Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
HIGH 7.8 CVE-2026-25191 The installer of FinalCode Client provided by Digital Arts Inc. contains an issue with the DLL search path. If a user is directed to place a maliciou… Mitigation only Fix from $1,9502026-02-26 HIGH 7.3 CVE-2026-3091 An uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read or write arbitrary files and… Presto Client 2.1.3-0672+ Fix from $1,9502026-02-24 HIGH 7.8 CVE-2026-21420 Dell Repository Manager (DRM), versions prior to 3.4.8, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with lo… Repository Manager 3.4.8+ Fix from $1,9502026-02-23 HIGH 7.8 CVE-2026-2492 TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escal… Patch available Fix from $1,9502026-02-20 HIGH 7.3 CVE-2026-2040 PDF-XChange Editor TrackerUpdate Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers… Mitigation only Fix from $1,9502026-02-20 MEDIUM 5.5 CVE-2026-26097 Uncontrolled Search Path Element in Owl opds 2.2.0.4 allows Leveraging/Manipulating Configuration File Search Paths via a crafted network request. Opds Talon Mitigation only Fix from $1,6002026-02-20 MEDIUM 5.5 CVE-2026-26098 Uncontrolled Search Path Element in Owl opds 2.2.0.4 allows Leveraging/Manipulating Configuration File Search Paths via a crafted network request. Opds Talon Mitigation only Fix from $1,6002026-02-20 MEDIUM 5.5 CVE-2026-26099 Uncontrolled Search Path Element in Owl opds 2.2.0.4 allows Leveraging/Manipulating Configuration File Search Paths via a crafted network request. Opds Talon Mitigation only Fix from $1,6002026-02-20 HIGH 7.8 CVE-2026-26050 The installer for ジョブログ集計/分析ソフトウェア RICOHジョブログ集計ツール versions prior to Ver.1.3.7 contains an issue with the DLL search path, w… Mitigation only Fix from $1,9502026-02-20 HIGH 7.0 CVE-2026-2538 A security flaw has been discovered in Flos Freeware Notepad2 4.2.22/4.2.23/4.2.24/4.2.25. Affected is an unknown function in the library Msimg32.dll… Mitigation only Fix from $1,9502026-02-16 HIGH 7.0 CVE-2026-2516 A vulnerability was identified in Unidocs ezPDF DRM Reader and ezPDF Reader 2.0/3.0.0.4. This affects an unknown part in the library SHFOLDER.dll. Su… Mitigation only Fix from $1,9502026-02-15 HIGH 7.3 CVE-2025-54519 A DLL hijacking vulnerability in Doc Nav could allow a local attacker to achieve privilege escalation, potentially resulting in arbitrary code execut… Mitigation only Fix from $1,9502026-02-12 HIGH 7.8 CVE-2026-25676 The installer of M-Track Duo HD version 1.0.0 contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries… Mitigation only Fix from $1,9502026-02-12 HIGH 8.0 CVE-2026-2360 PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a custom operator in the public schema and… Mitigation only Fix from $1,9502026-02-11 HIGH 8.0 CVE-2026-2361 PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a temporary view based on a function conta… Mitigation only Fix from $1,9502026-02-11 HIGH 7.3 CVE-2025-52541 A DLL hijacking vulnerability in Vivado could allow a local attacker to achieve privilege escalation, potentially resulting in arbitrary code executi… Mitigation only Fix from $1,9502026-02-11 HIGH 7.8 CVE-2025-48503 A DLL hijacking vulnerability in the AMD Software Installer could allow an attacker to achieve privilege escalation potentially resulting in arbitrar… Mitigation only Fix from $1,9502026-02-11 MEDIUM 6.7 CVE-2025-32452 Uncontrolled search path for some AI Playground before version 2.6.1 beta within Ring 3: User Applications may allow an escalation of privilege. Unpr… Mitigation only Fix from $1,6002026-02-10 MEDIUM 6.7 CVE-2025-20106 Uncontrolled search path in some software installer for some VTune(TM) Profiler software and Intel(R) oneAPI Base Toolkits before version 2025.0. wit… Mitigation only Fix from $1,6002026-02-10 HIGH 7.0 CVE-2025-15569 A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The impacted element is the function get_system_dpi of the file platform/x11/win_main… Mitigation only Fix from $1,9502026-02-10 HIGH 7.8 CVE-2026-25655 A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP2). The affected application permits improper modification of a configuration… Sinec Nms 4.0+ Fix from $1,9502026-02-10 HIGH 7.8 CVE-2026-25656 A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3), User Management Component (UMC) (All versions < V2.15.2.1). The affected … Sinec Nms 2.15.2.1+ Fix from $1,9502026-02-10 HIGH 7.8 CVE-2026-23740 Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, when as… Certified Asterisk 20.18.2 / 21.12.1+ Fix from $1,9502026-02-06 HIGH 8.8 CVE-2026-23741 Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the ast… Asterisk 20.18.2 / 21.12.1+ Fix from $1,9502026-02-06 HIGH 7.8 CVE-2026-24694 The installer for Roland Cloud Manager ver.3.1.19 and prior insecurely loads Dynamic Link Libraries (DLLs), which could allow an attacker to execute … Mitigation only Fix from $1,9502026-02-03 HIGH 7.3 CVE-2026-25129 PsySH is a runtime developer console, interactive debugger, and REPL for PHP. Prior to versions 0.11.23 and 0.12.19, PsySH automatically loads and ex… Psysh 0.11.23 / 0.12.19+ Fix from $1,9502026-01-30 HIGH 7.3 CVE-2026-21408 beat-access for Windows version 3.0.3 and prior contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Librari… Mitigation only Fix from $1,9502026-01-27 HIGH 8.9 CVE-2025-30248 DLL hijacking in the WD Discovery Installer in Western Digital WD Discovery 5.2.730 on Windows allows a local attacker to execute arbitrary code via … Mitigation only Fix from $1,9502026-01-26 HIGH 7.1 CVE-2025-71178 Crucial Storage Executive installer versions prior to 11.08.082025.00 contain a DLL preloading vulnerability. During installation, the installer runs… Mitigation only Fix from $1,9502026-01-26 HIGH 7.3 CVE-2026-0776 Discord Client Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privi… Mitigation only Fix from $1,9502026-01-23