Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
HIGH 7.3 CVE-2026-4158 KeePassXC OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers … Mitigation only Fix from $1,9502026-04-11 HIGH 7.8 CVE-2026-28704 Emocheck insecurely loads Dynamic Link Libraries (DLLs). If a crafted DLL file is placed to the same directory, an arbitrary code may be executed wit… Emocheck Mitigation only Fix from $1,9502026-04-10 HIGH 8.8 CVE-2026-30478 A Dynamic-link Library Injection vulnerability in GatewayGeo MapServer for Windows version 5 allows attackers to escalate privileges via a crafted ex… Mitigation only Fix from $1,9502026-04-09 HIGH 7.8 CVE-2026-40031 MemProcFS before 5.17 contains multiple unsafe library-loading patterns that enable DLL and shared-library hijacking across six attack surfaces, incl… Memprocfs 5.17+ Fix from $1,9502026-04-08 HIGH 7.0 CVE-2025-14821 A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and man… Hardened Images 0.12.0+ Fix from $1,9502026-04-07 MEDIUM 6.7 CVE-2026-28728 Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42902. True Image 2026+ Fix from $1,6002026-04-02 MEDIUM 6.7 CVE-2026-27774 Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42902. True Image 2026+ Fix from $1,6002026-04-02 HIGH 7.8 CVE-2026-5271 pymanager included the current working directory in sys.path meaning modules could be shadowed by modules in the current working directory. As a resu… Pymanager No fix yet Fix from $1,9502026-04-01 HIGH 7.8 CVE-2026-3775 The application's update service, when checking for updates, loads certain system libraries from a search path that includes directories writable by … Pdf Editor after 2025.3.0.35737 Fix from $1,9502026-04-01 HIGH 7.8 CVE-2026-22561 Uncontrolled search path elements in Anthropic Claude for Windows installer (Claude Setup.exe) versions prior to 1.1.3363 allow local privilege escal… Claude 1.1.3363+ Fix from $1,9502026-03-31 HIGH 7.8 CVE-2026-34054 vcpkg is a free and open-source C/C++ package manager. Prior to version 3.6.1#3, vcpkg's Windows builds of OpenSSL set openssldir to a path on the bu… Patch available Fix from $1,9502026-03-31 HIGH 7.0 CVE-2026-4962 A security flaw has been discovered in UltraVNC up to 1.6.4.0. Affected by this issue is some unknown functionality in the library version.dll of the… Ultravnc after 1.6.4.0 Fix from $1,9502026-03-27 HIGH 7.8 CVE-2026-28760 The installer of RATOC RAID Monitoring Manager for Windows searches the current directory to load certain DLLs. If a user is directed to place a craf… Mitigation only Fix from $1,9502026-03-26 HIGH 7.8 CVE-2026-26306 The installer for OM Workspace (Windows Edition) Ver 2.4 and earlier insecurely loads Dynamic Link Libraries (DLLs), which could allow an attacker to… Mitigation only Fix from $1,9502026-03-25 HIGH 7.0 CVE-2026-4546 A weakness has been identified in Flos Freeware Notepad2 4.2.25. This impacts an unknown function in the library TextShaping.dll. Executing a manipul… Notepad2 No fix yet Fix from $1,9502026-03-22 HIGH 7.0 CVE-2026-4545 A security flaw has been discovered in Flos Freeware Notepad2 4.2.25. This affects an unknown function in the library PROPSYS.dll. Performing a manip… Notepad2 Mitigation only Fix from $1,9502026-03-22 HIGH 7.8 CVE-2026-33156 ScreenToGif is a screen recording tool. In versions from 2.42.1 and prior, ScreenToGif is vulnerable to DLL sideloading via version.dll . When the po… Screentogif after 2.42.1 Fix from $1,9502026-03-20 HIGH 8.8 CVE-2025-69784 A local, non-privileged attacker can abuse a vulnerable IOCTL interface exposed by the OpenEDR 2.5.1.0 kernel driver to modify the DLL injection path… Openedr No fix yet Fix from $1,9502026-03-16 HIGH 7.8 CVE-2026-2713 IBM Trusteer Rapport installer 3.5.2309.290 IBM Trusteer Rapport could allow a local attacker to execute arbitrary code on the system, caused by DLL … Trusteer Rapport Mitigation only Fix from $1,9502026-03-10 MEDIUM 5.0 CVE-2026-24317 SAP GUI for Windows allows DLL files to be loaded from arbitrary directories within the application. An unauthenticated attacker could exploit this v… Mitigation only Fix from $1,6002026-03-10 HIGH 7.8 CVE-2026-30896 The installer for Qsee Client versions 1.0.1 and prior insecurely load Dynamic Link Libraries (DLLs). When a user is directed to place some malicious… Qsee Client after 1.0.1 Fix from $1,9502026-03-09 HIGH 7.0 CVE-2026-3787 A weakness has been identified in UltraVNC 1.6.4.0 on Windows. This affects an unknown function in the library cryptbase.dll of the component Windows… Ultravnc Mitigation only Fix from $1,9502026-03-08 MEDIUM 6.3 CVE-2026-28711 Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 4… Cyber Protect 17.0.41186+ Fix from $1,6002026-03-06 MEDIUM 6.3 CVE-2026-28712 Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 4… Cyber Protect 17.0.41186+ Fix from $1,6002026-03-06 HIGH 7.3 CVE-2025-11792 Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) befor… Agent Mitigation only Fix from $1,9502026-03-06 HIGH 8.8 CVE-2026-29610 OpenClaw versions prior to 2026.2.14 contain a command hijacking vulnerability that allows attackers to execute unintended binaries by manipulating P… Openclaw 2026.2.14+ Fix from $1,9502026-03-05 HIGH 7.2 CVE-2026-28456 OpenClaw versions 2026.1.5 prior to 2026.2.14 contain a vulnerability in the Gateway in which it does not sufficiently constrain configured hook modu… Openclaw 2026.2.14+ Fix from $1,9502026-03-05 HIGH 8.0 CVE-2025-15558 Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exist by default. A low-privilege… Command Line Interface after 29.1.5 Fix from $1,9502026-03-04 MEDIUM 6.7 CVE-2026-22270 Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an uncontrolled search path element vulnerability.… Powerscale Onefs 9.10.1.6 / 9.13.0.0+ Fix from $1,6002026-03-04 HIGH 7.8 CVE-2026-24502 Dell Command | Intel vPro Out of Band, versions prior to 4.7.0, contain an Uncontrolled Search Path Element vulnerability. A low privileged attacker … Command \| Intel Vpro Out Of Band 4.7.0+ Fix from $1,9502026-03-03