22139

Uncontrolled search path in the Intel(R) XTU software before version 7.3.0.33 may allow an authenticated user to potentially enable escalation of pri…

Fix: 7.3.0.33+
Fix from $1,950 2022-05-12
Acrobat Dc HIGH 7.3
CVE-2022-28247

Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an uncontrolled searc…

Fix: after 22.001.20085
Fix from $1,950 2022-05-11
Cortex Xdr Agent MEDIUM 6.7
CVE-2022-0025

A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local…

Fix: 7.7.1.62043+
Fix from $1,600 2022-05-11
Xd\/e Series Plc Program Tool HIGH 7.3
CVE-2021-34606

A vulnerability exists in XINJE XD/E Series PLC Program Tool in versions up to v3.5.1 that can allow an authenticated, local attacker to load a malic…

Fix: after 3.5.1
Fix from $1,950 2022-05-11
Splunk HIGH 7.8
CVE-2021-42743

A misconfiguration in the node default path allows for local privilege escalation from a lower privileged user to the Splunk user in Splunk Enterpris…

Fix: 8.1.1+
Fix from $1,950 2022-05-06
Big Ip Access Policy Manager HIGH 7.8
CVE-2022-28714

On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13…

Mitigation only
Fix from $1,950 2022-05-05
Global Vpn Client HIGH 7.8
CVE-2021-20051

SonicWall Global VPN Client 4.10.7.1117 installer (32-bit and 64-bit) and earlier versions have a DLL Search Order Hijacking vulnerability in one of …

Fix: after 4.10.7.1117
Fix from $1,950 2022-05-04
Gear Iconx Pc Manager HIGH 7.8
CVE-2022-28792

DLL hijacking vulnerability in Gear IconX PC Manager prior to version 2.1.220405.51 allows attacker to execute arbitrary code. The patch adds proper …

Fix: 2.1.220405.51+
Fix from $1,950 2022-05-03
Pcmanager HIGH 7.8
CVE-2022-0192

A DLL search path vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow privilege escalation.

Fix: 4.0.40.2175+
Fix from $1,950 2022-04-22
Git HIGH 7.8
CVE-2022-24765

Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untruste…

Fix: 2.35.2 / 13.4+
Fix from $1,950 2022-04-12
Visual Studio 2017 HIGH 7.8
CVE-2022-24767

GitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user account.

Fix: 2.35.2 / 15.9.46+
Fix from $1,950 2022-04-12
Simatic Energy Manager Basic HIGH 7.3
CVE-2022-23449

A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 U…

Fix: 7.3+
Fix from $1,950 2022-04-12
Smart Switch Pc HIGH 7.8
CVE-2022-27842

DLL hijacking vulnerability in Smart Switch PC prior to version 4.2.22022_4 allows attacker to execute abitrary code.

Fix: 4.2.22022_4+
Fix from $1,950 2022-04-11
Kies HIGH 7.8
CVE-2022-27843

DLL hijacking vulnerability in Kies prior to version 2.6.4.22014_2 allows attacker to execute abitrary code.

Fix: 2.6.4.22014_2+
Fix from $1,950 2022-04-11
Update HIGH 7.8
CVE-2022-28541

Uncontrolled search path element vulnerability in Samsung Update prior to version 3.0.77.0 allows attackers to execute arbitrary code as Samsung Upda…

Fix: 3.0.77.0+
Fix from $1,950 2022-04-11
Android Usb Driver Windows Installer HIGH 7.8
CVE-2022-28779

Uncontrolled search path element vulnerability in Samsung Android USB Driver windows installer program prior to version 1.7.50 allows attacker to exe…

Fix: 1.7.50+
Fix from $1,950 2022-04-11
T5 Firmware HIGH 7.3
CVE-2022-25154

A DLL hijacking vulnerability in Samsung portable SSD T5 PC software before 1.6.9 could allow a local attacker to escalate privileges. (An attacker m…

Fix: 1.6.9+
Fix from $1,950 2022-04-05
Diaenergie HIGH 7.8
CVE-2022-1098

Delta Electronics DIAEnergie (all versions prior to 1.8.02.004) are vulnerable to a DLL hijacking condition. When combined with the Incorrect Default…

Fix: 1.8.02.004+
Fix from $1,950 2022-04-01
Alienware Update HIGH 7.8
CVE-2022-24426

Dell Command | Update, Dell Update, and Alienware Update version 4.4.0 contains a Local Privilege Escalation Vulnerability in the Advanced Driver Res…

Patch available
Fix from $1,950 2022-04-01
Attachecase HIGH 7.8
CVE-2022-25348

Untrusted search path vulnerability in AttacheCase ver.4.0.2.7 and earlier allows an attacker to gain privileges and execute arbitrary code via a Tro…

Fix: after 4.0.2.7
Fix from $1,950 2022-03-31
Attachecase HIGH 7.8
CVE-2022-28128

Untrusted search path vulnerability in AttacheCase ver.3.6.1.0 and earlier allows an attacker to gain privileges and execute arbitrary code via a Tro…

Fix: after 3.6.1.0
Fix from $1,950 2022-03-31
Sandisk Professional G Raid 4\/8 Software Utility HIGH 7.8
CVE-2022-22996

The G-RAID 4/8 Software Utility setups for Windows were affected by a DLL hijacking vulnerability. Successful exploitation could lead to arbitrary co…

Fix: 6.2.0.16-2 / 300520006-2+
Fix from $1,950 2022-03-30
Synapse HIGH 7.3
CVE-2021-44226

Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\…

Fix: 3.7.0228.022817+
Fix from $1,950 2022-03-23
Epas Gtw Firmware MEDIUM 6.7
CVE-2020-25182

Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries. Uncontrolled loading of dynamic libraries …

Fix: 1.1.0+
Fix from $1,600 2022-03-18
Wps Office HIGH 7.8
CVE-2022-25969

The installer of WPS Office Version 10.8.0.6186 insecurely load VERSION.DLL (or some other DLLs), allowing an attacker to execute arbitrary code with…

Mitigation only
Fix from $1,950 2022-03-17
Wps Office HIGH 7.8
CVE-2022-26081

The installer of WPS Office Version 10.8.0.5745 insecurely load shcore.dll, allowing an attacker to execute arbitrary code with the privilege of the …

Mitigation only
Fix from $1,950 2022-03-17
Wps Presentation HIGH 7.8
CVE-2022-26511

WPS Presentation 11.8.0.5745 insecurely load d3dx9_41.dll when opening .pps files('current directory type' DLL loading).

Mitigation only
Fix from $1,950 2022-03-17
Fedora HIGH 7.8
CVE-2022-20001

fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary code execution. git repositories can contain per-re…

Fix: after 3.3.1
Fix from $1,950 2022-03-14
Centum Cs 3000 Firmware HIGH 7.8
CVE-2022-23401

The following Yokogawa Electric products contain insecure DLL loading issues. CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions f…

Mitigation only
Fix from $1,950 2022-03-11