Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
MEDIUM 6.7 CVE-2022-48223 An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. During SDK repair, certutil.exe is called by the Acuant installer to repair certifi… Acuant Acufill Sdk 10.22.02.03+ Fix from $1,6002023-04-04 HIGH 7.3 CVE-2022-48224 An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. It is installed with insecure permissions (full write access within Program Files).… Acuant Acufill Sdk 10.22.02.03+ Fix from $1,9502023-04-04 HIGH 7.3 CVE-2022-48225 An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. It is used to install drivers from several different vendors. The Gemalto Document … Acuant Acufill Sdk 10.22.02.03+ Fix from $1,9502023-04-04 HIGH 7.8 CVE-2023-1745 A vulnerability, which was classified as problematic, has been found in KMPlayer 4.2.2.73. This issue affects some unknown processing in the library … Kmplayer No fix yet Fix from $1,9502023-03-30 HIGH 7.8 CVE-2022-28686 This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). U… Aveva Edge 2020.2.00.40+ Fix from $1,9502023-03-29 HIGH 7.8 CVE-2022-28687 This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). U… Aveva Edge 2020.2.00.40+ Fix from $1,9502023-03-29 HIGH 7.8 CVE-2022-28688 This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). U… Aveva Edge 2020.2.00.40+ Fix from $1,9502023-03-29 HIGH 7.8 CVE-2023-0213 Elevation of privilege issue in M-Files Installer versions before 22.6 on Windows allows user to gain SYSTEM privileges via DLL hijacking. M Files 22.6+ Fix from $1,9502023-03-29 HIGH 7.8 CVE-2023-28596 Zoom Client for IT Admin macOS installers before version 5.13.5 contain a local privilege escalation vulnerability. A local low-privileged user could… Meetings 5.13.5+ Fix from $1,9502023-03-27 HIGH 7.8 CVE-2022-38745 Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code fro… Openoffice 4.1.14+ Fix from $1,9502023-03-24 HIGH 7.8 CVE-2023-28759 An issue was discovered in Veritas NetBackup before 10.0 on Windows. A vulnerability in the way the client validates the path to a DLL prior to loadi… Netbackup 10.0+ Fix from $1,9502023-03-23 HIGH 7.8 CVE-2022-48422 ONLYOFFICE Docs through 7.3 on certain Linux distributions allows local users to gain privileges via a Trojan horse libgcc_s.so.1 in the current work… Document Server after 7.3.0 Fix from $1,9502023-03-19 HIGH 7.8 CVE-2021-31637 An issue found in UwAmp v.1.1, 1.2, 1.3, 2.0, 2.1, 2.2, 2.2.1, 3.0.0, 3.0.1, 3.0.2 allows a remote attacker to execute arbitrary code via a crafted D… Uwamp after 3.0.2 Fix from $1,9502023-03-16 HIGH 8.8 CVE-2022-4313 A vulnerability was reported where through modifying the scan variables, an authenticated user in Tenable products, that has Scan Policy Configuratio… Nessus 10.4.2 / 202212081952+ Fix from $1,9502023-03-15 MEDIUM 5.5 CVE-2023-24578 McAfee Total Protection prior to 16.0.49 allows attackers to elevate user privileges due to DLL sideloading. This could enable a user with lower priv… Total Protection 16.0.49+ Fix from $1,6002023-03-13 MEDIUM 6.7 CVE-2023-25147 An issue in the Trend Micro Apex One agent could allow an attacker who has previously acquired administrative rights via other means to bypass the pr… Apex One 14.0.11960+ Fix from $1,6002023-03-10 CRITICAL 9.8 CVE-2023-25143 An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker to achieve a remote code execu… Apex One 14.0.11960+ Fix from $2,3002023-03-10 HIGH 8.8 CVE-2023-23554 Uncontrolled search path element vulnerability exists in pg_ivm versions prior to 1.5.1. When refreshing an IMMV, pg_ivm executes functions without s… Pg Ivm 1.5.1+ Fix from $1,9502023-03-07 HIGH 7.3 CVE-2023-26266 In AFL++ 4.05c, the CmpLog component uses the current working directory to resolve and execute unprefixed fuzzing targets, allowing code execution. Afl\+\+ Patch available Fix from $1,9502023-02-21 HIGH 7.8 CVE-2022-32972 Infoblox BloxOne Endpoint for Windows through 2.2.7 allows DLL injection that can result in local privilege escalation. Bloxone Endpoint 2.3.3+ Fix from $1,9502023-02-17 HIGH 7.3 CVE-2022-37340 Uncontrolled search path in some Intel(R) QAT drivers for Windows before version 1.6 may allow an authenticated user to potentially enable escalation… Quickassist Technology 1.6 / 4.17+ Fix from $1,9502023-02-16 HIGH 7.8 CVE-2022-41314 Uncontrolled search path in some Intel(R) Network Adapter installer software may allow an authenticated user to potentially enable escalation of priv… Administrative Tools For Intel Network Adapters 4.01 / 27.3+ Fix from $1,9502023-02-16 HIGH 7.3 CVE-2022-37329 Uncontrolled search path in some Intel(R) Quartus(R) Prime Pro and Standard Edition software may allow an authenticated user to potentially enable es… Fpga Software Development Kit 21.1 / 21.3+ Fix from $1,9502023-02-16 HIGH 7.8 CVE-2022-36398 Uncontrolled search path in the Intel(R) Battery Life Diagnostic Tool software before version 2.2.0 may allow an authenticated user to potentially en… Battery Life Diagnostic Tool Mitigation only Fix from $1,9502023-02-16 HIGH 7.3 CVE-2022-26345 Uncontrolled search path element in the Intel(R) oneAPI Toolkit OpenMP before version 2022.1 may allow an authenticated user to potentially enable es… Openmp 2022.1+ Fix from $1,9502023-02-16 HIGH 7.3 CVE-2022-26421 Uncontrolled search path element in the Intel(R) oneAPI DPC++/C++ Compiler Runtime before version 2022.0 may allow an authenticated user to potential… Oneapi Dpc\+\+\/c\+\+ Compiler Runtime 2022.0+ Fix from $1,9502023-02-16 HIGH 7.3 CVE-2022-26425 Uncontrolled search path element in the Intel(R) oneAPI Collective Communications Library (oneCCL) before version 2021.6 for Intel(R) oneAPI Base Too… Oneapi Collective Communications Library 2021.6+ Fix from $1,9502023-02-16 HIGH 7.3 CVE-2022-26512 Uncontrolled search path element in the Intel(R) FPGA Add-on for Intel(R) oneAPI Base Toolkit before version 2022.2 may allow an authenticated user t… Fpga Add On 2022.2+ Fix from $1,9502023-02-16 HIGH 7.3 CVE-2022-25905 Uncontrolled search path element in the Intel(R) oneAPI Data Analytics Library (oneDAL) before version 2021.5 for Intel(R) oneAPI Base Toolkit may al… Oneapi Data Analytics Library 2021.5+ Fix from $1,9502023-02-16 HIGH 7.3 CVE-2022-26032 Uncontrolled search path element in the Intel(R) Distribution for Python programming language before version 2022.1 for Intel(R) oneAPI Toolkits may … Distribution For Python 2022.1+ Fix from $1,9502023-02-16