Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
HIGH 7.8 CVE-2022-4956 A vulnerability classified as critical has been found in Caphyon Advanced Installer 19.7. This affects an unknown part of the component WinSxS DLL Ha… Advanced Installer No fix yet Fix from $1,9502023-09-30 HIGH 7.3 CVE-2023-41929 A DLL hijacking vulnerability in Samsung Memory Card & UFD Authentication Utility PC Software before 1.0.1 could allow a local attacker to escalate p… Memory Card \& Ufd Authentication 1.0.1+ Fix from $1,9502023-09-18 HIGH 7.8 CVE-2023-39374 ForeScout NAC SecureConnector version 11.2 - CWE-427: Uncontrolled Search Path Element Secureconnector Mitigation only Fix from $1,9502023-09-03 HIGH 8.8 CVE-2023-40596 In Splunk Enterprise versions earlier than 8.2.12, 9.0.6, and 9.1.1, a dynamic link library (DLL) that ships with Splunk Enterprise references an ins… Splunk 8.2.12 / 9.0.6+ Fix from $1,9502023-08-30 MEDIUM 6.5 CVE-2023-3252 An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges could alter logging variables to o… Nessus 10.6.0+ Fix from $1,6002023-08-29 HIGH 7.2 CVE-2023-40352 McAfee Safe Connect before 2.16.1.126 may allow an adversary with system privileges to achieve privilege escalation by loading arbitrary DLLs. Safe Connect 2.16.1.126+ Fix from $1,9502023-08-21 HIGH 7.8 CVE-2023-3078 An uncontrolled search path vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local access to … Universal Device Client 23.4+ Fix from $1,9502023-08-17 HIGH 7.3 CVE-2022-4894 Certain HP and Samsung Printer software packages may potentially be vulnerable to elevation of privilege due to Uncontrolled Search Path Element. 2zn49a Firmware Mitigation only Fix from $1,9502023-08-16 HIGH 7.3 CVE-2023-34355 Uncontrolled search path element for some Intel(R) Server Board M10JNP2SB integrated BMC video drivers before version 3.0 for Microsoft Windows and b… Integrated Bmc Video Driver 1.13.4 / 3.0+ Fix from $1,9502023-08-11 HIGH 7.8 CVE-2023-29151 Uncontrolled search path element in some Intel(R) PSR SDK before version 1.0.0.20 may allow an authenticated user to potentially enable escalation of… Platform Service Record Software Development Kit 1.0.0.20+ Fix from $1,9502023-08-11 HIGH 7.3 CVE-2023-28823 Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow an authenticated user t… Advisor For Oneapi 1.19.1 / 2023.1+ Fix from $1,9502023-08-11 HIGH 8.8 CVE-2023-28380 Uncontrolled search path for the Intel(R) AI Hackathon software before version 2.0.0 may allow an unauthenticated user to potentially enable escalati… Ai Hackathon 2.0.0+ Fix from $1,9502023-08-11 HIGH 7.8 CVE-2023-28405 Uncontrolled search path in the Intel(R) Distribution of OpenVINO(TM) Toolkit before version 2022.3.0 may allow an authenticated user to potentially … Openvino 2022.3.0+ Fix from $1,9502023-08-11 HIGH 7.8 CVE-2023-25944 Uncontrolled search path element in some Intel(R) VCUST Tool software downloaded before February 3nd 2023 may allow an authenticated user to potentia… Vcust Tool 2023-02-03+ Fix from $1,9502023-08-11 HIGH 7.3 CVE-2023-23577 Uncontrolled search path element for some ITE Tech consumer infrared drivers before version 5.5.2.1 for Intel(R) NUC may allow an authenticated user … Ite Tech Consumer Infrared Driver 5.5.2.1+ Fix from $1,9502023-08-11 HIGH 7.3 CVE-2023-24016 Uncontrolled search path element in some Intel(R) Quartus(R) Prime Pro and Standard edition software for linux may allow an authenticated user to pot… Quartus Prime 22.1std / 22.4+ Fix from $1,9502023-08-11 HIGH 7.8 CVE-2023-25182 Uncontrolled search path element in the Intel(R) Unite(R) Client software for Mac before version 4.2.11 may allow an authenticated user to potentiall… Unite 4.2.11+ Fix from $1,9502023-08-11 HIGH 7.3 CVE-2023-22841 Unquoted search path in the software installer for the System Firmware Update Utility (SysFwUpdt) for some Intel(R) Server Boards and Intel(R) Server… Server Firmware Update Utility 16.0.7+ Fix from $1,9502023-08-11 HIGH 7.8 CVE-2022-43456 Uncontrolled search path in some Intel(R) RST software before versions 16.8.5.1014.5, 17.11.3.1010.2, 18.7.6.1011.2 and 19.5.2.1049.5 may allow an au… Rapid Storage Technology 16.8.5.1014.5 / 17.11.3.1010.2+ Fix from $1,9502023-08-11 HIGH 7.8 CVE-2022-25864 Uncontrolled search path in some Intel(R) oneMKL software before version 2022.0 may allow an authenticated user to potentially enable escalation of p… Oneapi Math Kernel Library 2022.0+ Fix from $1,9502023-08-11 HIGH 7.8 CVE-2022-47636 A DLL hijacking vulnerability has been discovered in OutSystems Service Studio 11 11.53.30 build 61739. When a user open a .oml file (OutSystems Mode… Service Studio No fix yet Fix from $1,9502023-08-10 HIGH 7.8 CVE-2023-36344 An issue in Diebold Nixdorf Vynamic View Console v.5.3.1 and before allows a local attacker to execute arbitrary code via not restricting the search … Vynamic View after 5.3.1 Fix from $1,9502023-08-08 HIGH 7.8 CVE-2021-41544 A vulnerability has been identified in Siemens Software Center (All versions < V3.0). A DLL Hijacking vulnerability could allow a local attacker to e… Software Center 3.0+ Fix from $1,9502023-08-08 CRITICAL 9.0 CVE-2023-37490 SAP Business Objects Installer - versions 420, 430, allows an authenticated attacker within the network to overwrite an executable file created in a … Businessobjects Business Intelligence Mitigation only Fix from $2,3002023-08-08 HIGH 7.3 CVE-2023-3662 In CODESYS Development System versions from 3.5.17.0 and prior to 3.5.19.20 a vulnerability allows for execution of binaries from the current working… Development System 3.5.19.20+ Fix from $1,9502023-08-03 HIGH 7.8 CVE-2022-43703 An installer that loads or executes files using an unconstrained search path may be vulnerable to substitute files under control of an attacker being… Arm Development Studio after 5.29.3 Fix from $1,9502023-07-27 HIGH 7.8 CVE-2023-36853 ​In Keysight Geolocation Server v2.4.2 and prior, a low privileged attacker could create a local ZIP file containing a malicious script in any locati… Geolocation Server after 2.4.2 Fix from $1,9502023-07-19 MEDIUM 6.5 CVE-2023-37849 A DLL hijacking vulnerability in Panda Security VPN for Windows prior to version v15.14.8 allows attackers to execute arbitrary code via placing a cr… Panda Security Vpn 15.14.8+ Fix from $1,6002023-07-13 CRITICAL 9.8 CVE-2023-31543 A dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted PyPI package to the chosen rep… Pipreqs after 0.4.11 Fix from $2,3002023-06-30 HIGH 7.8 CVE-2023-28929 Trend Micro Security 2021, 2022, and 2023 (Consumer) are vulnerable to a DLL Hijacking vulnerability which could allow an attacker to use a specific … Antivirus\+ Security 2021 after 17.7.1476 Fix from $1,9502023-06-26