Skip to main content

CWE archive

CWE-427 CVEs

Programmatic archive

1,188 CVEs tagged with CWE-42724 Critical, 799 High, 357 Medium, 6 Low, 2 Unrated.

CVE-2020-24485

Published Feb 17, 2021

Improper conditions check in the Intel(R) FPGA OPAE Driver for Linux before kernel version 4.17 may allow an authenticated user to potentially enable escalation of privilege via l…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35145

Published Jan 29, 2021

Acronis True Image for Windows prior to 2021 Update 3 allowed local privilege escalation due to a DLL hijacking vulnerability in multiple components, aka an Untrusted Search Path…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21011

Published Jan 13, 2021

Adobe Captivate 2019 version 11.5.1.499 (and earlier) is affected by an uncontrolled search path element vulnerability that could lead to privilege escalation. An attacker with pe…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21010

Published Jan 13, 2021

InCopy version 15.1.1 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary code execution in the context of the curren…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21008

Published Jan 13, 2021

Adobe Animate version 21.0 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the context of the current user. Explo…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21007

Published Jan 13, 2021

Adobe Illustrator version 25.0 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the context of the current user. E…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2021-1240

Published Jan 13, 2021

A vulnerability in the loading process of specific DLLs in Cisco Proximity Desktop for Windows could allow an authenticated, local attacker to load a malicious library. To exploit…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1237

Published Jan 13, 2021

A vulnerability in the Network Access Manager and Web Security Agent components of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker…

CVSS 7.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-20616

Published Jan 13, 2021

Untrusted search path vulnerability in the installer of SKYSEA Client View Ver.1.020.05b to Ver.16.001.01g allows an attacker to gain privileges via a Trojan horse DLL in an unspe…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-26050

Published Jan 12, 2021

SaferVPN for Windows Ver 5.0.3.3 through 5.0.4.15 could allow local privilege escalation from low privileged users to SYSTEM via a crafted openssl configuration file. This issue i…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35483

Published Jan 11, 2021

AnyDesk before 6.1.0 on Windows, when run in portable mode on a system where the attacker has write access to the application directory, allows this attacker to compromise a local…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24447

Published Dec 11, 2020

Adobe Lightroom Classic version 10.0 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary code execution in the contex…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24440

Published Dec 11, 2020

Adobe Prelude version 9.0.1 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the context of the current user. Expl…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2020-28950

Published Dec 4, 2020

The installer of Kaspersky Anti-Ransomware Tool (KART) prior to KART 4.0 Patch C was vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges during ins…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6021

Published Dec 3, 2020

Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which the installation repair takes place. Since the MS Installer…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 926-950 of 1,188 CVEsPage 38 of 48