Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
Unclassified HIGH 7.3
CVE-2026-4158

KeePassXC OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers …

Mitigation only
Fix from $1,950 2026-04-11
Emocheck HIGH 7.8
CVE-2026-28704

Emocheck insecurely loads Dynamic Link Libraries (DLLs). If a crafted DLL file is placed to the same directory, an arbitrary code may be executed wit…

Mitigation only
Fix from $1,950 2026-04-10
Unclassified HIGH 8.8
CVE-2026-30478

A Dynamic-link Library Injection vulnerability in GatewayGeo MapServer for Windows version 5 allows attackers to escalate privileges via a crafted ex…

Mitigation only
Fix from $1,950 2026-04-09
Memprocfs HIGH 7.8
CVE-2026-40031

MemProcFS before 5.17 contains multiple unsafe library-loading patterns that enable DLL and shared-library hijacking across six attack surfaces, incl…

Fix: 5.17+
Fix from $1,950 2026-04-08
Hardened Images HIGH 7.0
CVE-2025-14821

A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and man…

Fix: 0.12.0+
Fix from $1,950 2026-04-07
True Image MEDIUM 6.7
CVE-2026-28728

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42902.

Fix: 2026+
Fix from $1,600 2026-04-02
True Image MEDIUM 6.7
CVE-2026-27774

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42902.

Fix: 2026+
Fix from $1,600 2026-04-02
Pymanager HIGH 7.8
CVE-2026-5271

pymanager included the current working directory in sys.path meaning modules could be shadowed by modules in the current working directory. As a resu…

No fix yet
Fix from $1,950 2026-04-01
Pdf Editor HIGH 7.8
CVE-2026-3775

The application's update service, when checking for updates, loads certain system libraries from a search path that includes directories writable by …

Fix: after 2025.3.0.35737
Fix from $1,950 2026-04-01
Claude HIGH 7.8
CVE-2026-22561

Uncontrolled search path elements in Anthropic Claude for Windows installer (Claude Setup.exe) versions prior to 1.1.3363 allow local privilege escal…

Fix: 1.1.3363+
Fix from $1,950 2026-03-31
Unclassified HIGH 7.8
CVE-2026-34054

vcpkg is a free and open-source C/C++ package manager. Prior to version 3.6.1#3, vcpkg's Windows builds of OpenSSL set openssldir to a path on the bu…

Patch available
Fix from $1,950 2026-03-31
Ultravnc HIGH 7.0
CVE-2026-4962

A security flaw has been discovered in UltraVNC up to 1.6.4.0. Affected by this issue is some unknown functionality in the library version.dll of the…

Fix: after 1.6.4.0
Fix from $1,950 2026-03-27
Unclassified HIGH 7.8
CVE-2026-28760

The installer of RATOC RAID Monitoring Manager for Windows searches the current directory to load certain DLLs. If a user is directed to place a craf…

Mitigation only
Fix from $1,950 2026-03-26
Unclassified HIGH 7.8
CVE-2026-26306

The installer for OM Workspace (Windows Edition) Ver 2.4 and earlier insecurely loads Dynamic Link Libraries (DLLs), which could allow an attacker to…

Mitigation only
Fix from $1,950 2026-03-25
Notepad2 HIGH 7.0
CVE-2026-4546

A weakness has been identified in Flos Freeware Notepad2 4.2.25. This impacts an unknown function in the library TextShaping.dll. Executing a manipul…

No fix yet
Fix from $1,950 2026-03-22
Notepad2 HIGH 7.0
CVE-2026-4545

A security flaw has been discovered in Flos Freeware Notepad2 4.2.25. This affects an unknown function in the library PROPSYS.dll. Performing a manip…

Mitigation only
Fix from $1,950 2026-03-22
Screentogif HIGH 7.8
CVE-2026-33156

ScreenToGif is a screen recording tool. In versions from 2.42.1 and prior, ScreenToGif is vulnerable to DLL sideloading via version.dll . When the po…

Fix: after 2.42.1
Fix from $1,950 2026-03-20
Openedr HIGH 8.8
CVE-2025-69784

A local, non-privileged attacker can abuse a vulnerable IOCTL interface exposed by the OpenEDR 2.5.1.0 kernel driver to modify the DLL injection path…

No fix yet
Fix from $1,950 2026-03-16
Trusteer Rapport HIGH 7.8
CVE-2026-2713

IBM Trusteer Rapport installer 3.5.2309.290 IBM Trusteer Rapport could allow a local attacker to execute arbitrary code on the system, caused by DLL …

Mitigation only
Fix from $1,950 2026-03-10
Unclassified MEDIUM 5.0
CVE-2026-24317

SAP GUI for Windows allows DLL files to be loaded from arbitrary directories within the application. An unauthenticated attacker could exploit this v…

Mitigation only
Fix from $1,600 2026-03-10
Qsee Client HIGH 7.8
CVE-2026-30896

The installer for Qsee Client versions 1.0.1 and prior insecurely load Dynamic Link Libraries (DLLs). When a user is directed to place some malicious…

Fix: after 1.0.1
Fix from $1,950 2026-03-09
Ultravnc HIGH 7.0
CVE-2026-3787

A weakness has been identified in UltraVNC 1.6.4.0 on Windows. This affects an unknown function in the library cryptbase.dll of the component Windows…

Mitigation only
Fix from $1,950 2026-03-08
Cyber Protect MEDIUM 6.3
CVE-2026-28711

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 4…

Fix: 17.0.41186+
Fix from $1,600 2026-03-06
Cyber Protect MEDIUM 6.3
CVE-2026-28712

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 4…

Fix: 17.0.41186+
Fix from $1,600 2026-03-06
Agent HIGH 7.3
CVE-2025-11792

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) befor…

Mitigation only
Fix from $1,950 2026-03-06
Openclaw HIGH 8.8
CVE-2026-29610

OpenClaw versions prior to 2026.2.14 contain a command hijacking vulnerability that allows attackers to execute unintended binaries by manipulating P…

Fix: 2026.2.14+
Fix from $1,950 2026-03-05
Openclaw HIGH 7.2
CVE-2026-28456

OpenClaw versions 2026.1.5 prior to 2026.2.14 contain a vulnerability in the Gateway in which it does not sufficiently constrain configured hook modu…

Fix: 2026.2.14+
Fix from $1,950 2026-03-05
Command Line Interface HIGH 8.0
CVE-2025-15558

Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exist by default. A low-privilege…

Fix: after 29.1.5
Fix from $1,950 2026-03-04
Powerscale Onefs MEDIUM 6.7
CVE-2026-22270

Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an uncontrolled search path element vulnerability.…

Fix: 9.10.1.6 / 9.13.0.0+
Fix from $1,600 2026-03-04
Command \| Intel Vpro Out Of Band HIGH 7.8
CVE-2026-24502

Dell Command | Intel vPro Out of Band, versions prior to 4.7.0, contain an Uncontrolled Search Path Element vulnerability. A low privileged attacker …

Fix: 4.7.0+
Fix from $1,950 2026-03-03