Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
HIGH 8.8 CVE-2023-2005 Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugin Feed ID #202306261202 ; Nes… Nessus Mitigation only Fix from $1,9502023-06-26 HIGH 7.8 CVE-2023-27908 A maliciously crafted DLL file can be forced to write beyond allocated boundaries in the Autodesk installer when parsing the DLL files and could lead… Installer 1.39.0.216+ Fix from $1,9502023-06-23 HIGH 8.1 CVE-2023-0142 Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-4… Diskstation Manager Unified Controller 1.3.1-9346 / 7.1-42661+ Fix from $1,9502023-06-13 HIGH 7.8 CVE-2023-0976 A command Injection Vulnerability in TA for mac-OS prior to version 5.7.9 allows local users to place an arbitrary file into the /Library/Trellix/Age… Agent 5.7.9+ Fix from $1,9502023-06-07 HIGH 7.8 CVE-2023-3091 ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Captura up to 8.0.0. It has been declared as critical. This vulnerability affects unknow… Captura after 8.0.0 Fix from $1,9502023-06-04 HIGH 7.3 CVE-2023-28080 PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains DLL Hijacking Vulnerabilities. A regular user (non-admin) can exploit these issues to potenti… Powerpath Patch available Fix from $1,9502023-05-30 HIGH 7.8 CVE-2023-25005 A maliciously crafted DLL file can be forced to read beyond allocated boundaries in Autodesk InfraWorks 2023, and 2021 when parsing the DLL files cou… Infraworks 2021.2 / 2023.1+ Fix from $1,9502023-05-12 HIGH 7.8 CVE-2023-25428 A DLL Hijacking issue discovered in Soft-o Free Password Manager 1.1.20 allows attackers to create arbitrary DLLs leading to code execution. Free Password Manager No fix yet Fix from $1,9502023-05-12 HIGH 7.8 CVE-2023-31197 Uncontrolled search path in the Intel(R) Trace Analyzer and Collector before version 2020 update 3 may allow an authenticated user to potentially ena… Trace Analyzer And Collector 2020+ Fix from $1,9502023-05-12 HIGH 8.8 CVE-2023-27298 Uncontrolled search path in the WULT software maintained by Intel(R) before version 1.0.0 (commit id 592300b) may allow an unauthenticated user to po… Wake Up Latency Tracer 1.0.0+ Fix from $1,9502023-05-10 HIGH 7.3 CVE-2023-27386 Uncontrolled search path in some Intel(R) Pathfinder for RISC-V software may allow an authenticated user to potentially enable escalation of privileg… Pathfinder For Risc V Mitigation only Fix from $1,9502023-05-10 HIGH 7.8 CVE-2023-22355 Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user t… Advisor 1.18.1 / 2023.0+ Fix from $1,9502023-05-10 HIGH 7.8 CVE-2022-43474 Uncontrolled search path for the DSP Builder software installer before version 22.4 for Intel(R) FPGAs Pro Edition may allow an authenticated user to… Dsp Builder 22.4+ Fix from $1,9502023-05-10 HIGH 7.8 CVE-2022-41982 Uncontrolled search path element in the Intel(R) VTune(TM) Profiler software before version 2023.0 may allow an authenticated user to potentially ena… Vtune Profiler 2023.0+ Fix from $1,9502023-05-10 HIGH 7.8 CVE-2022-41998 Uncontrolled search path in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privileg… Data Center Manager 5.1+ Fix from $1,9502023-05-10 HIGH 7.8 CVE-2022-41693 Uncontrolled search path in the Intel(R) Quartus(R) Prime Pro edition software before version 22.3 may allow an authenticated user to potentially ena… Quartus Prime 22.3+ Fix from $1,9502023-05-10 HIGH 7.8 CVE-2022-41628 Uncontrolled search path element in the HotKey Services for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.1.44 may a… Nuc P14e Laptop Element 1.1.44+ Fix from $1,9502023-05-10 HIGH 7.8 CVE-2022-34848 Uncontrolled search path for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalat… Nuc Pro Software Suite 2.0.0.3+ Fix from $1,9502023-05-10 HIGH 7.8 CVE-2022-38101 Uncontrolled search path in some Intel(R) NUC Chaco Canyon BIOS update software before version iFlashV Windows 5.13.00.2105 may allow an authenticate… Iflashv 5.13.00.2105+ Fix from $1,9502023-05-10 HIGH 7.8 CVE-2022-27180 Uncontrolled search path in the Intel(R) MacCPUID software before version 3.2 may allow an authenticated user to potentially enable escalation of pri… Maccpuid 3.2+ Fix from $1,9502023-05-10 HIGH 7.8 CVE-2022-32576 Uncontrolled search path in the Intel(R) Unite(R) Plugin SDK before version 4.2 may allow an authenticated user to potentially enable escalation of p… Unite 4.2+ Fix from $1,9502023-05-10 HIGH 7.3 CVE-2022-21162 Uncontrolled search path for the Intel(R) HDMI Firmware Update tool for NUC before version 1.79.1.1 may allow an authenticated user to potentially en… Nuc Hdmi Firmware Update Tool 1.79.1.1+ Fix from $1,9502023-05-10 HIGH 7.8 CVE-2023-30237 CyberGhostVPN Windows Client before v8.3.10.10015 was discovered to contain a DLL injection vulnerability via the component Dashboard.exe. Cyberghost 8.3.10.10015+ Fix from $1,9502023-05-09 HIGH 7.8 CVE-2023-2355 Local privilege escalation due to a DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 3900. Snap Deploy 6+ Fix from $1,9502023-04-27 HIGH 7.8 CVE-2023-29011 Git for Windows, the Windows port of Git, ships with an executable called `connect.exe`, which implements a SOCKS5 proxy that can be used to connect … Git For Windows 2.40.1+ Fix from $1,9502023-04-25 HIGH 7.8 CVE-2023-29012 Git for Windows is the Windows port of Git. Prior to version 2.40.1, any user of Git CMD who starts the command in an untrusted directory is impacted… Git For Windows 2.40.1+ Fix from $1,9502023-04-25 MEDIUM 6.7 CVE-2022-34755 A CWE-427 - Uncontrolled Search Path Element vulnerability exists that could allow an attacker with a local privileged account to place a specially c… Easergy Builder Installer after 1.7.23 Fix from $1,6002023-04-18 HIGH 7.0 CVE-2023-28140 An Executable Hijacking condition exists in the Qualys Cloud Agent for Windows platform in versions before 4.5.3.1. Attackers may load a malicious co… Cloud Agent 4.5.3.1+ Fix from $1,9502023-04-18 MEDIUM 6.7 CVE-2023-29187 A Windows user with basic user authorization can exploit a DLL hijacking attack in SapSetup (Software Installation Program) - version 9.0, resulting … Sapsetup Mitigation only Fix from $1,6002023-04-11 HIGH 7.8 CVE-2022-48222 An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. During SDK installation, certutil.exe is called by the Acuant installer to install … Acuant Acufill Sdk 10.22.02.03+ Fix from $1,9502023-04-04