Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
HIGH 7.8 CVE-2021-28953 The unofficial C/C++ Advanced Lint extension before 1.9.0 for Visual Studio Code allows attackers to execute arbitrary binaries if the user opens a c… C\/c\+\+ Advanced Lint 1.9.0+ Fix from $1,9502021-03-21 HIGH 7.8 CVE-2020-9367 The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 10.0.486 is vulnerable to DLL Hijacking: dcinventory.exe and dcconfig.exe try … Manageengine Desktop Central Mitigation only Fix from $1,9502021-03-18 HIGH 7.8 CVE-2021-22665 Rockwell Automation DriveTools SP v5.13 and below and Drives AOP v4.12 and below both contain a vulnerability that a local attacker with limited priv… Drivetools Add On Profiles after 5.13 Fix from $1,9502021-03-18 HIGH 7.8 CVE-2020-26155 Multiple files and folders in Utimaco SecurityServer 4.20.0.4 and 4.31.1.0. are installed with Read/Write permissions for authenticated users, which … Block Safe Firmware after 4.33.0 Fix from $1,9502021-03-18 HIGH 7.8 CVE-2021-21518 Dell SupportAssist Client for Consumer PCs versions 3.7.x, 3.6.x, 3.4.x, 3.3.x, Dell SupportAssist Client for Business PCs versions 2.0.x, 2.1.x, 2.2… Supportassist Client Promanage Mitigation only Fix from $1,9502021-03-12 HIGH 7.8 CVE-2021-20674 Untrusted search path vulnerability in Installer of MagicConnect Client program distributed before 2021 March 1 allows an attacker to gain privileges… Magicconnect 2021-03-01+ Fix from $1,9502021-03-12 HIGH 7.8 CVE-2020-28646 ownCloud owncloud/client before 2.7 allows DLL Injection. The desktop client loaded development plugins from certain directories when they were prese… Owncloud Desktop Client 2.7+ Fix from $1,9502021-02-26 HIGH 7.8 CVE-2021-1366 A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, … Anyconnect Secure Mobility Client 4.9.05042+ Fix from $1,9502021-02-17 HIGH 7.8 CVE-2020-24485 Improper conditions check in the Intel(R) FPGA OPAE Driver for Linux before kernel version 4.17 may allow an authenticated user to potentially enable… Trace Analyzer And Collector 2020+ Fix from $1,9502021-02-17 HIGH 7.3 CVE-2020-24451 Uncontrolled search path in the Intel(R) Optane(TM) DC Persistent Memory installer for Windows* before version 1.00.00.3506 may allow an authenticate… Optane Dc Persistent Memory Module Management 1.00.00.3506+ Fix from $1,9502021-02-17 HIGH 7.8 CVE-2020-25238 A vulnerability has been identified in PCS neo (Administration Console) (All versions < V3.1), TIA Portal (V15, V15.1 and V16). Manipulating certain … Simatic Process Control System Neo 3.1+ Fix from $1,9502021-02-09 HIGH 7.8 CVE-2020-35145 Acronis True Image for Windows prior to 2021 Update 3 allowed local privilege escalation due to a DLL hijacking vulnerability in multiple components,… True Image after 2021 Fix from $1,9502021-01-29 HIGH 7.8 CVE-2021-25247 A DLL hijacking vulnerability Trend Micro HouseCall for Home Networks version 5.3.1063 and below could allow an attacker to use a malicious DLL to es… Housecall For Home Networks Mitigation only Fix from $1,9502021-01-27 HIGH 7.5 CVE-2021-3115EPSS 6% Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to… Go 1.14.14 / 1.15.7+ Fix from $1,9502021-01-26 HIGH 7.3 CVE-2021-1280 A vulnerability in the loading mechanism of specific DLLs of Cisco Advanced Malware Protection (AMP) for Endpoints for Windows and Immunet for Window… Advanced Malware Protection For Endpoints 7.3.3 / 7.3.12+ Fix from $1,9502021-01-20 HIGH 7.0 CVE-2021-21008 Adobe Animate version 21.0 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the cont… Animate after 21.0 Fix from $1,9502021-01-13 HIGH 7.0 CVE-2021-21010 InCopy version 15.1.1 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary code executio… Incopy after 15.1.3 Fix from $1,9502021-01-13 HIGH 7.0 CVE-2021-21011 Adobe Captivate 2019 version 11.5.1.499 (and earlier) is affected by an uncontrolled search path element vulnerability that could lead to privilege e… Captivate after 11.5.1.499 Fix from $1,9502021-01-13 HIGH 7.0 CVE-2021-21007 Adobe Illustrator version 25.0 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the … Illustrator after 25.0 Fix from $1,9502021-01-13 HIGH 7.8 CVE-2021-1237 A vulnerability in the Network Access Manager and Web Security Agent components of Cisco AnyConnect Secure Mobility Client for Windows could allow an… Anyconnect Secure Mobility Client 4.9.04043+ Fix from $1,9502021-01-13 HIGH 7.3 CVE-2021-1240 A vulnerability in the loading process of specific DLLs in Cisco Proximity Desktop for Windows could allow an authenticated, local attacker to load a… Proximity 3.1.0+ Fix from $1,9502021-01-13 HIGH 7.8 CVE-2021-20616 Untrusted search path vulnerability in the installer of SKYSEA Client View Ver.1.020.05b to Ver.16.001.01g allows an attacker to gain privileges via … Skysea Client View after 16.001.01g Fix from $1,9502021-01-13 HIGH 7.8 CVE-2020-26050 SaferVPN for Windows Ver 5.0.3.3 through 5.0.4.15 could allow local privilege escalation from low privileged users to SYSTEM via a crafted openssl co… Safervpn after 5.0.4.15 Fix from $1,9502021-01-12 HIGH 7.8 CVE-2020-35483 AnyDesk before 6.1.0 on Windows, when run in portable mode on a system where the attacker has write access to the application directory, allows this … Anydesk 6.1.0+ Fix from $1,9502021-01-11 HIGH 7.8 CVE-2020-5681 Untrusted search path vulnerability in self-extracting files created by EpsonNet SetupManager versions 2.2.14 and earlier, and Offirio SynergyWare Pr… Epsonnet Setupmanager 1.6.1.1 / 2.2.15+ Fix from $1,9502020-12-24 MEDIUM 6.5 CVE-2020-24578 An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It has a misconfigured FTP service that allows a mali… Dsl2888a Firmware No fix yet Fix from $1,6002020-12-22 HIGH 7.8 CVE-2020-29654 Western Digital Dashboard before 3.2.2.9 allows DLL Hijacking that leads to compromise of the SYSTEM account. Dashboard 3.2.2.9+ Fix from $1,9502020-12-12 HIGH 7.0 CVE-2020-24440 Adobe Prelude version 9.0.1 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the con… Prelude after 9.0.1 Fix from $1,9502020-12-11 HIGH 7.0 CVE-2020-24447 Adobe Lightroom Classic version 10.0 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrar… Lightroom after 10.0 Fix from $1,9502020-12-11 HIGH 7.8 CVE-2020-2049 A local privilege escalation vulnerability exists in Palo Alto Networks Cortex XDR Agent on the Windows platform that allows an authenticated local W… Cortex Xdr Agent after 7.2.2 Fix from $1,9502020-12-09