Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
Unclassified HIGH 7.8
CVE-2026-25191

The installer of FinalCode Client provided by Digital Arts Inc. contains an issue with the DLL search path. If a user is directed to place a maliciou…

Mitigation only
Fix from $1,950 2026-02-26
Presto Client HIGH 7.3
CVE-2026-3091

An uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read or write arbitrary files and…

Fix: 2.1.3-0672+
Fix from $1,950 2026-02-24
Repository Manager HIGH 7.8
CVE-2026-21420

Dell Repository Manager (DRM), versions prior to 3.4.8, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with lo…

Fix: 3.4.8+
Fix from $1,950 2026-02-23
Unclassified HIGH 7.8
CVE-2026-2492

TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escal…

Patch available
Fix from $1,950 2026-02-20
Unclassified HIGH 7.3
CVE-2026-2040

PDF-XChange Editor TrackerUpdate Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers…

Mitigation only
Fix from $1,950 2026-02-20
Opds Talon MEDIUM 5.5
CVE-2026-26097

Uncontrolled Search Path Element in Owl opds 2.2.0.4 allows Leveraging/Manipulating Configuration File Search Paths via a crafted network request.

Mitigation only
Fix from $1,600 2026-02-20
Opds Talon MEDIUM 5.5
CVE-2026-26098

Uncontrolled Search Path Element in Owl opds 2.2.0.4 allows Leveraging/Manipulating Configuration File Search Paths via a crafted network request.

Mitigation only
Fix from $1,600 2026-02-20
Opds Talon MEDIUM 5.5
CVE-2026-26099

Uncontrolled Search Path Element in Owl opds 2.2.0.4 allows Leveraging/Manipulating Configuration File Search Paths via a crafted network request.

Mitigation only
Fix from $1,600 2026-02-20
Unclassified HIGH 7.8
CVE-2026-26050

The installer for ジョブログ集計/分析ソフトウェア RICOHジョブログ集計ツール versions prior to Ver.1.3.7 contains an issue with the DLL search path, w…

Mitigation only
Fix from $1,950 2026-02-20
Unclassified HIGH 7.0
CVE-2026-2538

A security flaw has been discovered in Flos Freeware Notepad2 4.2.22/4.2.23/4.2.24/4.2.25. Affected is an unknown function in the library Msimg32.dll…

Mitigation only
Fix from $1,950 2026-02-16
Unclassified HIGH 7.0
CVE-2026-2516

A vulnerability was identified in Unidocs ezPDF DRM Reader and ezPDF Reader 2.0/3.0.0.4. This affects an unknown part in the library SHFOLDER.dll. Su…

Mitigation only
Fix from $1,950 2026-02-15
Unclassified HIGH 7.3
CVE-2025-54519

A DLL hijacking vulnerability in Doc Nav could allow a local attacker to achieve privilege escalation, potentially resulting in arbitrary code execut…

Mitigation only
Fix from $1,950 2026-02-12
Unclassified HIGH 7.8
CVE-2026-25676

The installer of M-Track Duo HD version 1.0.0 contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries…

Mitigation only
Fix from $1,950 2026-02-12
Unclassified HIGH 8.0
CVE-2026-2360

PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a custom operator in the public schema and…

Mitigation only
Fix from $1,950 2026-02-11
Unclassified HIGH 8.0
CVE-2026-2361

PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a temporary view based on a function conta…

Mitigation only
Fix from $1,950 2026-02-11
Unclassified HIGH 7.3
CVE-2025-52541

A DLL hijacking vulnerability in Vivado could allow a local attacker to achieve privilege escalation, potentially resulting in arbitrary code executi…

Mitigation only
Fix from $1,950 2026-02-11
Unclassified HIGH 7.8
CVE-2025-48503

A DLL hijacking vulnerability in the AMD Software Installer could allow an attacker to achieve privilege escalation potentially resulting in arbitrar…

Mitigation only
Fix from $1,950 2026-02-11
Unclassified MEDIUM 6.7
CVE-2025-32452

Uncontrolled search path for some AI Playground before version 2.6.1 beta within Ring 3: User Applications may allow an escalation of privilege. Unpr…

Mitigation only
Fix from $1,600 2026-02-10
Unclassified MEDIUM 6.7
CVE-2025-20106

Uncontrolled search path in some software installer for some VTune(TM) Profiler software and Intel(R) oneAPI Base Toolkits before version 2025.0. wit…

Mitigation only
Fix from $1,600 2026-02-10
Unclassified HIGH 7.0
CVE-2025-15569

A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The impacted element is the function get_system_dpi of the file platform/x11/win_main…

Mitigation only
Fix from $1,950 2026-02-10
Sinec Nms HIGH 7.8
CVE-2026-25655

A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP2). The affected application permits improper modification of a configuration…

Fix: 4.0+
Fix from $1,950 2026-02-10
Sinec Nms HIGH 7.8
CVE-2026-25656

A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3), User Management Component (UMC) (All versions < V2.15.2.1). The affected …

Fix: 2.15.2.1+
Fix from $1,950 2026-02-10
Certified Asterisk HIGH 7.8
CVE-2026-23740

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, when as…

Fix: 20.18.2 / 21.12.1+
Fix from $1,950 2026-02-06
Asterisk HIGH 8.8
CVE-2026-23741

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the ast…

Fix: 20.18.2 / 21.12.1+
Fix from $1,950 2026-02-06
Unclassified HIGH 7.8
CVE-2026-24694

The installer for Roland Cloud Manager ver.3.1.19 and prior insecurely loads Dynamic Link Libraries (DLLs), which could allow an attacker to execute …

Mitigation only
Fix from $1,950 2026-02-03
Psysh HIGH 7.3
CVE-2026-25129

PsySH is a runtime developer console, interactive debugger, and REPL for PHP. Prior to versions 0.11.23 and 0.12.19, PsySH automatically loads and ex…

Fix: 0.11.23 / 0.12.19+
Fix from $1,950 2026-01-30
Unclassified HIGH 7.3
CVE-2026-21408

beat-access for Windows version 3.0.3 and prior contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Librari…

Mitigation only
Fix from $1,950 2026-01-27
Unclassified HIGH 8.9
CVE-2025-30248

DLL hijacking in the WD Discovery Installer in Western Digital WD Discovery 5.2.730 on Windows allows a local attacker to execute arbitrary code via …

Mitigation only
Fix from $1,950 2026-01-26
Unclassified HIGH 7.1
CVE-2025-71178

Crucial Storage Executive installer versions prior to 11.08.082025.00 contain a DLL preloading vulnerability. During installation, the installer runs…

Mitigation only
Fix from $1,950 2026-01-26
Unclassified HIGH 7.3
CVE-2026-0776

Discord Client Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privi…

Mitigation only
Fix from $1,950 2026-01-23