Skip to main content

CWE archive

CWE-427 CVEs

Programmatic archive

1,188 CVEs tagged with CWE-42724 Critical, 799 High, 357 Medium, 6 Low, 2 Unrated.

CVE-2020-25738

Published Nov 27, 2020

CyberArk Endpoint Privilege Manager (EPM) 11.1.0.173 allows attackers to bypass a Credential Theft protection mechanism by injecting a DLL into a process that normally has credent…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12329

Published Nov 12, 2020

Uncontrolled search path in the Intel(R) VTune(TM) Profiler before version 2020 Update 1 may allow an authenticated user to potentially enable escalation of privilege via local ac…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-12320

Published Nov 12, 2020

Uncontrolled search path in Intel(R) SCS Add-on for Microsoft* SCCM before version 2.1.10 may allow an authenticated user to potentially enable escalation of privilege via local a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13771

Published Nov 12, 2020

Various components in Ivanti Endpoint Manager through 2020.1.1 rely on Windows search order when loading a (nonexistent) library file, allowing (under certain conditions) one to g…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5992

Published Nov 11, 2020

NVIDIA GeForce NOW application software on Windows, all versions prior to 2.0.25.119, contains a vulnerability in its open-source software dependency in which the OpenSSL library…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27708

Published Nov 2, 2020

A vulnerability exists in the Origin Client that could allow a non-Administrative user to elevate their access to either Administrator or System. Once the user has obtained elevat…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5145

Published Oct 28, 2020

SonicWall Global VPN client version 4.10.4.0314 and earlier have an insecure library loading (DLL hijacking) vulnerability. Successful exploitation could lead to remote code execu…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24425

Published Oct 21, 2020

Dreamweaver version 20.2 (and earlier) is affected by an uncontrolled search path element vulnerability that could lead to privilege escalation. Successful exploitation could resu…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-24423

Published Oct 21, 2020

Adobe Media Encoder version 14.4 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary code execution in the context of…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24420

Published Oct 21, 2020

Adobe Photoshop for Windows version 21.2.1 (and earlier) is affected by an uncontrolled search path element vulnerability that could result in arbitrary code execution in the cont…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24419

Published Oct 21, 2020

Adobe After Effects version 17.1.1 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary code execution in the context…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-24422

Published Oct 21, 2020

Adobe Creative Cloud Desktop Application version 5.2 (and earlier) and 2.1 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8345

Published Oct 14, 2020

A DLL search path vulnerability was reported in the Lenovo HardwareScan Plugin for the Lenovo Vantage hardware scan feature prior to version 1.0.46.11 that could allow escalation…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2020-26947

Published Oct 10, 2020

monero-wallet-gui in Monero GUI before 0.17.1.0 includes the . directory in an embedded RPATH (with a preference ahead of /usr/lib), which allows local users to gain privileges vi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19115

Published Oct 8, 2020

An escalation of privilege vulnerability in Nahimic APO Software Component Driver 1.4.2, 1.5.0, 1.5.1, 1.6.1 and 1.6.2 allows an attacker to execute code with SYSTEM privileges.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-3535

Published Oct 8, 2020

A vulnerability in the loading mechanism of specific DLLs in the Cisco Webex Teams client for Windows could allow an authenticated, local attacker to load a malicious library. To…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-24356

Published Oct 2, 2020

`cloudflared` versions prior to 2020.8.1 contain a local privilege escalation vulnerability on Windows systems. When run on a Windows system, `cloudflared` searches for configurat…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 951-975 of 1,188 CVEsPage 39 of 48