Skip to main content

CWE archive

CWE-426 CVEs

Programmatic archive

655 CVEs tagged with CWE-42624 Critical, 536 High, 81 Medium, 13 Low, 1 Unrated.

CVE-2022-38060

Published Dec 21, 2022

A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A misconfiguration in /etc/sudoers within a container can lead to i…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31253

Published Nov 9, 2022

A Untrusted Search Path vulnerability in openldap2 of openSUSE Factory allows local attackers with control of the ldap user or group to change ownership of arbitrary directory ent…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3734

Published Oct 28, 2022

A vulnerability was found in a port or fork of Redis. It has been declared as critical. This vulnerability affects unknown code in the library C:/Program Files/Redis/dbghelp.dll.…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0074

Published Oct 27, 2022

Untrusted Search Path vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server Container allows Privilege Escalation. This affects versions from 1…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2021-3305

Published Oct 18, 2022

Beijing Feishu Technology Co., Ltd Feishu v3.40.3 was discovered to contain an untrusted search path vulnerability.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39245

Published Sep 26, 2022

Mist is the command-line interface for the makedeb Package Repository. Prior to version 0.9.5, a user-provided `sudo` binary via the `PATH` variable can allow a local user to run…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36403

Published Sep 8, 2022

Untrusted search path vulnerability in the installer of Device Software Manager prior to Ver.2.20.3.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecifie…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36070

Published Sep 7, 2022

Poetry is a dependency manager for Python. To handle dependencies that come from a Git repository, Poetry executes various commands, e.g. `git config`. These commands are being ex…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31012

Published Jul 12, 2022

Git for Windows is a fork of Git that contains Windows-specific patches. This vulnerability in versions prior to 2.37.1 lets Git for Windows' installer execute a binary into `C:\m…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36666

Published Jul 12, 2022

An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privileges via the inSyncDecommission.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28964

Published May 20, 2022

An arbitrary file write vulnerability in Avast Premium Security before v21.11.2500 (build 21.11.6809.528) allows attackers to cause a Denial of Service (DoS) via a crafted DLL fil…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-26184

Published Mar 21, 2022

Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute Poetry commands in a direct…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-26183

Published Mar 21, 2022

PNPM v6.15.1 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute PNPM commands in a directory…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-25366

Published Feb 19, 2022

Cryptomator through 1.6.5 allows DYLIB injection because, although it has the flag 0x1000 for Hardened Runtime, it has the com.apple.security.cs.disable-library-validation and com…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-45975

Published Jan 26, 2022

In ListCheck.exe in Acer Care Center 4.x before 4.00.3038, a vulnerability in the loading mechanism of Windows DLLs could allow a local attacker to perform a DLL hijacking attack.…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 251-275 of 655 CVEsPage 11 of 27