Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
HIGH 7.8 CVE-2021-38416 Delta Electronics DIALink versions 1.2.4.0 and prior insecurely loads libraries, which may allow an attacker to use DLL hijacking and takeover the sy… Dialink after 1.2.4.0 Fix from $1,9502021-11-03 HIGH 7.8 CVE-2021-38420 Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged user accounts, which may allow … Dialink after 1.2.4.0 Fix from $1,9502021-11-03 HIGH 7.8 CVE-2021-22037 Under certain circumstances, when manipulating the Windows registry, InstallBuilder uses the reg.exe system command. The full path to the command is … Installbuilder 21.6.0+ Fix from $1,9502021-10-29 HIGH 7.8 CVE-2021-30359 The Harmony Browse and the SandBlast Agent for Browsers installers must have admin privileges to execute some steps during the installation. Because … Harmony Browse 90.08.7405+ Fix from $1,9502021-10-22 HIGH 7.1 CVE-2021-38469 Many of the services used by the affected product do not specify full paths for the DLLs they are loading. An attacker can exploit the uncontrolled s… Versiondog 8.0.0+ Fix from $1,9502021-10-22 HIGH 7.8 CVE-2021-42101 An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privil… Apex One Patch available Fix from $1,9502021-10-21 HIGH 7.8 CVE-2021-42102 An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service agents could allow a local attacker to escalate… Apex One Patch available Fix from $1,9502021-10-21 HIGH 7.8 CVE-2021-42103 An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privil… Apex One Patch available Fix from $1,9502021-10-21 HIGH 7.3 CVE-2021-35982 Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Uncontrolle… Acrobat Dc after 21.005.20060 Fix from $1,9502021-09-29 HIGH 7.0 CVE-2021-32466 An uncontrolled search path element privilege escalation vulnerability in Trend Micro HouseCall for Home Networks version 5.3.1225 and below could al… Housecall For Home Networks after 5.3.1225 Fix from $1,9502021-09-29 HIGH 7.3 CVE-2021-40981 ASUS ROG Armoury Crate Lite before 4.2.10 allows local users to gain privileges by placing a Trojan horse file in the publicly writable %PROGRAMDATA%… Armoury Crate Lite Service 4.2.10+ Fix from $1,9502021-09-27 HIGH 7.8 CVE-2021-28130 Dr.Web Firewall 12.5.2.4160 on Windows incorrectly restricts applications signed by Dr.Web. A DLL for a custom payload within a legitimate binary (e.… Security Space No fix yet Fix from $1,9502021-09-24 HIGH 7.8 CVE-2021-26750 DLL hijacking in Panda Agent <=1.16.11 in Panda Security, S.L.U. Panda Adaptive Defense 360 <= 8.0.17 allows attacker to escalate privileges via mali… Panda Adaptive Defense 360 after 8.0.17 Fix from $1,9502021-09-23 HIGH 7.8 CVE-2021-31847 Improper access control vulnerability in the repair process for McAfee Agent for Windows prior to 5.7.4 could allow a local attacker to perform a DLL… Agent 5.7.4+ Fix from $1,9502021-09-22 HIGH 7.8 CVE-2021-36216 LINE for Windows 6.2.1.2289 and before allows arbitrary code execution via malicious DLL injection. Line after 6.2.1.2289 Fix from $1,9502021-09-08 HIGH 7.3 CVE-2021-28581 Adobe Creative Cloud Desktop 3.5 (and earlier) is affected by an uncontrolled search path vulnerability that could result in elevation of privileges.… Creative Cloud after 5.3 Fix from $1,9502021-09-08 HIGH 7.8 CVE-2021-22775 A CWE-427: Uncontrolled Search Path Element vulnerability exists in GP-Pro EX,V4.09.250 and prior, that could cause local code execution with elevate… Gp Pro Ex after 4.09.250 Fix from $1,9502021-09-02 HIGH 7.8 CVE-2021-20793 Untrusted search path vulnerability in the installer of Sony Audio USB Driver V1.10 and prior and the installer of HAP Music Transfer Ver.1.3.0 and p… Audio Usb Driver after 1.10 Fix from $1,9502021-08-26 HIGH 7.8 CVE-2021-28594 Adobe Creative Cloud Desktop Application (installer) version 2.4 (and earlier) is affected by an Uncontrolled Search Path Element vulnerability. An u… Creative Cloud Desktop Application 2.5+ Fix from $1,9502021-08-24 HIGH 7.3 CVE-2021-28636 Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an Uncontrolle… Acrobat Dc after 21.005.20054 Fix from $1,9502021-08-20 HIGH 7.8 CVE-2021-28595 Adobe Dimension version 3.4 (and earlier) is affected by an Uncontrolled Search Path Element element. An unauthenticated attacker could leverage this… Dimension after 3.4 Fix from $1,9502021-08-20 HIGH 7.3 CVE-2021-37617 The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. The Nextcloud Desktop Client invokes its uninstall… Desktop 3.3.0+ Fix from $1,9502021-08-18 HIGH 7.8 CVE-2021-3633 A DLL preloading vulnerability was reported in Lenovo Driver Management prior to version 2.9.0719.1104 that could allow privilege escalation. Drivers Management 2.9.0719.1104+ Fix from $1,9502021-08-17 HIGH 7.8 CVE-2021-38086 Acronis Cyber Protect 15 for Windows prior to build 27009 and Acronis Agent for Windows prior to build 26226 allowed local privilege escalation via D… Cyber Protect 15+ Fix from $1,9502021-08-12 HIGH 7.8 CVE-2021-36770 Encode.pm, as distributed in Perl through 5.34.0, allows local users to gain privileges via a Trojan horse Encode::ConfigLocal library (in the curren… Fedora 3.12+ Fix from $1,9502021-08-11 HIGH 7.8 CVE-2021-38571 An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows DLL hijacking, aka CNVD-C-2021-68000 and CNVD-C-2021-68502. Foxit Reader 9.7.5.29616 / 10.1.4+ Fix from $1,9502021-08-11 HIGH 7.8 CVE-2021-0160 Uncontrolled search path in some Intel(R) NUC Pro Chassis Element AverMedia Capture Card drivers before version 3.0.64.143 may allow an authenticated… Avermedia Capture Card 3.0.64.143+ Fix from $1,9502021-08-11 HIGH 7.8 CVE-2021-32580 Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to DLL hijacking. True Image Mitigation only Fix from $1,9502021-08-05 HIGH 7.3 CVE-2021-1593 A vulnerability in Cisco Packet Tracer for Windows could allow an authenticated, local attacker to perform a DLL injection attack on an affected devi… Packet Tracer Mitigation only Fix from $1,9502021-08-04 HIGH 7.8 CVE-2020-18173 A DLL injection vulnerability in 1password.dll of 1Password 7.3.712 allows attackers to execute arbitrary code. 1password No fix yet Fix from $1,9502021-07-26