CVE & Exploit Intelligence Database

Updated 50m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,278 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,568 researchers
1,099 results Clear all
CVE-2017-20123 8.8 HIGH 1 Writeup EPSS 0.01
Viscosity <1.6.8 - Untrusted Search Path
A vulnerability was found in Viscosity 1.6.7. It has been classified as critical. This affects an unknown part of the component DLL Handler. The manipulation leads to untrusted search path. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.8 is able to address this issue. It is recommended to upgrade the affected component.
CWE-427 Jun 30, 2022
CVE-2022-33037 7.8 HIGH EPSS 0.00
Orwell-Dev-Cpp <5.11 - RCE
A binary hijack in Orwell-Dev-Cpp v5.11 allows attackers to execute arbitrary code via a crafted .exe file.
CWE-427 Jun 29, 2022
CVE-2022-33036 7.8 HIGH EPSS 0.00
Embarcadero Dev-CPP <6.3 - RCE
A binary hijack in Embarcadero Dev-CPP v6.3 allows attackers to execute arbitrary code via a crafted .exe file.
CWE-427 Jun 29, 2022
CVE-2022-33035 7.8 HIGH EPSS 0.00
XLPD <7.0.0094 - Privilege Escalation
XLPD v7.0.0094 and below contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.
CWE-427 Jun 29, 2022
CVE-2022-1824 7.9 HIGH EPSS 0.00
Mcafee Consumer Product Removal Tool - Uncontrolled Search Path
An uncontrolled search path vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local attacker to perform a sideloading attack by using a specific file name. This could result in the user gaining elevated permissions and being able to execute arbitrary code as there were insufficient checks on the executable being signed by McAfee.
CWE-427 Jun 20, 2022
CVE-2017-20052 5.0 MEDIUM EPSS 0.00
Python 2.7.13 - Uncontrolled Search Path
A vulnerability classified as problematic was found in Python 2.7.13. This vulnerability affects unknown code of the component pgAdmin4. The manipulation leads to uncontrolled search path. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CWE-427 Jun 16, 2022
CVE-2017-20051 6.3 MEDIUM EPSS 0.00
InnoSetup Installer - Path Traversal
A vulnerability was found in InnoSetup Installer. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to uncontrolled search path. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CWE-427 Jun 16, 2022
CVE-2022-22788 7.1 HIGH EPSS 0.01
Zoom Meetings < 5.10.3 - Uncontrolled Search Path
The Zoom Opener installer is downloaded by a user from the Launch meeting page, when attempting to join a meeting without having the Zoom Meeting Client installed. The Zoom Opener installer for Zoom Client for Meetings before version 5.10.3 and Zoom Rooms for Conference Room for Windows before version 5.10.3 are susceptible to a DLL injection attack. This vulnerability could be used to run arbitrary code on the victims host.
CWE-427 Jun 15, 2022
CVE-2022-24077 7.8 HIGH EPSS 0.00
Naver Cloud Explorer Beta - Code Injection
Naver Cloud Explorer Beta allows the attacker to execute arbitrary code as System privilege via malicious DLL injection.
CWE-269 Jun 13, 2022
CVE-2022-29092 7.8 HIGH EPSS 0.00
Dell SupportAssist Client Consumer <3.11.0 & Commercial <3.2.0 - Pr...
Dell SupportAssist Client Consumer versions (3.11.0 and versions prior) and Dell SupportAssist Client Commercial versions (3.2.0 and versions prior) contain a privilege escalation vulnerability. A non-admin user can exploit the vulnerability and gain admin access to the system.
CWE-427 Jun 10, 2022
CVE-2017-20018 6.3 MEDIUM EPSS 0.00
XAMPP 7.1.1-0-VC14 - Privilege Escalation
A vulnerability was found in XAMPP 7.1.1-0-VC14. It has been classified as problematic. Affected is an unknown function of the component Installer. The manipulation leads to privilege escalation. It is possible to launch the attack remotely.
CWE-427 Jun 09, 2022
CVE-2022-30744 6.2 MEDIUM EPSS 0.00
Samsung Kies <2.6.4.22043_1 - RCE
DLL hijacking vulnerability in KiesWrapper in Samsung Kies prior to version 2.6.4.22043_1 allows attacker to execute arbitrary code.
CWE-427 Jun 07, 2022
CVE-2022-30701 7.8 HIGH EPSS 0.00
Trend Micro Apex One/Apex One as a Service - Privilege Escalation
An uncontrolled search path element vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to craft a special configuration file to load an untrusted library with escalated privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
CWE-427 May 27, 2022
CVE-2022-28394 7.8 HIGH EPSS 0.00
Trend Micro Password Manager <3.7.0.1223 - DLL Injection
EOL Product CVE - Installer of Trend Micro Password Manager (Consumer) versions 3.7.0.1223 and below provided by Trend Micro Incorporated contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427). Please note that this was reported on an EOL version of the product, and users are advised to upgrade to the latest supported version (5.x).
CWE-427 May 27, 2022
CVE-2022-23050 7.2 HIGH EPSS 0.27
Zohocorp Manageengine Applications Manager - Uncontrolled Search Path
ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the 'working' folder through the 'Upload Files / Binaries' functionality.
CWE-427 May 24, 2022
CVE-2022-31467 7.9 HIGH EPSS 0.00
Quick Heal Total Security <12.1.1.27 - Privilege Escalation
A DLL hijacking vulnerability in the installed for Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, leading to execution of arbitrary code, via the installer not restricting the search path for required DLLs and then not verifying the signature of the DLLs it tries to load.
CWE-427 May 23, 2022
CVE-2022-28965 6.5 MEDIUM 1 Writeup EPSS 0.00
Avast Premium Security <v21.11.2500 - RCE/DoS
Multiple DLL hijacking vulnerabilities via the components instup.exe and wsc_proxy.exe in Avast Premium Security before v21.11.2500 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via a crafted DLL file.
CWE-427 May 20, 2022
CVE-2022-30697 7.8 HIGH EPSS 0.00
Acronis Snap Deploy <build 3640 - Privilege Escalation
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 3640
CWE-427 May 16, 2022
CVE-2022-30696 7.8 HIGH EPSS 0.00
Acronis Snap Deploy <3640 - Privilege Escalation
Local privilege escalation due to a DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 3640
CWE-427 May 16, 2022
CVE-2022-22139 7.3 HIGH EPSS 0.00
Intel(R) XTU <7.3.0.33 - Privilege Escalation
Uncontrolled search path in the Intel(R) XTU software before version 7.3.0.33 may allow an authenticated user to potentially enable escalation of privilege via local access.
CWE-427 May 12, 2022