Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
HIGH 7.3 CVE-2026-23755 D-Link D-View 8 versions 2.0.1.107 and below contain an uncontrolled search path vulnerability in the installer. When executed with elevated privileg… D View 8 after 2.0.1.107 Fix from $1,9502026-01-21 HIGH 7.8 CVE-2026-24016 The installer of ServerView Agents for Windows provided by Fsas Technologies Inc. may insecurely load Dynamic Link Libraries. Arbitrary code may be e… Mitigation only Fix from $1,9502026-01-21 HIGH 7.3 CVE-2025-33229 NVIDIA Nsight Visual Studio for Windows contains a vulnerability in Nsight Monitor where an attacker can execute arbitrary code with the same privile… Cuda Toolkit 13.1.0+ Fix from $1,9502026-01-20 MEDIUM 6.7 CVE-2025-33231 NVIDIA Nsight Systems for Windows contains a vulnerability in the application’s DLL loading mechanism where an attacker could cause an uncontrolled s… Cuda Toolkit 13.1.0+ Fix from $1,6002026-01-20 HIGH 8.8 CVE-2025-65118 The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to trick Process Optimization services into loading arbi… Process Optimization 2025+ Fix from $1,9502026-01-16 HIGH 8.4 CVE-2022-50808 CoolerMaster MasterPlus 1.8.5 contains an unquoted service path vulnerability in the MPService that allows local attackers to execute code with eleva… No fix yet Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-21427 The installers for multiple products provided by PIONEER CORPORATION contain an issue with the DLL search path, which may lead to insecurely loading … Mitigation only Fix from $1,9502026-01-08 CRITICAL 9.8 CVE-2019-25268 NREL BEopt 2.8.0.0 contains a DLL hijacking vulnerability that allows attackers to load arbitrary libraries by tricking users into opening applicatio… Mitigation only Fix from $2,3002026-01-08 MEDIUM 6.7 CVE-2025-14625 Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard on Windows (Nios II Command Shell modules), Altera Quartus Prime Lite… Quartus Prime 25.1+ Fix from $1,6002026-01-07 MEDIUM 6.7 CVE-2025-14596 Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro Installer (SFX) on Windows allows Search Order Hijacking.This issue af… Quartus Prime 25.1+ Fix from $1,6002026-01-07 MEDIUM 6.7 CVE-2025-14599 Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard Installer (SFX) on Windows, Altera Quartus Prime Lite  Installer … Quartus Prime 25.1+ Fix from $1,6002026-01-07 MEDIUM 6.7 CVE-2025-14605 Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro on Windows (System Console modules) allows Search Order Hijacking.This iss… Quartus Prime 25.1.1+ Fix from $1,6002026-01-07 HIGH 7.8 CVE-2025-57836 An issue was discovered in Samsung Magician 6.3.0 through 8.3.2 on Windows. The installer creates a temporary folder with weak permissions during ins… Magician after 8.3.2 Fix from $1,9502026-01-05 HIGH 7.1 CVE-2025-66835 TrueConf Client 8.5.2 is vulnerable to DLL hijacking via crafted wfapi.dll allowing local attackers to execute arbitrary code within the user's conte… Trueconf No fix yet Fix from $1,9502025-12-30 HIGH 8.6 CVE-2025-59887 Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the… Ups Companion 3.0+ Fix from $1,9502025-12-26 HIGH 7.8 CVE-2025-67450 Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software package could perform arbit… Ups Companion 3.0+ Fix from $1,9502025-12-26 HIGH 7.8 CVE-2025-14498 TradingView Desktop Electron Uncontrolled Search Path Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate… Mitigation only Fix from $1,9502025-12-23 MEDIUM 6.8 CVE-2025-14405 PDFsam Enhanced Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows phyiscally-present attackers to … Enhanced Mitigation only Fix from $1,6002025-12-23 HIGH 7.8 CVE-2025-14406 Soda PDF Desktop Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate pri… Soda Pdf Mitigation only Fix from $1,9502025-12-23 CRITICAL 9.8 CVE-2023-53959 FileZilla Client 3.63.1 contains a DLL hijacking vulnerability that allows attackers to execute malicious code by placing a crafted TextShaping.dll i… Filezilla Client Mitigation only Fix from $2,3002025-12-19 HIGH 7.8 CVE-2023-53937 Hubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32 wow64log.dll with a malicious… Hubstaff No fix yet Fix from $1,9502025-12-18 HIGH 7.8 CVE-2025-53000 The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions of nbconvert up to and inclu… Nbconvert after 7.16.6 Fix from $1,9502025-12-17 MEDIUM 6.7 CVE-2025-13665 The System Console Utility for Windows is vulnerable to a DLL planting vulnerability Quartus Prime 24.1+ Fix from $1,6002025-12-12 MEDIUM 6.7 CVE-2025-13669 Uncontrolled Search Path Element vulnerability in Altera High Level Synthesis Compiler on Windows allows Search Order Hijacking.This issue affects Hi… High Level Synthesis Compiler after 24.3 Fix from $1,6002025-12-12 MEDIUM 6.7 CVE-2025-13670 The High Level Synthesis Compiler i++ command for Windows is vulnerable to a DLL planting vulnerability High Level Synthesis Compiler after 24.3 Fix from $1,6002025-12-12 MEDIUM 6.7 CVE-2025-13668 A potential security vulnerability in Quartus® Prime Pro Edition Design Software may allow escalation of privilege. Quartus Prime 25.1+ Fix from $1,6002025-12-11 MEDIUM 6.7 CVE-2025-13664 A potential security vulnerability in Quartus® Prime Standard Edition Design Software may allow escalation of privilege. Quartus Prime 24.1+ Fix from $1,6002025-12-11 MEDIUM 6.7 CVE-2025-64994 A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-SetWorkRate instruction prior… Digital Employee Experience 17.1+ Fix from $1,6002025-12-11 MEDIUM 6.7 CVE-2025-64995 A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Exchange-NomadClientHealth-Configur… Digital Employee Experience 3.4+ Fix from $1,6002025-12-11 HIGH 7.8 CVE-2025-34423 MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable admini… Mailenable 10.54+ Fix from $1,9502025-12-10