Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
Unclassified HIGH 7.3
CVE-2025-11178

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42386, …

Mitigation only
Fix from $1,950 2025-09-30
Unclassified HIGH 8.4
CVE-2025-56383

Notepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the original DLL file to execute malicious code. NOTE: this is disputed by mult…

Mitigation only
Fix from $1,950 2025-09-26
Unclassified HIGH 7.0
CVE-2025-9267

In Seagate Toolkit on Windows a vulnerability exists in the Toolkit Installer prior to versions 2.35.0.6 where it attempts to load DLLs from the curr…

Mitigation only
Fix from $1,950 2025-09-26
Unclassified HIGH 8.8
CVE-2025-9844

Uncontrolled Search Path Element vulnerability in Salesforce Salesforce CLI on Windows allows Replace Trusted Executable.This issue affects Salesforc…

Mitigation only
Fix from $1,950 2025-09-23
Asterisk HIGH 7.8
CVE-2025-1131

A local privilege escalation vulnerability exists in the safe_asterisk script included with the Asterisk toolkit package. When Asterisk is started vi…

Fix: 18.26.3 / 20.15.1+
Fix from $1,950 2025-09-23
Unclassified HIGH 7.8
CVE-2025-57624

A DLL hijacking vulnerability in CYRISMA Agent before 444 allows local users to escalate privileges and execute arbitrary code via multiple DLLs.

Mitigation only
Fix from $1,950 2025-09-16
Unclassified HIGH 7.8
CVE-2025-9201

A potential DLL hijacking vulnerability was discovered in Lenovo Browser during an internal security assessment that could allow a local user to exec…

No fix yet
Fix from $1,950 2025-09-11
Unclassified HIGH 8.8
CVE-2025-9059

The Altiris Core Agent Updater package (AeXNSC.exe) is prone to an elevation of privileges vulnerability through DLL hijacking.

Mitigation only
Fix from $1,950 2025-09-11
Unclassified HIGH 7.0
CVE-2025-40979

DLL search order hijacking vulnerability in the wave.exe executable for Windows 11, version 1.27.8. Exploitation of this vulnerability could allow at…

Mitigation only
Fix from $1,950 2025-09-10
Updf HIGH 7.8
CVE-2025-10214

DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with local access to execute arbitrar…

Mitigation only
Fix from $1,950 2025-09-10
Updf HIGH 7.8
CVE-2025-10215

DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with local access to execute arbitrar…

Mitigation only
Fix from $1,950 2025-09-10
Updf HIGH 7.8
CVE-2025-10213

DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with local access to execute arbitrar…

Mitigation only
Fix from $1,950 2025-09-10
Sunshine HIGH 7.8
CVE-2025-10198

Sunshine for Windows, version v2025.122.141614, contains a DLL search-order hijacking vulnerability, allowing attackers to insert a malicious DLL in …

Patch available
Fix from $1,950 2025-09-09
Unclassified HIGH 7.8
CVE-2025-55671

Uncontrolled search path element issue exists in TkEasyGUI versions prior to v1.0.22. If this vulnerability is exploited, arbitrary code may be execu…

Mitigation only
Fix from $1,950 2025-09-05
Pdf Editor HIGH 7.8
CVE-2025-9330

Foxit PDF Reader Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers …

Fix: after 2025.1.0.27937
Fix from $1,950 2025-09-02
Nomachine HIGH 7.8
CVE-2025-8614

NoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges…

Fix: 8.17.2 / 9.1.24+
Fix from $1,950 2025-09-02
Control Center Gx V2 HIGH 7.0
CVE-2025-9016

A vulnerability was identified in Mechrevo Control Center GX V2 5.56.51.48. This affects an unknown part of the file C:\Program Files\OEM\机械革命控…

Mitigation only
Fix from $1,950 2025-08-15
Control Center Gx V2 HIGH 7.0
CVE-2025-9000

A vulnerability was found in Mechrevo Control Center GX V2 5.56.51.48. Affected by this vulnerability is an unknown functionality of the component re…

Mitigation only
Fix from $1,950 2025-08-15
Substance 3d Modeler HIGH 7.8
CVE-2025-49571

Substance3D - Modeler versions 1.22.0 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary co…

Fix: 1.22.2+
Fix from $1,950 2025-08-12
Unclassified MEDIUM 6.7
CVE-2025-27717

Uncontrolled search path for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enable escalation of privilege via…

Mitigation only
Fix from $1,600 2025-08-12
Unclassified MEDIUM 6.7
CVE-2025-24923

Uncontrolled search path in some Intel(R) AI for Enterprise Retrieval-augmented Generation software may allow an authenticated user to potentially en…

Mitigation only
Fix from $1,600 2025-08-12
Unclassified MEDIUM 6.7
CVE-2025-26404

Uncontrolled search path for some Intel(R) DSA software before version 25.2.15.9 may allow an authenticated user to potentially enable escalation of …

Mitigation only
Fix from $1,600 2025-08-12
Unclassified MEDIUM 6.7
CVE-2025-21093

Uncontrolled search path element for some Intel(R) Driver & Support Assistant Tool software before version 24.6.49.8 may allow an authenticated u…

Mitigation only
Fix from $1,600 2025-08-12
Unclassified MEDIUM 6.7
CVE-2025-22838

Uncontrolled search path for some Intel(R) RealSense(TM) Dynamic Calibrator software before version 2.14.2.0 may allow an authenticated user to poten…

Mitigation only
Fix from $1,600 2025-08-12
Unclassified MEDIUM 6.7
CVE-2025-20627

Uncontrolled search path for some Intel(R) oneAPI DPC++/C++ Compiler software before version 2025.0.1 may allow an authenticated user to potentially …

Mitigation only
Fix from $1,600 2025-08-12
Unclassified MEDIUM 6.7
CVE-2025-20092

Uncontrolled search path for some Clock Jitter Tool software before version 6.0.1 may allow an authenticated user to potentially enable escalation of…

Mitigation only
Fix from $1,600 2025-08-12
Unclassified MEDIUM 6.7
CVE-2025-20048

Uncontrolled search path for the Intel(R) Trace Analyzer and Collector software all verions may allow an authenticated user to potentially enable esc…

Mitigation only
Fix from $1,600 2025-08-12
Unclassified MEDIUM 6.7
CVE-2025-20017

Uncontrolled search path for some Intel(R) oneAPI Toolkit and component software installers may allow an authenticated user to potentially enable esc…

Mitigation only
Fix from $1,600 2025-08-12
Unclassified HIGH 7.8
CVE-2025-30033

The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user installs a…

Mitigation only
Fix from $1,950 2025-08-12
Unclassified HIGH 7.7
CVE-2025-53395

Paramount Macrium Reflect through 2025-06-26 allows local attackers to execute arbitrary code with administrator privileges via a crafted .mrimgx bac…

Mitigation only
Fix from $1,950 2025-08-04