Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
HIGH 7.7 CVE-2025-53394 Paramount Macrium Reflect through 2025-06-26 allows attackers to execute arbitrary code with administrator privileges via a crafted .mrimgx or .mrbax… Mitigation only Fix from $1,9502025-08-04 HIGH 7.0 CVE-2025-0712 An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions. The vulnerability … Mitigation only Fix from $1,9502025-07-30 HIGH 7.0 CVE-2025-25011 An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions. The vulnerability … Mitigation only Fix from $1,9502025-07-30 MEDIUM 5.4 CVE-2025-7676 DLL hijacking of all PE32 executables when run on Windows for ARM64 CPU architecture. This allows an attacker to execute code, if the attacker can pl… Mitigation only Fix from $1,6002025-07-28 HIGH 8.5 CVE-2024-13976 A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During the installation of maintenance… Mitigation only Fix from $1,9502025-07-25 MEDIUM 5.9 CVE-2025-7427 Uncontrolled Search Path Element in Arm Development Studio before 2025 may allow an attacker to perform a DLL hijacking attack. Successful exploitati… Arm Development Studio 2025.0+ Fix from $1,6002025-07-22 HIGH 7.0 CVE-2025-1700 A DLL hijacking vulnerability was reported in the Motorola Software Fix (Rescue and Smart Assistant) installer that could allow a local attacker to e… Mitigation only Fix from $1,9502025-07-17 MEDIUM 6.7 CVE-2025-1729 A DLL hijacking vulnerability was reported in TrackPoint Quick Menu software that, under certain conditions, could allow a local attacker to escalate… Mitigation only Fix from $1,6002025-07-17 HIGH 7.5 CVE-2025-7472 A local privilege escalation vulnerability in the Intercept X for Windows installer prior version 1.22 can lead to a local user gaining system level … Mitigation only Fix from $1,9502025-07-17 HIGH 8.5 CVE-2025-34109 PSEvents.exe in multiple Panda Security products runs hourly with SYSTEM privileges and loads DLL files from a user-writable directory without proper… No fix yet Fix from $1,9502025-07-15 MEDIUM 5.1 CVE-2025-48496 Emerson ValveLink products use a fixed or controlled search path to find resources, but one or more locations in that path can be under the control… Mitigation only Fix from $1,6002025-07-11 HIGH 8.8 CVE-2025-36004 IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user to gain elevated privileges due to an unqualified library call in IBM Facsimile Support for i. A mali… I Mitigation only Fix from $1,9502025-06-25 HIGH 7.3 CVE-2025-49144 Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.… Patch available Fix from $1,9502025-06-23 CRITICAL 9.9 CVE-2025-4981 Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sanitize filenames in the archi… Mattermost Server 9.11.16 / 10.5.6+ Fix from $2,3002025-06-20 HIGH 7.8 CVE-2024-24916 Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution with the installer's privileg… Smartconsole Mitigation only Fix from $1,9502025-06-19 MEDIUM 6.5 CVE-2025-5981 Arbitrary file write as the OSV-SCALIBR user on the host system via a path traversal vulnerability when using OSV-SCALIBR's unpack() function for con… Osv Scalibr 0.1.8+ Fix from $1,6002025-06-18 MEDIUM 6.8 CVE-2025-49487 An uncontrolled search path vulnerability in the Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an attacker with … Worry Free Business Security Services 6.7.3954 / 14.3.1299+ Fix from $1,6002025-06-17 HIGH 8.8 CVE-2025-49155 An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacker to inject malicious code le… Apex One 14.0.0.14002 / 14.0.14492+ Fix from $1,9502025-06-17 HIGH 7.8 CVE-2025-49158 An uncontrolled search path vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalation privileges on affecte… Apex One 14.0.0.14002 / 14.0.14492+ Fix from $1,9502025-06-17 HIGH 7.5 CVE-2025-33122 IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 could allow a user to gain elevated privileges due to an unqualified library call in IBM Advanced Job Scheduler for… I Mitigation only Fix from $1,9502025-06-17 HIGH 7.3 CVE-2025-49148 ClipShare is a lightweight and cross-platform tool for clipboard sharing. Prior to 3.8.5, ClipShare Server for Windows uses the default Windows DLL s… Mitigation only Fix from $1,9502025-06-11 HIGH 7.8 CVE-2025-5480 Action1 Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges o… Agent 5.218.620.1+ Fix from $1,9502025-06-06 HIGH 7.3 CVE-2025-30167 Jupyter Core is a package for the core common functionality of Jupyter projects. When using Jupyter Core prior to version 5.8.0 on Windows, the share… Jupyter Core 5.8.0+ Fix from $1,9502025-06-03 CRITICAL 9.8 CVE-2024-42190 HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the appl… Traveler For Microsoft Outlook 3.0.12+ Fix from $2,3002025-05-30 CRITICAL 9.8 CVE-2024-42191 HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the appl… Traveler For Microsoft Outlook 3.0.12+ Fix from $2,3002025-05-30 HIGH 7.3 CVE-2025-5180 A vulnerability, which was classified as critical, has been found in Wondershare Filmora 14.5.16. Affected by this issue is some unknown functionalit… Filmora No fix yet Fix from $1,9502025-05-26 MEDIUM 6.3 CVE-2025-5129 A vulnerability has been found in Sangfor 零信任访问控制系统 aTrust 2.3.10.60 and classified as critical. Affected by this vulnerability is an unknow… Atrust No fix yet Fix from $1,6002025-05-24 MEDIUM 6.8 CVE-2024-13946 DLL's are not digitally signed when loaded in ASPECT's configuration toolset exposing the application to binary planting during device commissioning.… Mitigation only Fix from $1,6002025-05-22 HIGH 7.0 CVE-2025-2272 Uncontrolled Search Path Element vulnerability in Forcepoint FIE Endpoint allows Privilege Escalation, Code Injection, Hijacking a privileged process… Mitigation only Fix from $1,9502025-05-22 HIGH 8.4 CVE-2025-27997 An issue in Blizzard Battle.net v2.40.0.15267 allows attackers to escalate privileges via placing a crafted shell script or executable into the C:\Pr… Battle.net Mitigation only Fix from $1,9502025-05-21