Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
Portable Security MEDIUM 6.5
CVE-2022-26319

An installer search patch element vulnerability in Trend Micro Portable Security 3.0 Pro, 3.0 and 2.0 could allow a local attacker to place an arbitr…

Fix: 2.0.8056 / 3.0.5054+
Fix from $1,600 2022-03-08
Password Manager HIGH 7.8
CVE-2022-26337

Trend Micro Password Manager (Consumer) installer version 5.0.0.1262 and below is vulnerable to an Uncontrolled Search Path Element vulnerability tha…

Fix: 5.0.0.1266+
Fix from $1,950 2022-03-08
Tools MEDIUM 6.7
CVE-2022-22943

VMware Tools for Windows (11.x.y and 10.x.y prior to 12.0.0) contains an uncontrolled search path vulnerability. A malicious actor with local adminis…

Fix: 12.0.0+
Fix from $1,600 2022-03-03
Creative Cloud Desktop Application HIGH 7.0
CVE-2022-23202

Adobe Creative Cloud Desktop version 2.7.0.13 (and earlier) is affected by an Uncontrolled Search Path Element vulnerability that could result in arb…

Fix: after 2.7.0.13
Fix from $1,950 2022-02-16
Confluence Data Center HIGH 7.8
CVE-2021-43940

Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local syst…

Fix: 7.4.10 / 7.12.3+
Fix from $1,950 2022-02-15
Ip Utility HIGH 7.8
CVE-2022-23410

AXIS IP Utility before 4.18.0 allows for remote code execution and local privilege escalation by the means of DLL hijacking. IPUtility.exe would atte…

Fix: 4.18.0+
Fix from $1,950 2022-02-14
Kate HIGH 7.8
CVE-2022-23853

The LSP (Language Server Protocol) plugin in KDE Kate before 21.12.2 and KTextEditor before 5.91.0 tries to execute the associated LSP server binary …

Fix: 5.91.0 / 21.12.2+
Fix from $1,950 2022-02-11
Vss Doctor HIGH 7.8
CVE-2022-0483

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis VSS Doctor (Windows) before build 53

Mitigation only
Fix from $1,950 2022-02-11
Pdf Reader CRITICAL 9.8
CVE-2022-24955

Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files.

Fix: after 11.2.0.53415
Fix from $2,300 2022-02-11
Adaptive Server Enterprise HIGH 7.8
CVE-2022-22528

SAP Adaptive Server Enterprise (ASE) - version 16.0, installation makes an entry in the system PATH environment variable in Windows platform which, u…

Mitigation only
Fix from $1,950 2022-02-09
Graphics Performance Analyzers HIGH 7.8
CVE-2021-33101

Uncontrolled search path in the Intel(R) GPA software before version 21.2 may allow an authenticated user to potentially enable escalation of privile…

Fix: 21.2+
Fix from $1,950 2022-02-09
Amt Ac 8260 Firmware MEDIUM 6.7
CVE-2021-0169

Uncontrolled Search Path Element in software for Intel(R) PROSet/Wireless Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enabl…

Fix: 11.8.90 / 12.0.85+
Fix from $1,600 2022-02-09
True Image HIGH 7.3
CVE-2021-44205

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Home Office (Windows) befor…

Mitigation only
Fix from $1,950 2022-02-04
True Image HIGH 7.3
CVE-2021-44206

Local privilege escalation due to DLL hijacking vulnerability in Acronis Media Builder service. The following products are affected: Acronis Cyber Pr…

Mitigation only
Fix from $1,950 2022-02-04
Radeon Pro Software HIGH 7.8
CVE-2020-12891

AMD Radeon Software may be vulnerable to DLL Hijacking through path variable. An unprivileged user may be able to drop its malicious DLL file in any …

Fix: 21.q2 / 21.4.1+
Fix from $1,950 2022-02-04
Deltav HIGH 7.3
CVE-2021-44463

Missing DLLs, if replaced by an insider, could allow an attacker to achieve local privilege escalation on the DeltaV Distributed Control System Contr…

Mitigation only
Fix from $1,950 2022-01-28
Agent HIGH 7.8
CVE-2022-0166

A privilege escalation vulnerability in the McAfee Agent prior to 5.7.5. McAfee Agent uses openssl.cnf during the build process to specify the OPENSS…

Fix: 5.7.5+
Fix from $1,950 2022-01-19
Cortex Xdr Agent HIGH 7.8
CVE-2022-0015

A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authenticated local user to execute…

Fix: 5.0.12 / 6.1.9+
Fix from $1,950 2022-01-12
Techcheck MEDIUM 6.7
CVE-2022-0129

Uncontrolled search path element vulnerability in McAfee TechCheck prior to 4.0.0.2 allows a local administrator to load their own Dynamic Link Libra…

Fix: 4.0.0.2+
Fix from $1,600 2022-01-11
Fedora HIGH 8.6
CVE-2022-21668

pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in pipenv's parsing of requiremen…

Fix: 2022.1.8+
Fix from $1,950 2022-01-10
Endpoint Security HIGH 7.8
CVE-2021-30360

Users have access to the directory where the installation repair occurs. Since the MS Installer allows regular users to run the repair, an attacker c…

No fix yet
Fix from $1,950 2022-01-10
Insight Agent HIGH 7.8
CVE-2021-4007

Rapid7 Insight Agent, versions 3.0.1 to 3.1.2.34, suffer from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when…

Fix: 3.1.2.35+
Fix from $1,950 2021-12-14
Global Vpn Client HIGH 7.8
CVE-2021-20047

SonicWall Global VPN client version 4.10.6 (32-bit and 64-bit) and earlier have a DLL Search Order Hijacking vulnerability. Successful exploitation v…

Fix: after 4.10.6
Fix from $1,950 2021-12-08
Unitrends Backup HIGH 7.8
CVE-2021-43037

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Unitrends Windows agent was vulnerable to DLL injection and binary pl…

Fix: 10.5.5+
Fix from $1,950 2021-12-06
Forticlient HIGH 7.8
CVE-2021-32592

An unsafe search path vulnerability in FortiClientWindows 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x and FortiClientEMS 7.0.0, 6.4.6 and below, 6.2.x, 6.0.…

Fix: 6.4.7+
Fix from $1,950 2021-12-01
Cyber Protect HIGH 7.8
CVE-2021-44198

DLL hijacking could lead to local privilege escalation. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035

Fix: 15+
Fix from $1,950 2021-11-29
Agent MEDIUM 5.5
CVE-2021-44199

DLL hijacking could lead to denial of service. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Ag…

Fix: 15+
Fix from $1,600 2021-11-29
Ax210 Firmware HIGH 7.8
CVE-2021-0082

Uncontrolled search path in software installer for Intel(R) PROSet/Wireless WiFi in Windows 10 may allow an authenticated user to potentially enable …

Fix: 22.40+
Fix from $1,950 2021-11-17
Antilles HIGH 8.8
CVE-2021-3840

A dependency confusion vulnerability was reported in the Antilles open-source software prior to version 1.0.1 that could allow for remote code execut…

Fix: 1.0.1+
Fix from $1,950 2021-11-12
Drive Encryption HIGH 7.8
CVE-2021-31853

DLL Search Order Hijacking Vulnerability in McAfee Drive Encryption (MDE) prior to 7.3.0 HF2 (7.3.0.183) allows local users to execute arbitrary code…

Fix: after 7.2.10
Fix from $1,950 2021-11-10