Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
Dialink HIGH 7.8
CVE-2021-38416

Delta Electronics DIALink versions 1.2.4.0 and prior insecurely loads libraries, which may allow an attacker to use DLL hijacking and takeover the sy…

Fix: after 1.2.4.0
Fix from $1,950 2021-11-03
Dialink HIGH 7.8
CVE-2021-38420

Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged user accounts, which may allow …

Fix: after 1.2.4.0
Fix from $1,950 2021-11-03
Installbuilder HIGH 7.8
CVE-2021-22037

Under certain circumstances, when manipulating the Windows registry, InstallBuilder uses the reg.exe system command. The full path to the command is …

Fix: 21.6.0+
Fix from $1,950 2021-10-29
Harmony Browse HIGH 7.8
CVE-2021-30359

The Harmony Browse and the SandBlast Agent for Browsers installers must have admin privileges to execute some steps during the installation. Because …

Fix: 90.08.7405+
Fix from $1,950 2021-10-22
Versiondog HIGH 7.1
CVE-2021-38469

Many of the services used by the affected product do not specify full paths for the DLLs they are loading. An attacker can exploit the uncontrolled s…

Fix: 8.0.0+
Fix from $1,950 2021-10-22
Apex One HIGH 7.8
CVE-2021-42101

An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privil…

Patch available
Fix from $1,950 2021-10-21
Apex One HIGH 7.8
CVE-2021-42102

An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service agents could allow a local attacker to escalate…

Patch available
Fix from $1,950 2021-10-21
Apex One HIGH 7.8
CVE-2021-42103

An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privil…

Patch available
Fix from $1,950 2021-10-21
Acrobat Dc HIGH 7.3
CVE-2021-35982

Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Uncontrolle…

Fix: after 21.005.20060
Fix from $1,950 2021-09-29
Housecall For Home Networks HIGH 7.0
CVE-2021-32466

An uncontrolled search path element privilege escalation vulnerability in Trend Micro HouseCall for Home Networks version 5.3.1225 and below could al…

Fix: after 5.3.1225
Fix from $1,950 2021-09-29
Armoury Crate Lite Service HIGH 7.3
CVE-2021-40981

ASUS ROG Armoury Crate Lite before 4.2.10 allows local users to gain privileges by placing a Trojan horse file in the publicly writable %PROGRAMDATA%…

Fix: 4.2.10+
Fix from $1,950 2021-09-27
Security Space HIGH 7.8
CVE-2021-28130

Dr.Web Firewall 12.5.2.4160 on Windows incorrectly restricts applications signed by Dr.Web. A DLL for a custom payload within a legitimate binary (e.…

No fix yet
Fix from $1,950 2021-09-24
Panda Adaptive Defense 360 HIGH 7.8
CVE-2021-26750

DLL hijacking in Panda Agent <=1.16.11 in Panda Security, S.L.U. Panda Adaptive Defense 360 <= 8.0.17 allows attacker to escalate privileges via mali…

Fix: after 8.0.17
Fix from $1,950 2021-09-23
Agent HIGH 7.8
CVE-2021-31847

Improper access control vulnerability in the repair process for McAfee Agent for Windows prior to 5.7.4 could allow a local attacker to perform a DLL…

Fix: 5.7.4+
Fix from $1,950 2021-09-22
Line HIGH 7.8
CVE-2021-36216

LINE for Windows 6.2.1.2289 and before allows arbitrary code execution via malicious DLL injection.

Fix: after 6.2.1.2289
Fix from $1,950 2021-09-08
Creative Cloud HIGH 7.3
CVE-2021-28581

Adobe Creative Cloud Desktop 3.5 (and earlier) is affected by an uncontrolled search path vulnerability that could result in elevation of privileges.…

Fix: after 5.3
Fix from $1,950 2021-09-08
Gp Pro Ex HIGH 7.8
CVE-2021-22775

A CWE-427: Uncontrolled Search Path Element vulnerability exists in GP-Pro EX,V4.09.250 and prior, that could cause local code execution with elevate…

Fix: after 4.09.250
Fix from $1,950 2021-09-02
Audio Usb Driver HIGH 7.8
CVE-2021-20793

Untrusted search path vulnerability in the installer of Sony Audio USB Driver V1.10 and prior and the installer of HAP Music Transfer Ver.1.3.0 and p…

Fix: after 1.10
Fix from $1,950 2021-08-26
Creative Cloud Desktop Application HIGH 7.8
CVE-2021-28594

Adobe Creative Cloud Desktop Application (installer) version 2.4 (and earlier) is affected by an Uncontrolled Search Path Element vulnerability. An u…

Fix: 2.5+
Fix from $1,950 2021-08-24
Acrobat Dc HIGH 7.3
CVE-2021-28636

Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an Uncontrolle…

Fix: after 21.005.20054
Fix from $1,950 2021-08-20
Dimension HIGH 7.8
CVE-2021-28595

Adobe Dimension version 3.4 (and earlier) is affected by an Uncontrolled Search Path Element element. An unauthenticated attacker could leverage this…

Fix: after 3.4
Fix from $1,950 2021-08-20
Desktop HIGH 7.3
CVE-2021-37617

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. The Nextcloud Desktop Client invokes its uninstall…

Fix: 3.3.0+
Fix from $1,950 2021-08-18
Drivers Management HIGH 7.8
CVE-2021-3633

A DLL preloading vulnerability was reported in Lenovo Driver Management prior to version 2.9.0719.1104 that could allow privilege escalation.

Fix: 2.9.0719.1104+
Fix from $1,950 2021-08-17
Cyber Protect HIGH 7.8
CVE-2021-38086

Acronis Cyber Protect 15 for Windows prior to build 27009 and Acronis Agent for Windows prior to build 26226 allowed local privilege escalation via D…

Fix: 15+
Fix from $1,950 2021-08-12
Fedora HIGH 7.8
CVE-2021-36770

Encode.pm, as distributed in Perl through 5.34.0, allows local users to gain privileges via a Trojan horse Encode::ConfigLocal library (in the curren…

Fix: 3.12+
Fix from $1,950 2021-08-11
Foxit Reader HIGH 7.8
CVE-2021-38571

An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows DLL hijacking, aka CNVD-C-2021-68000 and CNVD-C-2021-68502.

Fix: 9.7.5.29616 / 10.1.4+
Fix from $1,950 2021-08-11
Avermedia Capture Card HIGH 7.8
CVE-2021-0160

Uncontrolled search path in some Intel(R) NUC Pro Chassis Element AverMedia Capture Card drivers before version 3.0.64.143 may allow an authenticated…

Fix: 3.0.64.143+
Fix from $1,950 2021-08-11
True Image HIGH 7.8
CVE-2021-32580

Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to DLL hijacking.

Mitigation only
Fix from $1,950 2021-08-05
Packet Tracer HIGH 7.3
CVE-2021-1593

A vulnerability in Cisco Packet Tracer for Windows could allow an authenticated, local attacker to perform a DLL injection attack on an affected devi…

Mitigation only
Fix from $1,950 2021-08-04
1password HIGH 7.8
CVE-2020-18173

A DLL injection vulnerability in 1password.dll of 1Password 7.3.712 allows attackers to execute arbitrary code.

No fix yet
Fix from $1,950 2021-07-26