Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
HIGH 7.3 CVE-2022-26052 Uncontrolled search path element in the Intel(R) MPI Library before version 2021.6 for Intel(R) oneAPI HPC Toolkit may allow an authenticated user to… Mpi Library 2021.6+ Fix from $1,9502023-02-16 HIGH 7.3 CVE-2022-26062 Uncontrolled search path element in the Intel(R) Trace Analyzer and Collector before version 2021.6 for Intel(R) oneAPI HPC Toolkit may allow an auth… Trace Analyzer And Collector 2021.6+ Fix from $1,9502023-02-16 HIGH 7.3 CVE-2022-26076 Uncontrolled search path element in the Intel(R) oneAPI Deep Neural Network (oneDNN) before version 2022.1 may allow an authenticated user to potenti… Oneapi Deep Neural Network 2022.1+ Fix from $1,9502023-02-16 HIGH 7.8 CVE-2022-48077 Genymotion Desktop v3.3.2 was discovered to contain a DLL hijacking vulnerability that allows attackers to escalate privileges and execute arbitrary … Genymotion Desktop Mitigation only Fix from $1,9502023-02-13 HIGH 7.8 CVE-2022-43440 Uncontrolled Search Path Element in Checkmk Agent in Tribe29 Checkmk before 2.1.0p1, before 2.0.0p25 and before 1.6.0p29 on a Checkmk server allows t… Checkmk 1.6.0+ Fix from $1,9502023-02-09 HIGH 7.3 CVE-2022-31611 NVIDIA GeForce Experience contains an uncontrolled search path vulnerability in all its client installers, where an attacker with user level privileg… Geforce Experience 3.27.0.112+ Fix from $1,9502023-02-07 HIGH 7.3 CVE-2022-38136 Uncontrolled search path in the Intel(R) oneAPI DPC++/C++ Compiler for Windows and Intel Fortran Compiler for Windows before version 2022.2.1 for som… Oneapi Dpc\+\+\/c\+\+ Compiler 2022.2.1+ Fix from $1,9502023-02-06 HIGH 8.2 CVE-2023-0400 The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local user to bypass DLP controls when … Data Loss Prevention 11.10.0+ Fix from $1,9502023-02-02 HIGH 7.8 CVE-2023-22358 In versions beginning with 7.2.2 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client Windows Installer. Note: Software… Big Ip Access Policy Manager 7.2.3.1 / 17.0.0.2+ Fix from $1,9502023-02-01 MEDIUM 6.5 CVE-2023-22283 On versions beginning in 7.1.5 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client for Windows. User interaction and ad… Big Ip Access Policy Manager 7.2.3.1 / 17.0.0.2+ Fix from $1,6002023-02-01 HIGH 7.8 CVE-2022-34396 Dell OpenManage Server Administrator (OMSA) version 10.3.0.0 and earlier contains a DLL Injection Vulnerability. A local low privileged authenticated… Openmanage Server Administrator after 10.3.0.0 Fix from $1,9502023-02-01 MEDIUM 6.8 CVE-2022-47632 Razer Synapse before 3.7.0830.081906 allows privilege escalation due to an unsafe installation path, improper privilege management, and improper cert… Synapse 3.7.0830.081906+ Fix from $1,6002023-01-27 HIGH 7.8 CVE-2022-41141 This vulnerability allows local attackers to escalate privileges on affected installations of Windscribe. An attacker must first obtain the ability t… Windscribe Mitigation only Fix from $1,9502023-01-26 HIGH 7.8 CVE-2020-25502 Cybereason EDR version 19.1.282 and above, 19.2.182 and above, 20.1.343 and above, and 20.2.X and above has a DLL hijacking vulnerability, which coul… Endpoint Detection And Response 19.1.282 / 19.2.182+ Fix from $1,9502023-01-20 HIGH 7.8 CVE-2023-0247 Uncontrolled Search Path Element in GitHub repository bits-and-blooms/bloom prior to 3.3.1. Bloom 3.3.1+ Fix from $1,9502023-01-12 HIGH 7.3 CVE-2023-22947 Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an unprivileged local attacker to… Service Provider 3.4.1+ Fix from $1,9502023-01-11 HIGH 7.8 CVE-2022-36930 Zoom Rooms for Windows installers before version 5.13.0 contain a local privilege escalation vulnerability. A local low-privileged user could exploit… Rooms 5.13.0+ Fix from $1,9502023-01-09 HIGH 7.8 CVE-2022-44939 Efs Software Easy Chat Server Version 3.1 was discovered to contain a DLL hijacking vulnerability via the component TextShaping.dll. This vulnerabili… Easy Chat Server No fix yet Fix from $1,9502023-01-06 MEDIUM 5.5 CVE-2022-36314 When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from… Firefox 102.1 / 103.0+ Fix from $1,6002022-12-22 HIGH 7.0 CVE-2022-22736 If Firefox was installed to a world-writable directory, a local privilege escalation could occur when Firefox searched the current directory for syst… Firefox 96.0+ Fix from $1,9502022-12-22 MEDIUM 6.7 CVE-2021-36631 Untrusted search path vulnerability in Baidunetdisk Version 7.4.3 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unsp… Baidunetdisk after 7.4.3 Fix from $1,6002022-12-22 HIGH 7.8 CVE-2022-46330 Squirrel.Windows is both a toolset and a library that provides installation and update functionality for Windows desktop applications. Installers gen… Squirrel.windows after 2.0.1 Fix from $1,9502022-12-21 HIGH 7.8 CVE-2022-42945 DWG TrueViewTM 2023 version has a DLL Search Order Hijacking vulnerability. Successful exploitation by a malicious attacker could result in remote co… Dwg Trueview Mitigation only Fix from $1,9502022-12-19 HIGH 7.8 CVE-2022-43722 A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0). Affected software does not properly secure a folder containing library fi… Sicam Pas\/pqs 7.0+ Fix from $1,9502022-12-13 HIGH 7.8 CVE-2022-29580 There exists a path traversal vulnerability in the Android Google Search app. This is caused by the incorrect usage of uri.getLastPathSegment. A symb… Google Search 13.41+ Fix from $1,9502022-12-13 HIGH 7.8 CVE-2022-38395 HP Support Assistant uses HP Performance Tune-up as a diagnostic tool. HP Support Assistant uses Fusion to launch HP Performance Tune-up. It is possi… Fusion 1.38.2601.0 / 9.11+ Fix from $1,9502022-12-12 MEDIUM 6.7 CVE-2022-3859 An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8. This allows an attacker with admin ac… Agent 5.7.8+ Fix from $1,6002022-11-30 HIGH 7.8 CVE-2022-43751 McAfee Total Protection prior to version 16.0.49 contains an uncontrolled search path element vulnerability due to the use of a variable pointing to … Total Protection 16.0.49+ Fix from $1,9502022-11-23 MEDIUM 6.7 CVE-2022-40746 IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the syste… I Access Client Solutions after 1.1.9.0 Fix from $1,6002022-11-21 HIGH 7.8 CVE-2022-45422 When LG SmartShare is installed, local privilege escalation is possible through DLL Hijacking attack. The LG ID is LVE-HOT-220005. Smart Share No fix yet Fix from $1,9502022-11-21