Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
HIGH 7.8 CVE-2026-56437 Uncontrolled search path element issue exists in Pupsman versions prior to 3.9.0. If a crafted DLL file is placed in the same folder as the affected … Mitigation only Fix from $1,9502026-07-08 HIGH 7.8 CVE-2026-38972 Notepad3 through 6.25.822.1 contains a DLL search-order hijacking vulnerability in the About-dialog code path in src/Notepad3.c. The application call… Notepad3 after 6.25.822.1 Fix from $1,9502026-07-02 HIGH 7.8 CVE-2026-54672 electron-updater allows for automatic updates for Electron apps. Prior to 26.15.0, AppImage targets built by app-builder-lib could use an empty path … Electron Builder Patch available Fix from $1,9502026-06-30 HIGH 8.8 CVE-2026-54232 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.1, the vLLM Dockerfile is vulnerable to a dependency confusio… Vllm 0.22.1+ Fix from $1,9502026-06-22 HIGH 8.8 CVE-2026-49241 The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. Prior to 21.2.4, the client-side Angular Lan… Angular Language Service 21.2.4+ Fix from $1,9502026-06-22 HIGH 7.3 CVE-2026-6645 An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows. The appli… Mitigation only Fix from $1,9502026-06-22 HIGH 7.3 CVE-2026-11958 Local privilege escalation by loading DLLs from a shared temporary directory in ANSSI’s DFIR-ORC, versions 10.2.7 and prior. An attacker with prior a… Mitigation only Fix from $1,9502026-06-18 MEDIUM 5.3 CVE-2026-12003 To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and us… Patch available Fix from $1,6002026-06-16 MEDIUM 6.7 CVE-2024-22451 Dell Peripheral Manager, versions from 1.5.1 to 1.7.2, contain an uncontrolled search path element vulnerability. An attacker could potentially explo… Peripheral Manager 1.7.3+ Fix from $1,6002026-06-16 HIGH 7.8 CVE-2024-22447 Dell Peripheral Manager, versions prior to 1.7.3, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit th… Peripheral Manager 1.7.3+ Fix from $1,9502026-06-16 HIGH 8.5 CVE-2026-5064 Potential security vulnerabilities have been identified in the HP One Agent for certain HP PC products, which might allow for escalat… Mitigation only Fix from $1,9502026-06-15 HIGH 7.8 CVE-2026-50100 Multiple printer drivers provided by Ricoh Company, Ltd. and KONICA MINOLTA JAPAN, INC. contain a privilege escalation vulnerability. If this vulnera… Mitigation only Fix from $1,9502026-06-15 HIGH 8.5 CVE-2026-11967 MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading a malicious DLL located in the sa… Mitigation only Fix from $1,9502026-06-12 HIGH 8.5 CVE-2026-11879 MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading malicious DLLs from a temporary d… Mitigation only Fix from $1,9502026-06-12 HIGH 7.8 CVE-2026-53813 OpenClaw before 2026.4.25 contains a path traversal vulnerability in memory-core artifact loading where workspace state influences local package root… Openclaw 2026.4.25+ Fix from $1,9502026-06-11 HIGH 8.8 CVE-2026-7870 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-co… I Mitigation only Fix from $1,9502026-06-11 HIGH 7.8 CVE-2026-10847 A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated local user may be able to execu… Mitigation only Fix from $1,9502026-06-11 HIGH 7.8 CVE-2026-8637 A potential uncontrolled search path vulnerability was reported in the LanSchool Classic client application that could allow a local authenticated us… Mitigation only Fix from $1,9502026-06-10 HIGH 7.7 CVE-2026-47937 Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in… Acrobat Dc 24.001.30383 / 26.001.21662+ Fix from $1,9502026-06-09 HIGH 7.2 CVE-2026-41567 Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is upl… Mitigation only Fix from $1,9502026-06-05 HIGH 7.3 CVE-2026-44609 Local privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0… Mitigation only Fix from $1,9502026-06-03 HIGH 7.3 CVE-2026-44682 Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0… Mitigation only Fix from $1,9502026-06-03 HIGH 7.3 CVE-2026-50033 Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0… Mitigation only Fix from $1,9502026-06-03 HIGH 7.8 CVE-2026-36574 A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escalate privileges and execute arbitrary code via a c… Mitigation only Fix from $1,9502026-06-03 HIGH 8.2 CVE-2026-44358 Espressif Shared GitHub DangerJS is a reusable GitHub Action CI DangerJS workflow for Espressif GitHub projects. Prior to 1.0.1, the action's entrypo… Patch available Fix from $1,9502026-05-28 MEDIUM 6.3 CVE-2026-47274 pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, multiple pam_usb helper tools resolved external bi… Patch available Fix from $1,6002026-05-27 HIGH 7.8 CVE-2023-52945 Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to exe… Beedrive 1.3.2-13814+ Fix from $1,9502026-05-27 HIGH 7.8 CVE-2025-41670 A local user with low privileges may be able to influence the behavior of a privileged system service by manipulating configuration or application-re… Mitigation only Fix from $1,9502026-05-27 HIGH 7.8 CVE-2026-32323 Mullvad VPN is a VPN client app for desktop and mobile. When using macOS with versions 2026.1 and below, Mullvad VPN may allow local privilege escala… Mullvad Vpn 2026.2+ Fix from $1,9502026-05-19 HIGH 7.8 CVE-2026-47092 Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attackers to execute arbitrary com… Claude Hud after 0.0.12 Fix from $1,9502026-05-18