Skip to main content

CWE archive

CWE-427 CVEs

Programmatic archive

1,198 CVEs tagged with CWE-42724 Critical, 807 High, 359 Medium, 6 Low, 2 Unrated.

CVE-2024-36283

Published Feb 12, 2025

Uncontrolled search path for the Intel(R) Thread Director Visualizer software before version 1.0.1 may allow an authenticated user to potentially enable escalation of privilege vi…

CVSS 5.4 · Medium

CVE-2024-36280

Published Feb 12, 2025

Uncontrolled search path for some Intel(R) High Level Synthesis Compiler software before version 24.2 may allow an authenticated user to potentially enable escalation of privilege…

CVSS 5.4 · Medium

CVE-2024-32938

Published Feb 12, 2025

Uncontrolled search path for some Intel(R) MPI Library for Windows software before version 2021.13 may allow an authenticated user to potentially enable escalation of privilege vi…

CVSS 5.4 · Medium

CVE-2024-29223

Published Feb 12, 2025

Uncontrolled search path for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via l…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24852

Published Feb 12, 2025

Uncontrolled search path in some Intel(R) Ethernet Adapter Complete Driver Pack install before versions 29.1 may allow an authenticated user to potentially enable escalation of pr…

CVSS 5.4 · Medium

CVE-2024-21830

Published Feb 12, 2025

Uncontrolled search path in some Intel(R) VPL software before version 2023.4.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS 5.4 · Medium

CVE-2023-31361

Published Feb 11, 2025

A DLL hijacking vulnerability in AMD Integrated Management Technology (AIM-T) Manageability Service could allow an attacker to achieve privilege escalation potentially resulting i…

CVSS 7.3 · High

CVE-2024-53977

Published Feb 11, 2025

A vulnerability has been identified in ModelSim (All versions < V2025.1), Questa (All versions < V2025.1). An example setup script contained in affected applications allows a spec…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-48091

Published Feb 7, 2025

Tally Prime Edit Log v2.1 was discovered to contain a DLL hijacking vulnerability via the component TextShaping.dll. This vulnerability allows attackers to execute arbitrary code…

CVSS 7.8 · High

CVE-2024-57426

Published Feb 6, 2025

NetMod VPN Client 5.3.1 is vulnerable to DLL injection, allowing an attacker to execute arbitrary code by placing a malicious DLL in a directory where the application loads depend…

CVSS 7.3 · High

CVE-2024-2658

Published Jan 30, 2025

A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauth…

CVSS 8.5 · High

CVE-2024-9499

Published Jan 24, 2025

DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress Win 98SE Dev Kit installer can lead to privilege escalation and arbitrary code execution when…

CVSS 8.6 · High

CVE-2024-9498

Published Jan 24, 2025

DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress SDK installer can lead to privilege escalation and arbitrary code execution when runni…

CVSS 8.6 · High

CVE-2024-9497

Published Jan 24, 2025

DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress 4 SDK installer can lead to privilege escalation and arbitrary code execution when run…

CVSS 8.6 · High

CVE-2024-9496

Published Jan 24, 2025

DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress Dev Kit installer can lead to privilege escalation and arbitrary code execution when r…

CVSS 8.6 · High

CVE-2024-9495

Published Jan 24, 2025

DLL hijacking vulnerabilities, caused by an uncontrolled search path in the CP210x VCP Windows installer can lead to privilege escalation and arbitrary code execution when ru…

CVSS 8.6 · High

CVE-2024-9494

Published Jan 24, 2025

DLL hijacking vulnerabilities, caused by an uncontrolled search path in the  CP210 VCP Win 2k installer can lead to privilege escalation and arbitrary code execution when r…

CVSS 8.6 · High

CVE-2024-9493

Published Jan 24, 2025

DLL hijacking vulnerabilities, caused by an uncontrolled search path in the  ToolStick installer can lead to privilege escalation and arbitrary code execution when running the…

CVSS 8.6 · High

CVE-2024-9492

Published Jan 24, 2025

DLL hijacking vulnerabilities, caused by an uncontrolled search path in Flash Programming Utility installer can lead to privilege escalation and arbitrary code execution when runn…

CVSS 8.6 · High

CVE-2024-9491

Published Jan 24, 2025

DLL hijacking vulnerabilities, caused by an uncontrolled search path in Configuration Wizard 2 installer can lead to privilege escalation and arbitrary code execution when running…

CVSS 8.6 · High

CVE-2024-9490

Published Jan 24, 2025

DLL hijacking vulnerabilities, caused by an uncontrolled search path in Silicon Labs (8-bit) IDE installer can lead to privilege escalation and arbitrary code execution when runni…

CVSS 8.6 · High

CVE-2024-53588

Published Jan 23, 2025

A DLL hijacking vulnerability in iTop VPN v16.0 allows attackers to execute arbitrary code via placing a crafted DLL file into the path \ProgramData\iTop VPN\Downloader\vpn6.

CVSS 7.8 · High
Showing 351-375 of 1,198 CVEsPage 15 of 48