VulnSea

CWE-427

CVEs classified under CWE-427, newest first.

52 CVEsRSS

CVE-2023-52945High· 7.8
4mo ago

Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to execute arbitrary code via unspecified vectors.

Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to execute arbitrary code via unspecified vectors.

▾ Twilightsynology · beedriveEPSS 0.14%via NVD
CVE-2025-14575None
4mo ago

An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attacker to load a rogue CA certificate as a trusted system authority via a crafted certificate …

An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attacker to load a rogue CA certificate as a trusted system authority via a crafted certificate …

▾ SunlitEPSS 0.09%via NVD
CVE-2026-20772Medium· 6.7
4mo ago

Uncontrolled search path for some Intel(R) Connectivity Performance Suite software installers before version 50.25.1121.193 within Ring 3: User Applications may allow an escalation of privilege

Uncontrolled search path for some Intel(R) Connectivity Performance Suite software installers before version 50.25.1121.193 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an au…

▾ Sunlitintel · connectivity_performance_suiteEPSS 0.09%via NVD
CVE-2026-32172High· 8.0
5mo ago

Microsoft Power Apps Remote Code Execution Vulnerability

Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft Power AppsEPSS 0.57%via CVEORG
CVE-2026-4134High· 7.3
5mo ago

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to execute code with elevated privileges.

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to execute code with elevated privileges.

▾ Twilightlenovo · software_fixEPSS 0.17%via NVD
CVE-2026-1636Medium· 6.7
5mo ago

A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a local authenticated user to execute code with elevated privileges.

A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a local authenticated user to execute code with elevated privileges.

▾ Sunlitlenovo · service_bridgeEPSS 0.13%via NVD
CVE-2026-34632High· 8.2
5mo ago

Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user

Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. A low-privileged local attacker could have exploited thi…

▾ Twilightadobe · photoshop_set-up.exeEPSS 0.31%via NVD
CVE-2025-14821High· 7.8
5mo ago

A flaw was found in libssh

A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a significant risk to the confidentiality,…

▾ TwilightEPSS 0.13%via NVD
CVE-2026-22561High· 7.8
6mo ago

Uncontrolled search path elements in Anthropic Claude for Windows installer (Claude Setup.exe) versions prior to 1.1.3363 allow local privilege escalation via DLL search-order hijacking

Uncontrolled search path elements in Anthropic Claude for Windows installer (Claude Setup.exe) versions prior to 1.1.3363 allow local privilege escalation via DLL search-order hijacking. The installer loads DLLs (e.g., profapi.dll) from …

▾ Twilightanthropic · claudeEPSS 0.18%via NVD
CVE-2025-34423High· 7.8
9mo ago

MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution

MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to load MEAIAU.DLL from its installation directory without …

▾ Twilightmailenable · mailenableEPSS 0.17%via NVD
CVE-2025-13152High· 7.8
9mo ago

A potential DLL hijacking vulnerability was reported in Lenovo One Client during an internal security assessment that could allow a local authenticated user to execute code with elevated privileges.

A potential DLL hijacking vulnerability was reported in Lenovo One Client during an internal security assessment that could allow a local authenticated user to execute code with elevated privileges.

▾ TwilightEPSS 0.14%via NVD
CVE-2025-12046High· 7.8
9mo ago

A DLL hijacking vulnerability was reported in the Lenovo App Store and Lenovo Browser applications that could allow a local authenticated user to execute code with elevated privileges under certain conditions.

A DLL hijacking vulnerability was reported in the Lenovo App Store and Lenovo Browser applications that could allow a local authenticated user to execute code with elevated privileges under certain conditions.

▾ TwilightEPSS 0.14%via NVD
CVE-2025-10939Low· 3.7
11mo ago

A flaw was found in Keycloak

A flaw was found in Keycloak. The Keycloak guides recommend to not expose /admin path to the outside in case the installation is using a proxy. The issue occurs at least via ha-proxy, as it can be tricked to using relative/non-normalized…

▾ SunlitEPSS 0.38%via NVD
CVE-2025-9844High· 8.8
1y ago

Uncontrolled Search Path Element vulnerability in Salesforce Salesforce CLI on Windows allows Replace Trusted Executable.This issue affects Salesforce CLI: before 2.106.6.

Uncontrolled Search Path Element vulnerability in Salesforce Salesforce CLI on Windows allows Replace Trusted Executable.This issue affects Salesforce CLI: before 2.106.6.

▾ TwilightEPSS 0.44%via NVD
CVE-2025-40979None
1y ago

DLL search order hijacking vulnerability in the wave.exe executable for Windows 11, version 1.27.8

DLL search order hijacking vulnerability in the wave.exe executable for Windows 11, version 1.27.8. Exploitation of this vulnerability could allow attackers with local access to execute arbitrary code by placing an arbitrary file in the …

▾ SunlitEPSS 0.14%via NVD
CVE-2025-10214High· 7.8
1y ago

DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with local access to execute arbitrary code by placing a FREngine.dll file of their choice in the 'C:\Users\<user>\AppData\Lo…

DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with local access to execute arbitrary code by placing a FREngine.dll file of their choice in the 'C:\Users\<user>\AppData\Lo…

▾ Twilightupdf · updfEPSS 0.17%via NVD
CVE-2025-30033High· 7.8
1y ago

The affected setup component is vulnerable to DLL hijacking

The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected setup component.

▾ TwilightSiemens · Automation License Manager V6.0EPSS 0.21%via NVD
CVE-2023-2005Medium· 6.3
3y ago

Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugin Feed ID #202306261202 ; Nessus: before Plugin Feed ID #202306261202 ; Security Center: before Plugin Feed ID #20230…

Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugin Feed ID #202306261202 ; Nessus: before Plugin Feed ID #202306261202 ; Security Center: before Plugin Feed ID #20230…

▾ Sunlittenable · nessusEPSS 0.38%via NVD
CVE-2022-36271High· 7.8PoC
4y ago

Outbyte PC Repair Installation File 1.7.112.7856 is vulnerable to Dll Hijacking

Outbyte PC Repair Installation File 1.7.112.7856 is vulnerable to Dll Hijacking. iertutil.dll is missing so an attacker can use a malicious dll with same name and can get admin privileges.

▾ Midnightoutbyte · pc_repairEPSS 0.51%via NVD
CVE-2021-42923High· 7.3
4y ago

ShowMyPC 3606 on Windows suffers from a DLL hijack vulnerability

ShowMyPC 3606 on Windows suffers from a DLL hijack vulnerability. If an attacker overwrites the file %temp%\ShowMyPC\-ShowMyPC3606\wodVPN.dll, it will run any malicious code contained in that file. The code will run with normal user priv…

▾ Twilightshowmypc · showmypcEPSS 0.21%via NVD
CVE-2020-3433High· 7.8CISA KEVPoC
6y ago

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the att…

▾ Abyssalcisco · anyconnect_secure_mobility_clientEPSS 10%via NVD
CVE-2020-3153Medium· 6.5CISA KEVPoC
6y ago

A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges

A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulne…

▾ Midnightcisco · anyconnect_secure_mobility_clientEPSS 28%via NVD
CWE-427 vulnerabilities (CVEs) — page 2 · VulnSea