CWE-427: CWE-427

398
Total CVEs
7
Critical
283
High
7.5
Avg CVSS

Yearly Trend

2026
36
2025
151
2024
88
2023
45
2022
26

Top Affected Vendors

1 Intel 37
2 Acronis 12
3 Dell 11
4 Mailenable 10
5 Microsoft 8
6 Adobe 8
7 Lenovo 8
8 Siemens 7
9 Trendmicro 6
10 Nvidia 6

All CWE-427 CVEs (398)

CVE-2024-10930
7.8

This vulnerability allows attackers to perform DLL hijacking by placing a malicious DLL in a location searched by the affected software before legitim...

Mar 4, 2025
CVE-2024-48091
7.8

Tally Prime Edit Log v2.1 contains a DLL hijacking vulnerability in TextShaping.dll that allows attackers to execute arbitrary code by placing a malic...

Feb 7, 2025
CVE-2024-53588
7.8

A DLL hijacking vulnerability in iTop VPN v16.0 allows attackers to execute arbitrary code with the privileges of the VPN application by placing a mal...

Jan 23, 2025
CVE-2025-21127
7.8

This CVE describes an uncontrolled search path element vulnerability in Adobe Photoshop Desktop that could allow arbitrary code execution. Attackers c...

Jan 14, 2025
CVE-2025-0069
7.8

This CVE describes a DLL injection vulnerability in SAPSetup that allows attackers with local Windows user privileges to escalate privileges. This ena...

Jan 14, 2025
CVE-2024-55543
7.8

This CVE describes a local privilege escalation vulnerability in Acronis Cyber Protect 16 for Windows due to DLL hijacking. Attackers with local acces...

Jan 2, 2025
CVE-2024-55540
7.8

This CVE describes a local privilege escalation vulnerability in Acronis Cyber Protect 16 for Windows due to DLL hijacking. Attackers with local acces...

Jan 2, 2025
CVE-2022-27595
7.8

CVE-2022-27595 is an insecure library loading vulnerability in QVPN Device Client that allows local attackers with user access to execute arbitrary co...

Dec 19, 2024
CVE-2024-9852
7.8

This vulnerability allows a local authenticated attacker to execute malicious code by placing a specially crafted DLL in a specific folder. It affects...

Nov 28, 2024
CVE-2024-8299
7.8

This CVE describes a DLL hijacking vulnerability in Mitsubishi Electric's GENESIS64, ICONICS Suite, and related industrial control software. A local a...

Nov 28, 2024
CVE-2024-48990
7.8

CVE-2024-48990 is a local privilege escalation vulnerability in needrestart versions before 3.8. Attackers can exploit it by manipulating the PYTHONPA...

Nov 19, 2024
CVE-2024-48992
7.8

CVE-2024-48992 is a local privilege escalation vulnerability in needrestart versions before 3.8. Attackers with local access can trick needrestart int...

Nov 19, 2024
CVE-2024-48605
7.8

This vulnerability allows a local attacker to execute arbitrary code on systems running Helakuru Desktop Application v1.1 by exploiting DLL hijacking ...

Oct 22, 2024
CVE-2024-10093
7.8

This vulnerability allows local attackers to execute arbitrary code through DLL hijacking in VSO ConvertXtoDvd. Attackers can place a malicious avcode...

Oct 17, 2024
CVE-2024-4131
7.8

A DLL hijack vulnerability in Lenovo Emulator allows local attackers to execute arbitrary code with elevated privileges by placing a malicious DLL in ...

Oct 11, 2024
CVE-2024-4089
7.8

A DLL hijack vulnerability in Lenovo Super File allows local attackers to execute arbitrary code with elevated privileges by placing a malicious DLL i...

Oct 11, 2024
CVE-2024-33582
7.8

A DLL hijack vulnerability in Lenovo Service Framework allows local attackers to execute arbitrary code with elevated privileges by placing a maliciou...

Oct 11, 2024
CVE-2024-33578
7.8

A DLL hijack vulnerability in Lenovo Leyun allows local attackers to execute arbitrary code with elevated privileges by placing a malicious DLL in a l...

Oct 11, 2024
CVE-2024-33580
7.8

A DLL hijack vulnerability in Lenovo Personal Cloud allows a local attacker to execute arbitrary code with elevated privileges by placing a malicious ...

Oct 11, 2024
CVE-2024-6510
7.8

CVE-2024-6510 is a local privilege escalation vulnerability in AVG Internet Security v24 on Windows. It allows an unprivileged local user to gain SYST...

Sep 12, 2024
CVE-2024-7326
7.8

This vulnerability in IObit DualSafe Password Manager 1.4.0.3 allows DLL side-loading attacks via the RTL120.BPL library. Attackers can execute arbitr...

Jul 31, 2024
CVE-2024-7325
7.8

This vulnerability in IObit Driver Booster 11.0.0.0 allows local attackers to exploit an uncontrolled search path issue in the VCL120.BPL library comp...

Jul 31, 2024
CVE-2024-7324
7.8

This vulnerability in IObit iTop Data Recovery Pro 4.4.0.687 allows local attackers to execute arbitrary code via DLL hijacking in the madbasic_.bpl l...

Jul 31, 2024
CVE-2024-5509
7.8

This vulnerability allows remote attackers to execute arbitrary code on Luxion KeyShot installations by tricking users into opening malicious BIP file...

Jun 6, 2024
CVE-2024-5292
7.8

This vulnerability allows local attackers to escalate privileges on systems running D-Link Network Assistant. Attackers with low-privileged access can...

May 23, 2024
CVE-2023-44437
7.8

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious fi...

May 3, 2024
CVE-2023-27362
7.8

This vulnerability allows local attackers to escalate privileges on 3CX installations by exploiting an insecure OpenSSL configuration file location. A...

May 3, 2024
CVE-2024-28099
7.8

This vulnerability in VT STUDIO allows attackers to execute arbitrary code by exploiting insecure DLL loading. It affects users of VT STUDIO version 8...

Apr 15, 2024
CVE-2024-29734
7.8

This vulnerability allows attackers to execute arbitrary code by exploiting an uncontrolled DLL search path in SonicDICOM Media Viewer. Attackers can ...

Apr 3, 2024
CVE-2024-28131
7.8

EasyRange Ver 1.41 has a path search order vulnerability where it may execute malicious files from the same folder as extracted files instead of legit...

Mar 26, 2024
CVE-2023-42920
7.8

This CVE describes a dylib hijacking vulnerability in FileMaker Pro and Claris Pro applications on macOS. Attackers can place malicious dynamic librar...

Mar 19, 2024
CVE-2024-1595
7.8

Delta Electronics CNCSoft-B DOPSoft versions before 4.0.0.82 insecurely load dynamic link libraries (DLLs), allowing attackers to perform DLL hijackin...

Feb 29, 2024
CVE-2024-23940
7.8

This vulnerability allows attackers to hijack DLL files used by Trend Micro's uiAirSupport component, enabling them to execute arbitrary code with ele...

Jan 29, 2024
CVE-2023-29445
7.8

This CVE describes a DLL hijacking vulnerability in PTC's Kepware KEPServerEX software that allows a locally authenticated attacker to escalate privil...

Jan 10, 2024
CVE-2023-48677
7.8

This CVE describes a DLL hijacking vulnerability in Acronis Cyber Protect products for Windows that allows local attackers to escalate privileges. Att...

Dec 12, 2023
CVE-2023-41613
7.8

EzViz Studio v2.2.0 is vulnerable to DLL hijacking, allowing attackers to execute arbitrary code by placing malicious DLL files in directories where t...

Dec 4, 2023
CVE-2023-45252
7.8

A DLL hijacking vulnerability in HuddlyCameraService allows attackers to place malicious DLLs in the service directory, which standard users can write...

Dec 1, 2023
CVE-2023-47452
7.8

This CVE describes an untrusted search path vulnerability in Notepad++ 6.5 that allows local users to escalate privileges by placing a malicious msimg...

Nov 30, 2023
CVE-2023-47454
7.8

This CVE describes an untrusted search path vulnerability in NetEase CloudMusic for Windows that allows local users to escalate privileges by placing ...

Nov 30, 2023
CVE-2023-29069
7.8

This vulnerability allows attackers to place malicious DLL files in non-default locations, which can then be loaded by affected Autodesk software with...

Nov 22, 2023
CVE-2023-46814
7.8

A binary hijacking vulnerability in VLC media player's uninstaller on Windows allows standard users to execute arbitrary code with SYSTEM privileges. ...

Nov 22, 2023
CVE-2023-6235
7.8

This vulnerability allows attackers to execute arbitrary code on systems running Duet Display version 2.5.9.1 by placing a malicious DLL in a specific...

Nov 21, 2023
CVE-2023-4632
7.8

This vulnerability in Lenovo System Update allows attackers with local access to execute arbitrary code with elevated privileges by exploiting an unco...

Nov 8, 2023
CVE-2023-5463
7.8

This is a critical local privilege escalation vulnerability in XINJE XDPPro software up to version 3.7.17a. It allows attackers with local access to e...

Oct 9, 2023
CVE-2022-4956
7.8

CVE-2022-4956 is a critical local privilege escalation vulnerability in Caphyon Advanced Installer 19.7 that allows attackers to execute arbitrary cod...

Sep 30, 2023
CVE-2023-3078
7.8

This vulnerability in Lenovo Universal Device Client allows attackers with local access to execute arbitrary code with elevated privileges by exploiti...

Aug 17, 2023
CVE-2022-47636
7.8

This CVE describes a DLL hijacking vulnerability in OutSystems Service Studio 11. When users open .oml files, the application loads specific DLLs from...

Aug 10, 2023
CVE-2023-36344
7.8

This vulnerability allows a local attacker to execute arbitrary code on Diebold Nixdorf Vynamic View Console systems via DLL hijacking. Attackers can ...

Aug 8, 2023
CVE-2021-41544
7.8

A DLL hijacking vulnerability in Siemens Software Center allows local attackers to execute arbitrary code with elevated privileges by placing a malici...

Aug 8, 2023
CVE-2023-27908
7.8

This vulnerability allows privilege escalation through a DLL hijacking attack in Autodesk installers. An attacker could execute arbitrary code with el...

Jun 23, 2023

About CWE-427 (CWE-427)

Our database tracks 398 CVEs classified as CWE-427, with 7 rated critical and 283 rated high severity. The average CVSS score for CWE-427 vulnerabilities is 7.5.

External reference: View CWE-427 on MITRE CWE →

Monitor CWE-427 Vulnerabilities

Get alerted when new CWE-427 CVEs affect your infrastructure.

Start Monitoring Free