Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
D View 8 HIGH 7.3
CVE-2026-23755

D-Link D-View 8 versions 2.0.1.107 and below contain an uncontrolled search path vulnerability in the installer. When executed with elevated privileg…

Fix: after 2.0.1.107
Fix from $1,950 2026-01-21
Unclassified HIGH 7.8
CVE-2026-24016

The installer of ServerView Agents for Windows provided by Fsas Technologies Inc. may insecurely load Dynamic Link Libraries. Arbitrary code may be e…

Mitigation only
Fix from $1,950 2026-01-21
Cuda Toolkit HIGH 7.3
CVE-2025-33229

NVIDIA Nsight Visual Studio for Windows contains a vulnerability in Nsight Monitor where an attacker can execute arbitrary code with the same privile…

Fix: 13.1.0+
Fix from $1,950 2026-01-20
Cuda Toolkit MEDIUM 6.7
CVE-2025-33231

NVIDIA Nsight Systems for Windows contains a vulnerability in the application’s DLL loading mechanism where an attacker could cause an uncontrolled s…

Fix: 13.1.0+
Fix from $1,600 2026-01-20
Process Optimization HIGH 8.8
CVE-2025-65118

The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to trick Process Optimization services into loading arbi…

Fix: 2025+
Fix from $1,950 2026-01-16
Unclassified HIGH 8.4
CVE-2022-50808

CoolerMaster MasterPlus 1.8.5 contains an unquoted service path vulnerability in the MPService that allows local attackers to execute code with eleva…

No fix yet
Fix from $1,950 2026-01-13
Unclassified HIGH 7.8
CVE-2026-21427

The installers for multiple products provided by PIONEER CORPORATION contain an issue with the DLL search path, which may lead to insecurely loading …

Mitigation only
Fix from $1,950 2026-01-08
Unclassified CRITICAL 9.8
CVE-2019-25268

NREL BEopt 2.8.0.0 contains a DLL hijacking vulnerability that allows attackers to load arbitrary libraries by tricking users into opening applicatio…

Mitigation only
Fix from $2,300 2026-01-08
Quartus Prime MEDIUM 6.7
CVE-2025-14625

Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard on Windows (Nios II Command Shell modules), Altera Quartus Prime Lite…

Fix: 25.1+
Fix from $1,600 2026-01-07
Quartus Prime MEDIUM 6.7
CVE-2025-14596

Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro Installer (SFX) on Windows allows Search Order Hijacking.This issue af…

Fix: 25.1+
Fix from $1,600 2026-01-07
Quartus Prime MEDIUM 6.7
CVE-2025-14599

Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard Installer (SFX) on Windows, Altera Quartus Prime Lite  Installer …

Fix: 25.1+
Fix from $1,600 2026-01-07
Quartus Prime MEDIUM 6.7
CVE-2025-14605

Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro on Windows (System Console modules) allows Search Order Hijacking.This iss…

Fix: 25.1.1+
Fix from $1,600 2026-01-07
Magician HIGH 7.8
CVE-2025-57836

An issue was discovered in Samsung Magician 6.3.0 through 8.3.2 on Windows. The installer creates a temporary folder with weak permissions during ins…

Fix: after 8.3.2
Fix from $1,950 2026-01-05
Trueconf HIGH 7.1
CVE-2025-66835

TrueConf Client 8.5.2 is vulnerable to DLL hijacking via crafted wfapi.dll allowing local attackers to execute arbitrary code within the user's conte…

No fix yet
Fix from $1,950 2025-12-30
Ups Companion HIGH 8.6
CVE-2025-59887

Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the…

Fix: 3.0+
Fix from $1,950 2025-12-26
Ups Companion HIGH 7.8
CVE-2025-67450

Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software package could perform arbit…

Fix: 3.0+
Fix from $1,950 2025-12-26
Unclassified HIGH 7.8
CVE-2025-14498

TradingView Desktop Electron Uncontrolled Search Path Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate…

Mitigation only
Fix from $1,950 2025-12-23
Enhanced MEDIUM 6.8
CVE-2025-14405

PDFsam Enhanced Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows phyiscally-present attackers to …

Mitigation only
Fix from $1,600 2025-12-23
Soda Pdf HIGH 7.8
CVE-2025-14406

Soda PDF Desktop Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate pri…

Mitigation only
Fix from $1,950 2025-12-23
Filezilla Client CRITICAL 9.8
CVE-2023-53959

FileZilla Client 3.63.1 contains a DLL hijacking vulnerability that allows attackers to execute malicious code by placing a crafted TextShaping.dll i…

Mitigation only
Fix from $2,300 2025-12-19
Hubstaff HIGH 7.8
CVE-2023-53937

Hubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32 wow64log.dll with a malicious…

No fix yet
Fix from $1,950 2025-12-18
Nbconvert HIGH 7.8
CVE-2025-53000

The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions of nbconvert up to and inclu…

Fix: after 7.16.6
Fix from $1,950 2025-12-17
Quartus Prime MEDIUM 6.7
CVE-2025-13665

The System Console Utility for Windows is vulnerable to a DLL planting vulnerability

Fix: 24.1+
Fix from $1,600 2025-12-12
High Level Synthesis Compiler MEDIUM 6.7
CVE-2025-13669

Uncontrolled Search Path Element vulnerability in Altera High Level Synthesis Compiler on Windows allows Search Order Hijacking.This issue affects Hi…

Fix: after 24.3
Fix from $1,600 2025-12-12
High Level Synthesis Compiler MEDIUM 6.7
CVE-2025-13670

The High Level Synthesis Compiler i++ command for Windows is vulnerable to a DLL planting vulnerability

Fix: after 24.3
Fix from $1,600 2025-12-12
Quartus Prime MEDIUM 6.7
CVE-2025-13668

A potential security vulnerability in Quartus® Prime Pro Edition Design Software may allow escalation of privilege.

Fix: 25.1+
Fix from $1,600 2025-12-11
Quartus Prime MEDIUM 6.7
CVE-2025-13664

A potential security vulnerability in Quartus® Prime Standard Edition Design Software may allow escalation of privilege.

Fix: 24.1+
Fix from $1,600 2025-12-11
Digital Employee Experience MEDIUM 6.7
CVE-2025-64994

A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-SetWorkRate instruction prior…

Fix: 17.1+
Fix from $1,600 2025-12-11
Digital Employee Experience MEDIUM 6.7
CVE-2025-64995

A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Exchange-NomadClientHealth-Configur…

Fix: 3.4+
Fix from $1,600 2025-12-11
Mailenable HIGH 7.8
CVE-2025-34423

MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable admini…

Fix: 10.54+
Fix from $1,950 2025-12-10