Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
Anti Ransomware Tool HIGH 7.8
CVE-2020-28950

The installer of Kaspersky Anti-Ransomware Tool (KART) prior to KART 4.0 Patch C was vulnerable to a DLL hijacking attack that allowed an attacker to…

Fix: 4.0+
Fix from $1,950 2020-12-04
Snapcraft MEDIUM 6.8
CVE-2020-27348

In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a malicious snap to gain code execu…

Fix: 4.4.4+
Fix from $1,600 2020-12-04
Endpoint Security HIGH 7.8
CVE-2020-6021

Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which the installation repair takes …

Mitigation only
Fix from $1,950 2020-12-03
Endpoint Privilege Manager MEDIUM 5.5
CVE-2020-25738

CyberArk Endpoint Privilege Manager (EPM) 11.1.0.173 allows attackers to bypass a Credential Theft protection mechanism by injecting a DLL into a pro…

No fix yet
Fix from $1,600 2020-11-27
Album Print HIGH 7.8
CVE-2020-5674

Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL i…

Mitigation only
Fix from $1,950 2020-11-24
Vtune Profiler HIGH 7.8
CVE-2020-12329

Uncontrolled search path in the Intel(R) VTune(TM) Profiler before version 2020 Update 1 may allow an authenticated user to potentially enable escala…

Fix: after 2020
Fix from $1,950 2020-11-12
Scs Add On For Microsoft Sccm HIGH 7.8
CVE-2020-12320

Uncontrolled search path in Intel(R) SCS Add-on for Microsoft* SCCM before version 2.1.10 may allow an authenticated user to potentially enable escal…

Mitigation only
Fix from $1,950 2020-11-12
Endpoint Manager HIGH 7.8
CVE-2020-13771

Various components in Ivanti Endpoint Manager through 2020.1.1 rely on Windows search order when loading a (nonexistent) library file, allowing (unde…

Fix: after 2020.1.1
Fix from $1,950 2020-11-12
Geforce Now HIGH 7.8
CVE-2020-5992

NVIDIA GeForce NOW application software on Windows, all versions prior to 2.0.25.119, contains a vulnerability in its open-source software dependency…

Fix: 2.0.25.119+
Fix from $1,950 2020-11-11
Onlinesuite Application Package HIGH 7.8
CVE-2020-25174

A DLL hijacking vulnerability in the B. Braun OnlineSuite Version AP 3.0 and earlier allows local attackers to execute code on the system as a high p…

Fix: after 3.0
Fix from $1,950 2020-11-06
Git Large File Storage CRITICAL 9.8
CVE-2020-27955EPSS 83%

Git LFS 2.12.0 allows Remote Code Execution.

No fix yet
Fix from $2,300 2020-11-05
Origin HIGH 7.8
CVE-2020-27708

A vulnerability exists in the Origin Client that could allow a non-Administrative user to elevate their access to either Administrator or System. Onc…

Fix: after 10.5.86
Fix from $1,950 2020-11-02
Global Vpn Client HIGH 8.6
CVE-2020-5145

SonicWall Global VPN client version 4.10.4.0314 and earlier have an insecure library loading (DLL hijacking) vulnerability. Successful exploitation c…

Fix: after 4.10.4.0314
Fix from $1,950 2020-10-28
Dreamweaver HIGH 7.8
CVE-2020-24425

Dreamweaver version 20.2 (and earlier) is affected by an uncontrolled search path element vulnerability that could lead to privilege escalation. Succ…

Fix: after 20.2
Fix from $1,950 2020-10-21
After Effects HIGH 7.8
CVE-2020-24419

Adobe After Effects version 17.1.1 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary …

Fix: after 17.1.1
Fix from $1,950 2020-10-21
Photoshop HIGH 7.8
CVE-2020-24420

Adobe Photoshop for Windows version 21.2.1 (and earlier) is affected by an uncontrolled search path element vulnerability that could result in arbitr…

Fix: after 21.2.1
Fix from $1,950 2020-10-21
Media Encoder HIGH 7.8
CVE-2020-24423

Adobe Media Encoder version 14.4 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary co…

Fix: after 14.4
Fix from $1,950 2020-10-21
Premiere Pro HIGH 7.8
CVE-2020-24424

Adobe Premiere Pro version 14.4 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the…

Fix: after 14.4
Fix from $1,950 2020-10-21
Creative Cloud HIGH 7.8
CVE-2020-24422

Adobe Creative Cloud Desktop Application version 5.2 (and earlier) and 2.1 (and earlier) for Windows is affected by an uncontrolled search path vulne…

Fix: after 5.2
Fix from $1,950 2020-10-21
Hardware Scan HIGH 7.8
CVE-2020-8345

A DLL search path vulnerability was reported in the Lenovo HardwareScan Plugin for the Lenovo Vantage hardware scan feature prior to version 1.0.46.1…

Fix: 1.0.46.11+
Fix from $1,950 2020-10-14
Monero HIGH 7.8
CVE-2020-26947

monero-wallet-gui in Monero GUI before 0.17.1.0 includes the . directory in an embedded RPATH (with a preference ahead of /usr/lib), which allows loc…

Fix: 0.17.1.0+
Fix from $1,950 2020-10-10
Apo Software Component HIGH 7.8
CVE-2019-19115

An escalation of privilege vulnerability in Nahimic APO Software Component Driver 1.4.2, 1.5.0, 1.5.1, 1.6.1 and 1.6.2 allows an attacker to execute …

No fix yet
Fix from $1,950 2020-10-08
Wildlife Issues In The New Millennium HIGH 7.8
CVE-2020-26894

LiveCode v9.6.1 on Windows allows local, low-privileged users to gain privileges by creating a malicious "cmd.exe" in the folder of the vulnerable Li…

Patch available
Fix from $1,950 2020-10-08
Webex Teams HIGH 8.4
CVE-2020-3535

A vulnerability in the loading mechanism of specific DLLs in the Cisco Webex Teams client for Windows could allow an authenticated, local attacker to…

Fix: after 3.0.16040.0
Fix from $1,950 2020-10-08
Cloudflared HIGH 7.8
CVE-2020-24356

`cloudflared` versions prior to 2020.8.1 contain a local privilege escalation vulnerability on Windows systems. When run on a Windows system, `cloudf…

Fix: 2020.8.1+
Fix from $1,950 2020-10-02
Foxit Reader HIGH 7.8
CVE-2020-26538

An issue was discovered in Foxit Reader and PhantomPDF before 10.1. It allows attackers to execute arbitrary code via a Trojan horse taskkill.exe in …

Fix: 10.1+
Fix from $1,950 2020-10-02
Firefox HIGH 8.8
CVE-2020-15663

If Firefox is installed to a user-writable directory, the Mozilla Maintenance Service would execute updater.exe from the install location with system…

Fix: 68.12 / 78.2+
Fix from $1,950 2020-10-01
9000x Programming And Configuration Software HIGH 7.8
CVE-2020-6654

A DLL Hijacking vulnerability in Eaton's 9000x Programming and Configuration Software v 2.0.38 and prior allows an attacker to execute arbitrary code…

Fix: after 2.0.38
Fix from $1,950 2020-09-30
Installbuilder HIGH 7.8
CVE-2020-3979

InstallBuilder for Qt Windows (versions prior to 20.7.0) installers look for plugins at a predictable location at initialization time, writable by no…

Fix: 20.7.0+
Fix from $1,950 2020-09-18
Appspider MEDIUM 6.5
CVE-2020-7358

In AppSpider installer versions prior to 7.2.126, the AppSpider installer calls an executable which can be placed in the appropriate directory by an …

Fix: 7.2.126+
Fix from $1,600 2020-09-18