Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
Radeon Software HIGH 7.8
CVE-2024-36333

A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potentially resulting in arbitrary c…

Fix: 25.q3.1 / 26.q1+
Fix from $1,950 2026-05-15
Unclassified HIGH 8.5
CVE-2026-7373

Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows a user to gain SYSTEM level control of a Windows host. When st…

Mitigation only
Fix from $1,950 2026-05-15
Unclassified HIGH 7.0
CVE-2025-62628

Unsafe OpenSSL initialization within some AMD optional tools may allow a local user-privileged attacker to inject a malicious DLL, potentially result…

Mitigation only
Fix from $1,950 2026-05-14
Checkmk HIGH 7.8
CVE-2024-47091

Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk <2.4.0p29, <2.3.0p47, and 2.2.0 (EOL) allows a local unprivileged user able t…

Mitigation only
Fix from $1,950 2026-05-13
Unclassified HIGH 7.8
CVE-2026-44612

Bytello Share (Windows Edition) installer executable provided by Bytello insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the sa…

Mitigation only
Fix from $1,950 2026-05-13
Connectivity Performance Suite MEDIUM 6.7
CVE-2026-20772

Uncontrolled search path for some Intel(R) Connectivity Performance Suite software installers before version 50.25.1121.193 within Ring 3: User Appli…

Fix: 50.25.1121.193+
Fix from $1,600 2026-05-12
Unclassified MEDIUM 5.4
CVE-2025-36515

Uncontrolled search path for some AI Playground software before version 3.0.0 alpha within Ring 3: User Applications may allow an escalation of privi…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified MEDIUM 5.4
CVE-2025-35969

Uncontrolled search path for some Intel(R) Server Firmware Update Utility Software before version 16.0.12. within Ring 3: User Applications may allow…

Mitigation only
Fix from $1,600 2026-05-12
Openclaw HIGH 7.8
CVE-2026-45004

OpenClaw before 2026.4.23 contains an arbitrary code execution vulnerability in the bundled plugin setup resolver that loads setup-api.js from proces…

Fix: 2026.4.23+
Fix from $1,950 2026-05-11
Unclassified CRITICAL 9.8
CVE-2025-69599

RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control the value of the PATH environment variable. NOTE: th…

Mitigation only
Fix from $2,300 2026-05-08
Zxcloud Irai HIGH 7.8
CVE-2026-44406

ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijac…

Fix: 7.25.43+
Fix from $1,950 2026-05-07
Zxcloud Irai HIGH 7.8
CVE-2026-40004

There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execute arbitrary code locally and …

Fix: 7.25.43+
Fix from $1,950 2026-05-07
Unclassified HIGH 8.4
CVE-2026-21661

Uncontrolled Search Path Element vulnerability in JohnsonControls AC2000 on Windows allows Leveraging/Manipulating Configuration File Search Paths. …

Mitigation only
Fix from $1,950 2026-05-06
Agent HIGH 7.8
CVE-2026-6788

Uncontrolled Search Path Element vulnerability in WatchGuard Agent on Windows allows Using Malicious Files.

Fix: 1.25.03.0000+
Fix from $1,950 2026-05-06
Unclassified MEDIUM 6.7
CVE-2026-25852

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0…

Mitigation only
Fix from $1,600 2026-04-29
Openclaw MEDIUM 6.1
CVE-2026-41373

OpenClaw before 2026.3.31 contains an incomplete host-env-security-policy.json that fails to restrict compiler binary environment variables, allowing…

Fix: 2026.3.31+
Fix from $1,600 2026-04-28
Unclassified HIGH 7.8
CVE-2026-7279

AVACAST developed by eMPIA Technology, has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a malicious DLL in a specif…

Mitigation only
Fix from $1,950 2026-04-28
Nullsoft Scriptable Install System HIGH 7.8
CVE-2026-42171

NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attack…

Fix: 3.12+
Fix from $1,950 2026-04-24
Power Apps HIGH 8.0
CVE-2026-32172

Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network.

Mitigation only
Fix from $1,950 2026-04-23
Unclassified HIGH 7.3
CVE-2026-34488

IP Setting Software contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary c…

Mitigation only
Fix from $1,950 2026-04-23
Unclassified MEDIUM 5.1
CVE-2025-10549

EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the installation directory. A local…

Mitigation only
Fix from $1,600 2026-04-23
Canonnwcamplugin.exe HIGH 7.8
CVE-2026-32679

The installers of LiveOn Meet Client for Windows (Downloader5Installer.exe and Downloader5InstallerForAdmin.exe) and the installers of Canon Network …

Mitigation only
Fix from $1,950 2026-04-23
Firebird CRITICAL 9.9
CVE-2026-40342

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader con…

Fix: 3.0.14 / 4.0.7+
Fix from $2,300 2026-04-17
Unclassified HIGH 7.0
CVE-2026-6421

A vulnerability has been found in Mobatek MobaXterm Home Edition up to 26.1. This affects an unknown part in the library msimg32.dll. The manipulatio…

Mitigation only
Fix from $1,950 2026-04-17
Intelligent Power Protector CRITICAL 9.9
CVE-2026-22619

Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to arbitrary code execution by an…

Fix: 2.00+
Fix from $2,300 2026-04-16
Photoshop Installer HIGH 8.6
CVE-2026-34632

Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in t…

No fix yet
Fix from $1,950 2026-04-15
Unclassified MEDIUM 6.7
CVE-2026-1636

A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a local authenticated user …

Mitigation only
Fix from $1,600 2026-04-15
Unclassified HIGH 7.3
CVE-2026-4134

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local…

Mitigation only
Fix from $1,950 2026-04-15
Unclassified HIGH 7.8
CVE-2026-5397

It has been identified that a vulnerability (CWE-427) exists in the UPS (Uninterruptible Power Supply) management application, whereby improper permi…

Mitigation only
Fix from $1,950 2026-04-15
Nomachine HIGH 7.8
CVE-2026-5055

NoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges…

Fix: 9.4.14+
Fix from $1,950 2026-04-11