Skip to main content

CWE archive

CWE-427 CVEs

Programmatic archive

1,189 CVEs tagged with CWE-42724 Critical, 800 High, 357 Medium, 6 Low, 2 Unrated.

CVE-2021-31840

Published Jun 10, 2021

A vulnerability in the preloading mechanism of specific dynamic link libraries in McAfee Agent for Windows prior to 5.7.3 could allow an authenticated, local attacker to perform a…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-23023

Published Jun 10, 2021

On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, a DLL hijacking issue exists in cachecleaner.dll included in the BIG-IP Edge Client Windows Installer. Note: S…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0108

Published Jun 9, 2021

Uncontrolled search path in the Intel Unite(R) Client for Windows before version 4.2.25031 may allow an authenticated user to potentially enable an escalation of privilege via loc…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0104

Published Jun 9, 2021

Uncontrolled search path element in the installer for the Intel(R) Rapid Storage Technology software, before versions 17.9.0.34, 18.0.0.640 and 18.1.0.24, may allow an authenticat…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0090

Published Jun 9, 2021

Uncontrolled search path element in Intel(R) DSA before version 20.11.50.9 may allow an authenticated user to potentially enable an escalation of privilege via local access.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8702

Published Jun 9, 2021

Uncontrolled search path element in the Intel(R) Processor Diagnostic Tool before version 4.1.5.37 may allow an authenticated user to potentially enable escalation of privilege vi…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2019-4588

Published May 26, 2021

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to execute arbitrary code and conduct DLL hijacking atta…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20726

Published May 24, 2021

Untrusted search path vulnerability in The Installer of Overwolf 2.168.0.n and earlier allows an attacker to gain privileges and execute arbitrary code with the privilege of the u…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20722

Published May 24, 2021

Untrusted search path vulnerability in the installers of ScanSnap Manager prior to versions V7.0L20 and the Software Download Installer prior to WinSSInst2JP.exe and WinSSInst2iX1…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3423

Published May 18, 2021

Uncontrolled Search Path Element vulnerability in the openssl component as used in Bitdefender GravityZone Business Security allows an attacker to load a third party DLL to elevat…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24755

Published May 17, 2021

In Ubiquiti UniFi Video v3.10.13, when the executable starts, its first library validation is in the current directory. This allows the impersonation and modification of the libra…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25694

Published May 13, 2021

Teradici PCoIP Graphics Agent for Windows prior to 21.03 does not validate NVENC.dll. An attacker could replace the .dll and redirect pixels elsewhere.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3464

Published Apr 27, 2021

A DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow privilege escalation.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25244

Published Apr 22, 2021

A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.4). The software insecurely loads libraries which makes it vulnerable to DLL hijacking. Successful exp…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21070

Published Apr 19, 2021

Adobe Robohelp version 2020.0.3 (and earlier) is affected by an uncontrolled search path element vulnerability that could lead to privilege escalation. An attacker with admin perm…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 876-900 of 1,189 CVEsPage 36 of 48