CWE-427: CWE-427

401
Total CVEs
7
Critical
286
High
7.5
Avg CVSS

Yearly Trend

2026
36
2025
151
2024
88
2023
45
2022
26

Top Affected Vendors

1 Intel 37
2 Acronis 13
3 Dell 11
4 Mailenable 10
5 Lenovo 8
6 Microsoft 8
7 Adobe 8
8 Trendmicro 7
9 Siemens 7
10 Nvidia 6

All CWE-427 CVEs (401)

CVE-2023-25005
7.8

This vulnerability in Autodesk InfraWorks allows attackers to craft malicious DLL files that cause the software to read beyond allocated memory bounda...

May 12, 2023
CVE-2023-25428
7.8

This DLL hijacking vulnerability in Soft-o Free Password Manager allows attackers to place malicious DLL files in directories where the application se...

May 12, 2023
CVE-2023-30237
7.8

The CyberGhostVPN Windows client before version 8.3.10.10015 contains a DLL injection vulnerability in Dashboard.exe that allows attackers to execute ...

May 9, 2023
CVE-2023-2355
7.8

This CVE describes a DLL hijacking vulnerability in Acronis Snap Deploy for Windows that allows local attackers to escalate privileges. Attackers can ...

Apr 27, 2023
CVE-2022-28687
7.8

This vulnerability allows remote attackers to execute arbitrary code on AVEVA Edge 2020 installations by tricking users into opening malicious APP fil...

Mar 29, 2023
CVE-2022-48422
7.8

This vulnerability allows local users on Linux systems to escalate privileges by placing a malicious libgcc_s.so.1 library in a directory where ONLYOF...

Mar 19, 2023
CVE-2021-31637
7.8

CVE-2021-31637 is a DLL hijacking vulnerability in UwAmp web server software that allows remote attackers to execute arbitrary code by placing a malic...

Mar 16, 2023
CVE-2022-32972
7.8

CVE-2022-32972 is a DLL injection vulnerability in Infoblox BloxOne Endpoint for Windows that allows local attackers to execute arbitrary code with el...

Feb 17, 2023
CVE-2022-48077
7.8

CVE-2022-48077 is a DLL hijacking vulnerability in Genymotion Desktop that allows attackers to escalate privileges and execute arbitrary code by placi...

Feb 13, 2023
CVE-2022-36415
7.8

A DLL hijacking vulnerability in Scooter Beyond Compare's uninstaller allows local attackers to execute arbitrary code with SYSTEM privileges. When th...

Jul 23, 2022
CVE-2022-34901
7.8

This vulnerability allows local attackers with low-privileged code execution on affected Parallels Access Agent installations to escalate privileges t...

Jul 18, 2022
CVE-2022-29092
7.8

Dell SupportAssist contains a privilege escalation vulnerability where non-admin users can gain admin access to the system. This affects both Consumer...

Jun 10, 2022
CVE-2022-28394
7.8

This vulnerability in Trend Micro Password Manager installer versions 3.7.0.1223 and below allows attackers to execute arbitrary code by placing malic...

May 27, 2022
CVE-2022-30696
7.8

This CVE describes a DLL hijacking vulnerability in Acronis Snap Deploy for Windows that allows local attackers to escalate privileges. Attackers can ...

May 16, 2022
CVE-2021-20051
7.8

CVE-2021-20051 is a DLL search order hijacking vulnerability in SonicWall Global VPN Client installer versions 4.10.7.1117 and earlier. A local attack...

May 4, 2022
CVE-2022-24767
7.8

This vulnerability allows attackers to perform DLL hijacking when the Git for Windows uninstaller runs under the SYSTEM user account. Attackers could ...

Apr 12, 2022
CVE-2022-1098
7.8

Delta Electronics DIAEnergie versions prior to 1.8.02.004 are vulnerable to DLL hijacking combined with incorrect default permissions. This allows loc...

Apr 1, 2022
CVE-2022-28128
7.8

This vulnerability allows attackers to execute arbitrary code with elevated privileges by placing a malicious DLL in a directory that AttacheCase sear...

Mar 31, 2022
CVE-2022-26081
7.8

This vulnerability in WPS Office installer allows attackers to execute arbitrary code by exploiting insecure DLL loading. It affects users running WPS...

Mar 17, 2022
CVE-2022-26337
7.8

This vulnerability in Trend Micro Password Manager installer allows attackers to place malicious DLL files in specific directories, which the installe...

Mar 8, 2022
CVE-2021-43940
7.8

This CVE describes a DLL hijacking vulnerability in Atlassian Confluence Server and Data Center installers on Windows. Authenticated local attackers c...

Feb 15, 2022
CVE-2022-23410
7.8

CVE-2022-23410 is a DLL hijacking vulnerability in AXIS IP Utility that allows attackers to execute arbitrary code with elevated privileges. It affect...

Feb 14, 2022
CVE-2022-23853
7.8

This vulnerability allows arbitrary code execution when KDE Kate or KTextEditor opens a file from an untrusted directory. If the required LSP server b...

Feb 11, 2022
CVE-2022-0483
7.8

CVE-2022-0483 is a local privilege escalation vulnerability in Acronis VSS Doctor for Windows caused by insecure folder permissions. This allows authe...

Feb 11, 2022
CVE-2021-33101
7.8

This vulnerability in Intel GPA software allows authenticated local users to escalate privileges by manipulating the software's search path. It affect...

Feb 9, 2022
CVE-2020-12891
7.8

This vulnerability allows an unprivileged user to perform DLL hijacking by placing a malicious DLL in a directory listed in the system's PATH environm...

Feb 4, 2022
CVE-2022-0166
7.8

This CVE describes a local privilege escalation vulnerability in McAfee Agent where a low-privileged user can create malicious directories and files t...

Jan 19, 2022
CVE-2021-43037
7.8

CVE-2021-43037 is a privilege escalation vulnerability in Kaseya Unitrends Backup Appliance Windows agent due to insecure default permissions that all...

Dec 6, 2021
CVE-2021-44198
7.8

This CVE describes a DLL hijacking vulnerability in Acronis Cyber Protect 15 for Windows that allows local attackers to escalate privileges by placing...

Nov 29, 2021
CVE-2021-0082
7.8

This vulnerability in Intel PROSet/Wireless WiFi software for Windows 10 allows authenticated local users to escalate privileges by exploiting an unco...

Nov 17, 2021
CVE-2021-31853
7.8

This vulnerability allows local users to execute arbitrary code with elevated privileges by placing a malicious DLL in a folder that McAfee Drive Encr...

Nov 10, 2021
CVE-2021-38416
7.8

Delta Electronics DIALink versions 1.2.4.0 and earlier have a DLL hijacking vulnerability due to insecure library loading. This allows attackers to ex...

Nov 3, 2021
CVE-2021-38420
7.8

Delta Electronics DIALink versions 1.2.4.0 and earlier have insecure default permissions that grant excessive privileges to low-privileged user accoun...

Nov 3, 2021
CVE-2021-22037
7.8

This vulnerability allows attackers to perform path interception attacks on Windows systems by planting a malicious reg.exe binary that gets executed ...

Oct 29, 2021
CVE-2021-30359
7.8

This vulnerability allows attackers to escalate privileges by exploiting the MSI installer repair function in Checkpoint Harmony Browse and SandBlast ...

Oct 22, 2021
CVE-2021-42102
7.8

This vulnerability allows a local attacker with low-privileged code execution to escalate privileges on Trend Micro Apex One installations. It affects...

Oct 21, 2021
CVE-2021-36216
7.8

CVE-2021-36216 is a DLL injection vulnerability in LINE for Windows that allows attackers to execute arbitrary code by placing malicious DLL files in ...

Sep 8, 2021
CVE-2021-20793
7.8

This CVE describes an untrusted search path vulnerability in Sony Audio USB Driver and HAP Music Transfer installers. Attackers can place malicious DL...

Aug 26, 2021
CVE-2021-28595
7.8

CVE-2021-28595 is an uncontrolled search path vulnerability in Adobe Dimension that allows arbitrary code execution when a user opens a malicious file...

Aug 20, 2021
CVE-2020-5316
7.8

This vulnerability allows a locally authenticated low-privileged user to load arbitrary DLLs through Dell SupportAssist, leading to privilege escalati...

Jul 22, 2021
CVE-2021-1089
7.8

This vulnerability in NVIDIA GPU Display Driver for Windows allows attackers to execute arbitrary code, cause denial of service, disclose information,...

Jul 22, 2021
CVE-2021-3550
7.8

This CVE describes a DLL search path vulnerability in Lenovo PCManager that could allow local attackers to escalate privileges by placing a malicious ...

Jul 16, 2021
CVE-2021-36753
7.8

CVE-2021-36753 is a path traversal vulnerability in sharkdp's BAT syntax highlighter where the application executes less.exe from the current working ...

Jul 15, 2021
CVE-2021-3042
7.8

This CVE describes a local privilege escalation vulnerability in Palo Alto Networks Cortex XDR agent on Windows. An authenticated local user with file...

Jul 15, 2021
CVE-2021-22000
7.8

CVE-2021-22000 is a DLL hijacking vulnerability in VMware ThinApp that allows attackers with local non-administrative access to execute arbitrary code...

Jul 13, 2021
CVE-2021-36376
7.8

This vulnerability in dandavison delta on Windows allows path traversal attacks by resolving executable paths relative to the current directory instea...

Jul 13, 2021
CVE-2021-3613
7.8

CVE-2021-3613 is a local privilege escalation vulnerability in OpenVPN Connect for Windows that allows local users to load arbitrary dynamic libraries...

Jul 2, 2021
CVE-2021-29949
7.8

This vulnerability allows Thunderbird to load a malicious shared library instead of the legitimate OTR protocol library due to an incorrect filename s...

Jun 24, 2021
CVE-2021-34803
7.8

This vulnerability in TeamViewer for Windows allows attackers to execute arbitrary code by placing malicious DLL files in specific directories that th...

Jun 16, 2021
CVE-2021-23023
7.8

This CVE describes a DLL hijacking vulnerability in cachecleaner.dll within the BIG-IP Edge Client Windows Installer. Attackers can exploit this by pl...

Jun 10, 2021

About CWE-427 (CWE-427)

Our database tracks 401 CVEs classified as CWE-427, with 7 rated critical and 286 rated high severity. The average CVSS score for CWE-427 vulnerabilities is 7.5.

External reference: View CWE-427 on MITRE CWE →

Monitor CWE-427 Vulnerabilities

Get alerted when new CWE-427 CVEs affect your infrastructure.

Start Monitoring Free