Skip to main content

CWE archive

CWE-427 CVEs

Programmatic archive

1,208 CVEs tagged with CWE-42725 Critical, 810 High, 365 Medium, 6 Low, 2 Unrated.

CVE-2021-33101

Published Feb 9, 2022

Uncontrolled search path in the Intel(R) GPA software before version 21.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-44463

Published Jan 28, 2022

Missing DLLs, if replaced by an insider, could allow an attacker to achieve local privilege escalation on the DeltaV Distributed Control System Controllers and Workstations (All v…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-0166

Published Jan 19, 2022

A privilege escalation vulnerability in the McAfee Agent prior to 5.7.5. McAfee Agent uses openssl.cnf during the build process to specify the OPENSSLDIR variable as a subdirector…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2022-0015

Published Jan 12, 2022

A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authenticated local user to execute programs with elevated privil…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-0129

Published Jan 11, 2022

Uncontrolled search path element vulnerability in McAfee TechCheck prior to 4.0.0.2 allows a local administrator to load their own Dynamic Link Library (DLL) gaining elevation of…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2021-30360

Published Jan 10, 2022

Users have access to the directory where the installation repair occurs. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation r…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-4007

Published Dec 14, 2021

Rapid7 Insight Agent, versions 3.0.1 to 3.1.2.34, suffer from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when Insight Agent versions 3.0.1…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20047

Published Dec 8, 2021

SonicWall Global VPN client version 4.10.6 (32-bit and 64-bit) and earlier have a DLL Search Order Hijacking vulnerability. Successful exploitation via a local attacker could resu…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43037

Published Dec 6, 2021

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Unitrends Windows agent was vulnerable to DLL injection and binary planting due to insecure default…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3840

Published Nov 12, 2021

A dependency confusion vulnerability was reported in the Antilles open-source software prior to version 1.0.1 that could allow for remote code execution during installation due to…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-31853

Published Nov 10, 2021

DLL Search Order Hijacking Vulnerability in McAfee Drive Encryption (MDE) prior to 7.3.0 HF2 (7.3.0.183) allows local users to execute arbitrary code and escalate privileges via e…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-38420

Published Nov 3, 2021

Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged user accounts, which may allow an attacker to modify the inst…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-38416

Published Nov 3, 2021

Delta Electronics DIALink versions 1.2.4.0 and prior insecurely loads libraries, which may allow an attacker to use DLL hijacking and takeover the system where the software is ins…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22037

Published Oct 29, 2021

Under certain circumstances, when manipulating the Windows registry, InstallBuilder uses the reg.exe system command. The full path to the command is not enforced, which results in…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 826-850 of 1,208 CVEsPage 34 of 49