Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
C\/c\+\+ Advanced Lint HIGH 7.8
CVE-2021-28953

The unofficial C/C++ Advanced Lint extension before 1.9.0 for Visual Studio Code allows attackers to execute arbitrary binaries if the user opens a c…

Fix: 1.9.0+
Fix from $1,950 2021-03-21
Manageengine Desktop Central HIGH 7.8
CVE-2020-9367

The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 10.0.486 is vulnerable to DLL Hijacking: dcinventory.exe and dcconfig.exe try …

Mitigation only
Fix from $1,950 2021-03-18
Drivetools Add On Profiles HIGH 7.8
CVE-2021-22665

Rockwell Automation DriveTools SP v5.13 and below and Drives AOP v4.12 and below both contain a vulnerability that a local attacker with limited priv…

Fix: after 5.13
Fix from $1,950 2021-03-18
Block Safe Firmware HIGH 7.8
CVE-2020-26155

Multiple files and folders in Utimaco SecurityServer 4.20.0.4 and 4.31.1.0. are installed with Read/Write permissions for authenticated users, which …

Fix: after 4.33.0
Fix from $1,950 2021-03-18
Supportassist Client Promanage HIGH 7.8
CVE-2021-21518

Dell SupportAssist Client for Consumer PCs versions 3.7.x, 3.6.x, 3.4.x, 3.3.x, Dell SupportAssist Client for Business PCs versions 2.0.x, 2.1.x, 2.2…

Mitigation only
Fix from $1,950 2021-03-12
Magicconnect HIGH 7.8
CVE-2021-20674

Untrusted search path vulnerability in Installer of MagicConnect Client program distributed before 2021 March 1 allows an attacker to gain privileges…

Fix: 2021-03-01+
Fix from $1,950 2021-03-12
Owncloud Desktop Client HIGH 7.8
CVE-2020-28646

ownCloud owncloud/client before 2.7 allows DLL Injection. The desktop client loaded development plugins from certain directories when they were prese…

Fix: 2.7+
Fix from $1,950 2021-02-26
Anyconnect Secure Mobility Client HIGH 7.8
CVE-2021-1366

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, …

Fix: 4.9.05042+
Fix from $1,950 2021-02-17
Trace Analyzer And Collector HIGH 7.8
CVE-2020-24485

Improper conditions check in the Intel(R) FPGA OPAE Driver for Linux before kernel version 4.17 may allow an authenticated user to potentially enable…

Fix: 2020+
Fix from $1,950 2021-02-17
Optane Dc Persistent Memory Module Management HIGH 7.3
CVE-2020-24451

Uncontrolled search path in the Intel(R) Optane(TM) DC Persistent Memory installer for Windows* before version 1.00.00.3506 may allow an authenticate…

Fix: 1.00.00.3506+
Fix from $1,950 2021-02-17
Simatic Process Control System Neo HIGH 7.8
CVE-2020-25238

A vulnerability has been identified in PCS neo (Administration Console) (All versions < V3.1), TIA Portal (V15, V15.1 and V16). Manipulating certain …

Fix: 3.1+
Fix from $1,950 2021-02-09
True Image HIGH 7.8
CVE-2020-35145

Acronis True Image for Windows prior to 2021 Update 3 allowed local privilege escalation due to a DLL hijacking vulnerability in multiple components,…

Fix: after 2021
Fix from $1,950 2021-01-29
Housecall For Home Networks HIGH 7.8
CVE-2021-25247

A DLL hijacking vulnerability Trend Micro HouseCall for Home Networks version 5.3.1063 and below could allow an attacker to use a malicious DLL to es…

Mitigation only
Fix from $1,950 2021-01-27
Go HIGH 7.5
CVE-2021-3115EPSS 6%

Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to…

Fix: 1.14.14 / 1.15.7+
Fix from $1,950 2021-01-26
Advanced Malware Protection For Endpoints HIGH 7.3
CVE-2021-1280

A vulnerability in the loading mechanism of specific DLLs of Cisco Advanced Malware Protection (AMP) for Endpoints for Windows and Immunet for Window…

Fix: 7.3.3 / 7.3.12+
Fix from $1,950 2021-01-20
Animate HIGH 7.0
CVE-2021-21008

Adobe Animate version 21.0 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the cont…

Fix: after 21.0
Fix from $1,950 2021-01-13
Incopy HIGH 7.0
CVE-2021-21010

InCopy version 15.1.1 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary code executio…

Fix: after 15.1.3
Fix from $1,950 2021-01-13
Captivate HIGH 7.0
CVE-2021-21011

Adobe Captivate 2019 version 11.5.1.499 (and earlier) is affected by an uncontrolled search path element vulnerability that could lead to privilege e…

Fix: after 11.5.1.499
Fix from $1,950 2021-01-13
Illustrator HIGH 7.0
CVE-2021-21007

Adobe Illustrator version 25.0 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the …

Fix: after 25.0
Fix from $1,950 2021-01-13
Anyconnect Secure Mobility Client HIGH 7.8
CVE-2021-1237

A vulnerability in the Network Access Manager and Web Security Agent components of Cisco AnyConnect Secure Mobility Client for Windows could allow an…

Fix: 4.9.04043+
Fix from $1,950 2021-01-13
Proximity HIGH 7.3
CVE-2021-1240

A vulnerability in the loading process of specific DLLs in Cisco Proximity Desktop for Windows could allow an authenticated, local attacker to load a…

Fix: 3.1.0+
Fix from $1,950 2021-01-13
Skysea Client View HIGH 7.8
CVE-2021-20616

Untrusted search path vulnerability in the installer of SKYSEA Client View Ver.1.020.05b to Ver.16.001.01g allows an attacker to gain privileges via …

Fix: after 16.001.01g
Fix from $1,950 2021-01-13
Safervpn HIGH 7.8
CVE-2020-26050

SaferVPN for Windows Ver 5.0.3.3 through 5.0.4.15 could allow local privilege escalation from low privileged users to SYSTEM via a crafted openssl co…

Fix: after 5.0.4.15
Fix from $1,950 2021-01-12
Anydesk HIGH 7.8
CVE-2020-35483

AnyDesk before 6.1.0 on Windows, when run in portable mode on a system where the attacker has write access to the application directory, allows this …

Fix: 6.1.0+
Fix from $1,950 2021-01-11
Epsonnet Setupmanager HIGH 7.8
CVE-2020-5681

Untrusted search path vulnerability in self-extracting files created by EpsonNet SetupManager versions 2.2.14 and earlier, and Offirio SynergyWare Pr…

Fix: 1.6.1.1 / 2.2.15+
Fix from $1,950 2020-12-24
Dsl2888a Firmware MEDIUM 6.5
CVE-2020-24578

An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It has a misconfigured FTP service that allows a mali…

No fix yet
Fix from $1,600 2020-12-22
Dashboard HIGH 7.8
CVE-2020-29654

Western Digital Dashboard before 3.2.2.9 allows DLL Hijacking that leads to compromise of the SYSTEM account.

Fix: 3.2.2.9+
Fix from $1,950 2020-12-12
Prelude HIGH 7.0
CVE-2020-24440

Adobe Prelude version 9.0.1 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the con…

Fix: after 9.0.1
Fix from $1,950 2020-12-11
Lightroom HIGH 7.0
CVE-2020-24447

Adobe Lightroom Classic version 10.0 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrar…

Fix: after 10.0
Fix from $1,950 2020-12-11
Cortex Xdr Agent HIGH 7.8
CVE-2020-2049

A local privilege escalation vulnerability exists in Palo Alto Networks Cortex XDR Agent on the Windows platform that allows an authenticated local W…

Fix: after 7.2.2
Fix from $1,950 2020-12-09