Skip to main content

CWE archive

CWE-427 CVEs

Programmatic archive

1,188 CVEs tagged with CWE-42724 Critical, 799 High, 357 Medium, 6 Low, 2 Unrated.

CVE-2025-30167

Published Jun 3, 2025

Jupyter Core is a package for the core common functionality of Jupyter projects. When using Jupyter Core prior to version 5.8.0 on Windows, the shared `%PROGRAMDATA%` directory is…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42191

Published May 30, 2025

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42190

Published May 30, 2025

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-5129

Published May 24, 2025

A vulnerability has been found in Sangfor 零信任访问控制系统 aTrust 2.3.10.60 and classified as critical. Affected by this vulnerability is an unknown functionality in the library MSASN1.d…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-13946

Published May 22, 2025

DLL's are not digitally signed when loaded in ASPECT's configuration toolset exposing the application to binary planting during device commissioning.This issue affects ASPECT-Ente…

CVSS 7.1 · High

CVE-2025-2272

Published May 22, 2025

Uncontrolled Search Path Element vulnerability in Forcepoint FIE Endpoint allows Privilege Escalation, Code Injection, Hijacking a privileged process.This issue affects FIE Endpoi…

CVSS 7.3 · High

CVE-2025-27997

Published May 21, 2025

An issue in Blizzard Battle.net v2.40.0.15267 allows attackers to escalate privileges via placing a crafted shell script or executable into the C:\ProgramData directory.

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-4769

Published May 16, 2025

A vulnerability classified as critical was found in CBEWIN Anytxt Searcher 1.3.1128.0. This vulnerability affects unknown code of the file ATService.exe. The manipulation leads to…

CVSS 7.3 · High

CVE-2025-43553

Published May 13, 2025

Substance3D - Modeler versions 1.21.0 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-21099

Published May 13, 2025

Uncontrolled search path for some Intel(R) Graphics software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS 5.4 · Medium

CVE-2025-20108

Published May 13, 2025

Uncontrolled search path element for some Intel(R) Network Adapter Driver installers for Windows 11 before version 29.4 may allow an authenticated user to potentially enable escal…

CVSS 5.4 · Medium

CVE-2025-20043

Published May 13, 2025

Uncontrolled search path for some Intel(R) RealSense™ SDK software before version 2.56.2 may allow an authenticated user to potentially enable escalation of privilege via local ac…

CVSS 5.4 · Medium

CVE-2025-20041

Published May 13, 2025

Uncontrolled search path for some Intel(R) Graphics software for Intel(R) Arc™ graphics and Intel(R) Iris(R) Xe graphics before version 32.0.101.6325/32.0.101.6252 may allow an au…

CVSS 5.4 · Medium

CVE-2025-20015

Published May 13, 2025

Uncontrolled search path element for some Intel(R) Ethernet Connection software before version 29.4 may allow an authenticated user to potentially enable escalation of privilege v…

CVSS 5.4 · Medium

CVE-2024-47800

Published May 13, 2025

Uncontrolled search path for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS 5.4 · Medium

CVE-2024-47795

Published May 13, 2025

Uncontrolled search path for some Intel(R) oneAPI DPC++/C++ Compiler software before version 2025.0.0 may allow an authenticated user to potentially enable escalation of privilege…

CVSS 5.4 · Medium

CVE-2024-46895

Published May 13, 2025

Uncontrolled search path for some Intel(R) Arc™ & Iris(R) Xe graphics software before version 32.0.101.6083/32.0.101.5736 may allow an authenticated user to potentially enable…

CVSS 5.4 · Medium

CVE-2024-39833

Published May 13, 2025

Uncontrolled search path for some Intel(R) QAT software before version 2.3.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS 5.4 · Medium

CVE-2024-31073

Published May 13, 2025

Uncontrolled search path for some Intel(R) oneAPI Level Zero software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS 5.4 · Medium

CVE-2023-31358

Published May 13, 2025

A DLL hijacking vulnerability in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-32917

Published May 13, 2025

Privilege escalation in jar_signature agent plugin in Checkmk versions <2.4.0b7 (beta), <2.3.0p32, <2.2.0p42, and 2.1.0p49 (EOL) allow user with write access to JAVA_HOME/bin dire…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-4539

Published May 11, 2025

A vulnerability was found in Hainan ToDesk 4.7.6.3. It has been declared as critical. This vulnerability affects unknown code in the library profapi.dll of the component DLL File…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort
Showing 276-300 of 1,188 CVEsPage 12 of 48