Skip to main content

CWE archive

CWE-427 CVEs

Programmatic archive

1,190 CVEs tagged with CWE-42724 Critical, 801 High, 357 Medium, 6 Low, 2 Unrated.

CVE-2026-8164

Published Jul 28, 2026

Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desktop Client allows Search Order Hijacking. This issue affec…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-16519

Published Jul 24, 2026

A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe sear…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-21770

Published Jul 17, 2026

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-5674

Published Jul 16, 2026

A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio com…

CVSS 8.8 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-42936

Published Jul 15, 2026

The installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be e…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-0487

Published Jul 14, 2026

SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code on the system. Th…

CVSS 8.4 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-48364

Published Jul 13, 2026

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of t…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48363

Published Jul 13, 2026

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of t…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-15515

Published Jul 13, 2026

A security vulnerability has been detected in Tencent PC Manager 18.1.30242.301. This issue affects some unknown processing in the library qmudisk64.sys of the component QMUDisk D…

CVSS 6.4 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-56437

Published Jul 8, 2026

Uncontrolled search path element issue exists in Pupsman versions prior to 3.9.0. If a crafted DLL file is placed in the same folder as the affected installer and the installer is…

CVSS 8.4 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-38972

Published Jul 2, 2026

Notepad3 through 6.25.822.1 contains a DLL search-order hijacking vulnerability in the About-dialog code path in src/Notepad3.c. The application calls LoadLibrary(L"MSFTEDIT.DLL")…

CVSS 7.8 · High
evidence mentions
3
Buzz score
23.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-54672

Published Jun 30, 2026

electron-updater allows for automatic updates for Electron apps. Prior to 26.15.0, AppImage targets built by app-builder-lib could use an empty path component when setting the LD_…

CVSS 7.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2025-13162

Published Jun 23, 2026

Uncontrolled Search Path Element vulnerability in ABB Control Builder A, ABB 800xA for Advant Master. This issue affects Control Builder A: through 1.4/4; 800xA for Advant Master…

CVSS 4.1 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-54232

Published Jun 22, 2026

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.1, the vLLM Dockerfile is vulnerable to a dependency confusion attack through the flashinfe…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-6645

Published Jun 22, 2026

An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows. The application, which typically operat…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-11958

Published Jun 18, 2026

Local privilege escalation by loading DLLs from a shared temporary directory in ANSSI’s DFIR-ORC, versions 10.2.7 and prior. An attacker with prior access to the system, can place…

CVSS 7.3 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-12003

Published Jun 16, 2026

To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks…

CVSS 5.3 · Medium
evidence mentions
9
Buzz score
39.5

CVE-2024-22451

Published Jun 16, 2026

Dell Peripheral Manager, versions from 1.5.1 to 1.7.2, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22447

Published Jun 16, 2026

Dell Peripheral Manager, versions prior to 1.7.3, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through prelo…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-5064

Published Jun 15, 2026

Potential security vulnerabilities have been identified in the HP One Agent for certain HP PC products, which might allow for escalation of privilege and/or denial…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-50100

Published Jun 15, 2026

Multiple printer drivers provided by Ricoh Company, Ltd. and KONICA MINOLTA JAPAN, INC. contain a privilege escalation vulnerability. If this vulnerability is exploited, an attack…

CVSS 8.5 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-11967

Published Jun 12, 2026

MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading a malicious DLL located in the same directory as the portable e…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 1,190 CVEsPage 1 of 48