Skip to main content

CWE archive

CWE-427 CVEs

Programmatic archive

1,188 CVEs tagged with CWE-42724 Critical, 799 High, 357 Medium, 6 Low, 2 Unrated.

CVE-2025-20017

Published Aug 12, 2025

Uncontrolled search path for some Intel(R) oneAPI Toolkit and component software installers may allow an authenticated user to potentially enable escalation of privilege via local…

CVSS 5.4 · Medium

CVE-2025-30033

Published Aug 12, 2025

The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the af…

CVSS 8.5 · High

CVE-2025-53395

Published Aug 4, 2025

Paramount Macrium Reflect through 2025-06-26 allows local attackers to execute arbitrary code with administrator privileges via a crafted .mrimgx backup file and a malicious VSSSv…

CVSS 7.7 · High

CVE-2025-53394

Published Aug 4, 2025

Paramount Macrium Reflect through 2025-06-26 allows attackers to execute arbitrary code with administrator privileges via a crafted .mrimgx or .mrbax backup file and a renamed exe…

CVSS 7.7 · High

CVE-2025-25011

Published Jul 30, 2025

An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions. The vulnerability arises from improper handling…

CVSS 7.0 · High

CVE-2025-0712

Published Jul 30, 2025

An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions. The vulnerability arises from improper handling…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-7676

Published Jul 28, 2025

DLL hijacking of all PE32 executables when run on Windows for ARM64 CPU architecture. This allows an attacker to execute code, if the attacker can plant a DLL in the same director…

CVSS 5.4 · Medium

CVE-2024-13976

Published Jul 25, 2025

A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During the installation of maintenance updates, an attacker with loc…

CVSS 8.5 · High

CVE-2025-7427

Published Jul 22, 2025

Uncontrolled Search Path Element in Arm Development Studio before 2025 may allow an attacker to perform a DLL hijacking attack. Successful exploitation could lead to local arbitra…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1729

Published Jul 17, 2025

A DLL hijacking vulnerability was reported in TrackPoint Quick Menu software that, under certain conditions, could allow a local attacker to escalate privileges.

CVSS 5.4 · Medium

CVE-2025-1700

Published Jul 17, 2025

A DLL hijacking vulnerability was reported in the Motorola Software Fix (Rescue and Smart Assistant) installer that could allow a local attacker to escalate privileges during inst…

CVSS 7.1 · High

CVE-2025-7472

Published Jul 17, 2025

A local privilege escalation vulnerability in the Intercept X for Windows installer prior version 1.22 can lead to a local user gaining system level privileges, if the installer i…

CVSS 7.5 · High

CVE-2025-34109

Published Jul 15, 2025

PSEvents.exe in multiple Panda Security products runs hourly with SYSTEM privileges and loads DLL files from a user-writable directory without proper validation. An attacker with…

CVSS 8.5 · High

CVE-2025-48496

Published Jul 11, 2025

Emerson ValveLink products use a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

CVSS 5.9 · Medium

CVE-2025-36004

Published Jun 25, 2025

IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user to gain elevated privileges due to an unqualified library call in IBM Facsimile Support for i. A malicious actor could cause user-c…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-49144

Published Jun 23, 2025

Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unpr…

CVSS 7.3 · High
evidence mentions
2
Buzz score
16.0

CVE-2025-4981

Published Jun 20, 2025

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sanitize filenames in the archive extractor which allows auth…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-5981

Published Jun 18, 2025

Arbitrary file write as the OSV-SCALIBR user on the host system via a path traversal vulnerability when using OSV-SCALIBR's unpack() function for container images. Particularly, w…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-49158

Published Jun 17, 2025

An uncontrolled search path vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalation privileges on affected installations. Please not…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-49155

Published Jun 17, 2025

An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacker to inject malicious code leading to arbitrary code execut…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-33122

Published Jun 17, 2025

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 could allow a user to gain elevated privileges due to an unqualified library call in IBM Advanced Job Scheduler for i. A malicious actor could ca…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-49148

Published Jun 11, 2025

ClipShare is a lightweight and cross-platform tool for clipboard sharing. Prior to 3.8.5, ClipShare Server for Windows uses the default Windows DLL search order and loads system l…

CVSS 7.3 · High

CVE-2025-5480

Published Jun 6, 2025

Action1 Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Ac…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 251-275 of 1,188 CVEsPage 11 of 48