Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
HIGH 7.8 CVE-2022-30697 Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 3640 Snap Deploy 6+ Fix from $1,9502022-05-16 HIGH 7.3 CVE-2022-22139 Uncontrolled search path in the Intel(R) XTU software before version 7.3.0.33 may allow an authenticated user to potentially enable escalation of pri… Extreme Tuning Utility 7.3.0.33+ Fix from $1,9502022-05-12 HIGH 7.3 CVE-2022-28247 Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an uncontrolled searc… Acrobat Dc after 22.001.20085 Fix from $1,9502022-05-11 MEDIUM 6.7 CVE-2022-0025 A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local… Cortex Xdr Agent 7.7.1.62043+ Fix from $1,6002022-05-11 HIGH 7.3 CVE-2021-34606 A vulnerability exists in XINJE XD/E Series PLC Program Tool in versions up to v3.5.1 that can allow an authenticated, local attacker to load a malic… Xd\/e Series Plc Program Tool after 3.5.1 Fix from $1,9502022-05-11 HIGH 7.8 CVE-2021-42743 A misconfiguration in the node default path allows for local privilege escalation from a lower privileged user to the Splunk user in Splunk Enterpris… Splunk 8.1.1+ Fix from $1,9502022-05-06 HIGH 7.8 CVE-2022-28714 On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13… Big Ip Access Policy Manager Mitigation only Fix from $1,9502022-05-05 HIGH 7.8 CVE-2021-20051 SonicWall Global VPN Client 4.10.7.1117 installer (32-bit and 64-bit) and earlier versions have a DLL Search Order Hijacking vulnerability in one of … Global Vpn Client after 4.10.7.1117 Fix from $1,9502022-05-04 HIGH 7.8 CVE-2022-28792 DLL hijacking vulnerability in Gear IconX PC Manager prior to version 2.1.220405.51 allows attacker to execute arbitrary code. The patch adds proper … Gear Iconx Pc Manager 2.1.220405.51+ Fix from $1,9502022-05-03 HIGH 7.8 CVE-2022-0192 A DLL search path vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow privilege escalation. Pcmanager 4.0.40.2175+ Fix from $1,9502022-04-22 HIGH 7.8 CVE-2022-24765 Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untruste… Git 2.35.2 / 13.4+ Fix from $1,9502022-04-12 HIGH 7.8 CVE-2022-24767 GitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user account. Visual Studio 2017 2.35.2 / 15.9.46+ Fix from $1,9502022-04-12 HIGH 7.3 CVE-2022-23449 A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 U… Simatic Energy Manager Basic 7.3+ Fix from $1,9502022-04-12 HIGH 7.8 CVE-2022-27842 DLL hijacking vulnerability in Smart Switch PC prior to version 4.2.22022_4 allows attacker to execute abitrary code. Smart Switch Pc 4.2.22022_4+ Fix from $1,9502022-04-11 HIGH 7.8 CVE-2022-27843 DLL hijacking vulnerability in Kies prior to version 2.6.4.22014_2 allows attacker to execute abitrary code. Kies 2.6.4.22014_2+ Fix from $1,9502022-04-11 HIGH 7.8 CVE-2022-28541 Uncontrolled search path element vulnerability in Samsung Update prior to version 3.0.77.0 allows attackers to execute arbitrary code as Samsung Upda… Update 3.0.77.0+ Fix from $1,9502022-04-11 HIGH 7.8 CVE-2022-28779 Uncontrolled search path element vulnerability in Samsung Android USB Driver windows installer program prior to version 1.7.50 allows attacker to exe… Android Usb Driver Windows Installer 1.7.50+ Fix from $1,9502022-04-11 HIGH 7.3 CVE-2022-25154 A DLL hijacking vulnerability in Samsung portable SSD T5 PC software before 1.6.9 could allow a local attacker to escalate privileges. (An attacker m… T5 Firmware 1.6.9+ Fix from $1,9502022-04-05 HIGH 7.8 CVE-2022-1098 Delta Electronics DIAEnergie (all versions prior to 1.8.02.004) are vulnerable to a DLL hijacking condition. When combined with the Incorrect Default… Diaenergie 1.8.02.004+ Fix from $1,9502022-04-01 HIGH 7.8 CVE-2022-24426 Dell Command | Update, Dell Update, and Alienware Update version 4.4.0 contains a Local Privilege Escalation Vulnerability in the Advanced Driver Res… Alienware Update Patch available Fix from $1,9502022-04-01 HIGH 7.8 CVE-2022-25348 Untrusted search path vulnerability in AttacheCase ver.4.0.2.7 and earlier allows an attacker to gain privileges and execute arbitrary code via a Tro… Attachecase after 4.0.2.7 Fix from $1,9502022-03-31 HIGH 7.8 CVE-2022-28128 Untrusted search path vulnerability in AttacheCase ver.3.6.1.0 and earlier allows an attacker to gain privileges and execute arbitrary code via a Tro… Attachecase after 3.6.1.0 Fix from $1,9502022-03-31 HIGH 7.8 CVE-2022-22996 The G-RAID 4/8 Software Utility setups for Windows were affected by a DLL hijacking vulnerability. Successful exploitation could lead to arbitrary co… Sandisk Professional G Raid 4\/8 Software Utility 6.2.0.16-2 / 300520006-2+ Fix from $1,9502022-03-30 HIGH 7.3 CVE-2021-44226 Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\… Synapse 3.7.0228.022817+ Fix from $1,9502022-03-23 MEDIUM 6.7 CVE-2020-25182 Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries. Uncontrolled loading of dynamic libraries … Epas Gtw Firmware 1.1.0+ Fix from $1,6002022-03-18 HIGH 7.8 CVE-2022-25969 The installer of WPS Office Version 10.8.0.6186 insecurely load VERSION.DLL (or some other DLLs), allowing an attacker to execute arbitrary code with… Wps Office Mitigation only Fix from $1,9502022-03-17 HIGH 7.8 CVE-2022-26081 The installer of WPS Office Version 10.8.0.5745 insecurely load shcore.dll, allowing an attacker to execute arbitrary code with the privilege of the … Wps Office Mitigation only Fix from $1,9502022-03-17 HIGH 7.8 CVE-2022-26511 WPS Presentation 11.8.0.5745 insecurely load d3dx9_41.dll when opening .pps files('current directory type' DLL loading). Wps Presentation Mitigation only Fix from $1,9502022-03-17 HIGH 7.8 CVE-2022-20001 fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary code execution. git repositories can contain per-re… Fedora after 3.3.1 Fix from $1,9502022-03-14 HIGH 7.8 CVE-2022-23401 The following Yokogawa Electric products contain insecure DLL loading issues. CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions f… Centum Cs 3000 Firmware Mitigation only Fix from $1,9502022-03-11