CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,278 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,568 researchers
1,099 results Clear all
CVE-2022-36380 6.7 MEDIUM EPSS 0.00
Intel NUC Kit Wireless Adapter <22.40 - Privilege Escalation
Uncontrolled search path in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.
CWE-427 Nov 11, 2022
CVE-2022-30548 6.7 MEDIUM EPSS 0.00
Intel Glorp - Uncontrolled Search Path
Uncontrolled search path element in the Intel(R) Glorp software may allow an authenticated user to potentially enable escalation of privilege via local access.
CWE-427 Nov 11, 2022
CVE-2022-27638 6.7 MEDIUM EPSS 0.00
Intel Advanced Link Analyzer < 22.1.1 - Uncontrolled Search Path
Uncontrolled search path element in the Intel(R) Advanced Link Analyzer Pro before version 22.2 and Standard edition software before version 22.1.1 STD may allow an authenticated user to potentially enable escalation of privilege via local access.
CWE-427 Nov 11, 2022
CVE-2022-27187 6.7 MEDIUM EPSS 0.00
Intel Quartus Prime < 21.1 - Uncontrolled Search Path
Uncontrolled search path element in the Intel(R) Quartus Prime Standard edition software before version 21.1 Patch 0.02std may allow an authenticated user to potentially enable escalation of privilege via local access.
CWE-427 Nov 11, 2022
CVE-2022-26086 6.7 MEDIUM EPSS 0.00
Intel(R) PresentMon <1.7.1 - Privilege Escalation
Uncontrolled search path element in the PresentMon software maintained by Intel(R) before version 1.7.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
CWE-427 Nov 11, 2022
CVE-2022-26028 6.7 MEDIUM EPSS 0.00
Intel(R) VTune(TM) Profiler <2022.2.0 - Privilege Escalation
Uncontrolled search path in the Intel(R) VTune(TM) Profiler software before version 2022.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
CWE-427 Nov 11, 2022
CVE-2021-33064 6.7 MEDIUM EPSS 0.00
Intel(R) System Studio - Privilege Escalation
Uncontrolled search path in the software installer for Intel(R) System Studio for all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.
CWE-427 Nov 11, 2022
CVE-2022-43310 7.8 HIGH EPSS 0.00
Foxit Reader <11.2.118.51569 - Privilege Escalation
An Uncontrolled Search Path Element in Foxit Software released Foxit Reader v11.2.118.51569 allows attackers to escalate privileges when searching for DLL libraries without specifying an absolute path.
CWE-427 Nov 09, 2022
CVE-2022-34825 9.8 CRITICAL EPSS 0.02
NEC Expresscluster X < 5.0 - Uncontrolled Search Path
Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier allows a remote unauthenticated attacker to overwrite existing files on the file system and to potentially execute arbitrary code.
CWE-427 Nov 08, 2022
CVE-2022-44744 7.3 HIGH EPSS 0.00
Acronis Cyber Protect Home Office < 40107 - Uncontrolled Search Path
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107.
CWE-427 Nov 07, 2022
CVE-2022-39286 8.8 HIGH 1 Writeup EPSS 0.00
Jupyter Core <4.11.2 - Code Injection
Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code execution vulnerability in `jupyter_core` that stems from `jupyter_core` executing untrusted files in CWD. This vulnerability allows one user to run code as another. Version 4.11.2 contains a patch for this issue. There are no known workarounds.
CWE-269 Oct 26, 2022
CVE-2022-41796 7.8 HIGH EPSS 0.00
Content Transfer <1.3 - Privilege Escalation
Untrusted search path vulnerability in the installer of Content Transfer (for Windows) Ver.1.3 and prior allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
CWE-427 Oct 24, 2022
CVE-2022-33921 7.0 HIGH EPSS 0.00
Dell GeoDrive <2.2 - RCE
Dell GeoDrive, versions prior to 2.2, contains Multiple DLL Hijacking Vulnerabilities. A low privilege attacker could potentially exploit this vulnerability, leading to the execution of arbitrary code in the SYSTEM security context.
CWE-427 Oct 12, 2022
CVE-2022-32168 7.8 HIGH 1 Writeup EPSS 0.00
Notepad-plus-plus Notepad++ < 8.4.5 - Uncontrolled Search Path
Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.
CWE-427 Sep 28, 2022
CVE-2022-40978 7.5 HIGH EPSS 0.00
JetBrains IntelliJ IDEA <2022.2.2 - Code Injection
The installer of JetBrains IntelliJ IDEA before 2022.2.2 was vulnerable to EXE search order hijacking
CWE-427 Sep 19, 2022
CVE-2022-2333 8.8 HIGH 1 PoC Analysis EPSS 0.00
Honeywell SoftMaster <4.51 - Code Injection
If an attacker manages to trick a valid user into loading a malicious DLL, the attacker may be able to achieve code execution in Honeywell SoftMaster version 4.51 application’s context and permissions.
CWE-427 Sep 16, 2022
CVE-2022-38633 7.8 HIGH 1 Writeup EPSS 0.00
Genymotion Desktop <3.2.1 - Privilege Escalation
Genymotion Desktop v3.2.1 was discovered to contain a DLL hijacking vulnerability which allows attackers to escalate privileges and execute arbitrary code via a crafted binary.
CWE-427 Sep 13, 2022
CVE-2022-34101 7.8 HIGH EPSS 0.00
Crestron AirMedia <4.3.1.39 - Privilege Escalation
A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can place a malicious DLL in a certain path to execute code and preform a privilege escalation attack.
CWE-427 Sep 13, 2022
CVE-2022-39846 6.2 MEDIUM EPSS 0.00
Samsung Smart Switch PC < 4.3.22083_3 - Uncontrolled Search Path
DLL hijacking vulnerability in Smart Switch PC prior to version 4.3.22083_3 allows attacker to execute arbitrary code.
CWE-427 Sep 09, 2022
CVE-2022-36271 7.8 HIGH 1 PoC Analysis EPSS 0.02
Outbyte PC Repair Installation File <1.7.112.7856 - Code Injection
Outbyte PC Repair Installation File 1.7.112.7856 is vulnerable to Dll Hijacking. iertutil.dll is missing so an attacker can use a malicious dll with same name and can get admin privileges.
CWE-427 Sep 07, 2022