Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
HIGH 7.8 CVE-2024-36333 A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potentially resulting in arbitrary c… Radeon Software 25.q3.1 / 26.q1+ Fix from $1,9502026-05-15 HIGH 8.5 CVE-2026-7373 Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows a user to gain SYSTEM level control of a Windows host. When st… Mitigation only Fix from $1,9502026-05-15 HIGH 7.0 CVE-2025-62628 Unsafe OpenSSL initialization within some AMD optional tools may allow a local user-privileged attacker to inject a malicious DLL, potentially result… Mitigation only Fix from $1,9502026-05-14 HIGH 7.8 CVE-2024-47091 Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk <2.4.0p29, <2.3.0p47, and 2.2.0 (EOL) allows a local unprivileged user able t… Checkmk Mitigation only Fix from $1,9502026-05-13 HIGH 7.8 CVE-2026-44612 Bytello Share (Windows Edition) installer executable provided by Bytello insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the sa… Mitigation only Fix from $1,9502026-05-13 MEDIUM 6.7 CVE-2026-20772 Uncontrolled search path for some Intel(R) Connectivity Performance Suite software installers before version 50.25.1121.193 within Ring 3: User Appli… Connectivity Performance Suite 50.25.1121.193+ Fix from $1,6002026-05-12 MEDIUM 5.4 CVE-2025-36515 Uncontrolled search path for some AI Playground software before version 3.0.0 alpha within Ring 3: User Applications may allow an escalation of privi… Mitigation only Fix from $1,6002026-05-12 MEDIUM 5.4 CVE-2025-35969 Uncontrolled search path for some Intel(R) Server Firmware Update Utility Software before version 16.0.12. within Ring 3: User Applications may allow… Mitigation only Fix from $1,6002026-05-12 HIGH 7.8 CVE-2026-45004 OpenClaw before 2026.4.23 contains an arbitrary code execution vulnerability in the bundled plugin setup resolver that loads setup-api.js from proces… Openclaw 2026.4.23+ Fix from $1,9502026-05-11 CRITICAL 9.8 CVE-2025-69599 RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control the value of the PATH environment variable. NOTE: th… Mitigation only Fix from $2,3002026-05-08 HIGH 7.8 CVE-2026-44406 ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijac… Zxcloud Irai 7.25.43+ Fix from $1,9502026-05-07 HIGH 7.8 CVE-2026-40004 There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execute arbitrary code locally and … Zxcloud Irai 7.25.43+ Fix from $1,9502026-05-07 HIGH 8.4 CVE-2026-21661 Uncontrolled Search Path Element vulnerability in JohnsonControls AC2000 on Windows allows Leveraging/Manipulating Configuration File Search Paths. … Mitigation only Fix from $1,9502026-05-06 HIGH 7.8 CVE-2026-6788 Uncontrolled Search Path Element vulnerability in WatchGuard Agent on Windows allows Using Malicious Files. Agent 1.25.03.0000+ Fix from $1,9502026-05-06 MEDIUM 6.7 CVE-2026-25852 Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0… Mitigation only Fix from $1,6002026-04-29 MEDIUM 6.1 CVE-2026-41373 OpenClaw before 2026.3.31 contains an incomplete host-env-security-policy.json that fails to restrict compiler binary environment variables, allowing… Openclaw 2026.3.31+ Fix from $1,6002026-04-28 HIGH 7.8 CVE-2026-7279 AVACAST developed by eMPIA Technology, has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a malicious DLL in a specif… Mitigation only Fix from $1,9502026-04-28 HIGH 7.8 CVE-2026-42171 NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attack… Nullsoft Scriptable Install System 3.12+ Fix from $1,9502026-04-24 HIGH 8.0 CVE-2026-32172 Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network. Power Apps Mitigation only Fix from $1,9502026-04-23 HIGH 7.3 CVE-2026-34488 IP Setting Software contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary c… Mitigation only Fix from $1,9502026-04-23 MEDIUM 5.1 CVE-2025-10549 EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the installation directory. A local… Mitigation only Fix from $1,6002026-04-23 HIGH 7.8 CVE-2026-32679 The installers of LiveOn Meet Client for Windows (Downloader5Installer.exe and Downloader5InstallerForAdmin.exe) and the installers of Canon Network … Canonnwcamplugin.exe Mitigation only Fix from $1,9502026-04-23 CRITICAL 9.9 CVE-2026-40342 Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader con… Firebird 3.0.14 / 4.0.7+ Fix from $2,3002026-04-17 HIGH 7.0 CVE-2026-6421 A vulnerability has been found in Mobatek MobaXterm Home Edition up to 26.1. This affects an unknown part in the library msimg32.dll. The manipulatio… Mitigation only Fix from $1,9502026-04-17 CRITICAL 9.9 CVE-2026-22619 Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to arbitrary code execution by an… Intelligent Power Protector 2.00+ Fix from $2,3002026-04-16 HIGH 8.6 CVE-2026-34632 Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in t… Photoshop Installer No fix yet Fix from $1,9502026-04-15 MEDIUM 6.7 CVE-2026-1636 A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a local authenticated user … Mitigation only Fix from $1,6002026-04-15 HIGH 7.3 CVE-2026-4134 During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local… Mitigation only Fix from $1,9502026-04-15 HIGH 7.8 CVE-2026-5397 It has been identified that a vulnerability (CWE-427) exists in the UPS (Uninterruptible Power Supply) management application, whereby improper permi… Mitigation only Fix from $1,9502026-04-15 HIGH 7.8 CVE-2026-5055 NoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges… Nomachine 9.4.14+ Fix from $1,9502026-04-11