CWE-427: CWE-427
Yearly Trend
Top Affected Vendors
All CWE-427 CVEs (401)
This CVE describes an elevation of privilege vulnerability in Visual Studio Code where an attacker could execute arbitrary code with higher privileges...
Feb 11, 2025This vulnerability in Visual Studio Installer allows attackers to elevate privileges on Windows systems. An authenticated attacker could execute arbit...
Feb 11, 2025NetMod VPN Client 5.3.1 is vulnerable to DLL injection, allowing attackers to execute arbitrary code by placing malicious DLLs in directories where th...
Feb 6, 2025This vulnerability allows local attackers to escalate privileges on systems running vulnerable versions of Famatech Advanced IP Scanner. Attackers who...
Nov 22, 2024Solid Edge SE2024 versions before V224.0 Update 9 contain a DLL hijacking vulnerability that allows attackers to execute arbitrary code by placing a m...
Nov 12, 2024This CVE describes a local privilege escalation vulnerability in Acronis Cyber Files for Windows due to DLL hijacking. Attackers with local access can...
Oct 17, 2024This CVE describes an uncontrolled search path element vulnerability in Diebold Nixdorf products, allowing attackers to execute arbitrary code by plac...
Oct 6, 2024This vulnerability allows authenticated local attackers to execute arbitrary code with SYSTEM privileges on Windows systems running vulnerable Cisco M...
Sep 12, 2024This CVE describes a local privilege escalation vulnerability in Acronis Snap Deploy for Windows due to DLL hijacking. Attackers with local access can...
Aug 29, 2024This CVE describes a local privilege escalation vulnerability in Acronis Snap Deploy for Windows due to DLL hijacking. Attackers with local access can...
Aug 29, 2024Dell Peripheral Manager versions before 1.7.6 have a DLL hijacking vulnerability where attackers can place malicious DLLs in locations the software se...
Jul 31, 2024Dell Peripheral Manager versions before 1.7.6 have a DLL hijacking vulnerability where attackers can place malicious DLLs in locations the application...
Jul 31, 2024Dell OpenManage Server Administrator (OMSA) versions 11.0.1.0 and prior contain a local privilege escalation vulnerability via XSL hijacking. A local ...
Jun 11, 2024This vulnerability allows attackers with local access to execute arbitrary code by placing malicious DLLs in the same folder as the SanDisk Security I...
Nov 15, 2023This CVE describes a DLL search order hijacking vulnerability in SonicWall NetExtender Windows client versions 10.2.336 and earlier. A local attacker ...
Oct 27, 2023This CVE describes a DLL hijacking vulnerability in Acronis Cyber Protect products on Windows that allows local attackers to escalate privileges. An a...
Oct 9, 2023This vulnerability in CODESYS Development System allows attackers to execute arbitrary binaries from the current working directory with the user's pri...
Aug 3, 2023This vulnerability allows standard users to replace files in the Acuant AcuFill SDK installation directory due to insecure permissions. When these fil...
Apr 4, 2023This vulnerability in AFL++ 4.05c allows attackers to execute arbitrary code by exploiting the CmpLog component's use of the current working directory...
Feb 21, 2023This vulnerability allows attackers to perform DLL hijacking in AVEVA PCS Portal by placing malicious DLLs in locations the software searches. It affe...
Jul 27, 2022ShowMyPC 3606 on Windows has a DLL hijack vulnerability where attackers can place malicious code in a specific temporary directory file (wodVPN.dll) t...
Jul 18, 2022Node.js on Windows is vulnerable to DLL hijacking when OpenSSL is installed with a specific configuration file path. This allows attackers to execute ...
Jul 14, 2022This DLL search path vulnerability in Lenovo PCManager allows attackers to place malicious DLLs in directories searched by the application, potentiall...
Apr 22, 2022This vulnerability allows local privilege escalation in Razer Synapse software. An unprivileged user can create a directory and place malicious DLLs b...
Mar 23, 2022This CVE describes a DLL hijacking vulnerability in Acronis Media Builder service that allows local attackers to escalate privileges on Windows system...
Feb 4, 2022This CVE describes a DLL hijacking vulnerability in Adobe Acrobat Reader DC where a local attacker with non-administrative privileges can plant a mali...
Sep 29, 2021This vulnerability allows an attacker to execute arbitrary code on a victim's system by placing a malicious DLL in the C:/ folder and tricking the use...
Aug 20, 2021This vulnerability allows authenticated local attackers on Windows systems with McAfee Agent to perform DLL preloading attacks using unsigned DLLs, le...
Jun 10, 2021This vulnerability in Intel Driver & Support Assistant (DSA) allows authenticated local users to escalate privileges by exploiting an uncontrolled sea...
Jun 9, 2021This vulnerability in Intel Processor Diagnostic Tool allows authenticated local users to escalate privileges by exploiting an uncontrolled search pat...
Jun 9, 2021This CVE describes an Uncontrolled Search Path Element vulnerability in multiple B&R Industrial Automation products that allows an authenticated local...
May 14, 2024This vulnerability in McAfee Safe Connect allows attackers with existing system privileges to escalate their privileges by loading arbitrary DLLs. It ...
Aug 21, 2023TrueConf Client 8.5.2 is vulnerable to DLL hijacking where attackers can place a malicious wfapi.dll file to execute arbitrary code. This affects loca...
Dec 30, 2025This vulnerability allows local attackers to escalate privileges on TensorFlow installations by exploiting an insecure plugin loading mechanism. Attac...
Feb 20, 2026This CVE describes an uncontrolled search path element vulnerability in Elastic Beats Windows installer that allows local privilege escalation. Attack...
Jul 30, 2025This CVE describes an uncontrolled search path element vulnerability in Forcepoint FIE Endpoint that allows attackers to escalate privileges, inject c...
May 22, 2025CVE-2024-41817 is a path injection vulnerability in ImageMagick's AppImage version where empty paths in MAGICK_CONFIGURE_PATH and LD_LIBRARY_PATH envi...
Jul 29, 2024This vulnerability in IBM System Management for i allows a local user to escalate privileges by exploiting an unqualified library program call. An att...
Jul 8, 2024This is a DLL hijacking vulnerability in Mitsubishi Electric's GENESIS and ICONICS industrial control software suites. A local attacker can execute ar...
Jul 4, 2024Dell OpenManage Server Administrator (OMSA) versions 10.3.0.0 and earlier contain a DLL injection vulnerability that allows local authenticated attack...
Feb 1, 2023This vulnerability allows authenticated local attackers to perform DLL hijacking attacks on affected Cisco security products for Windows. Attackers ca...
Apr 8, 2021CVE-2021-21008 is a path traversal vulnerability in Adobe Animate that allows arbitrary code execution when a user opens a malicious file. Attackers c...
Jan 13, 2021CVE-2021-21010 is an uncontrolled search path vulnerability in Adobe InCopy for Windows that allows arbitrary code execution when a user opens a malic...
Jan 13, 2021This vulnerability allows physically-present attackers to escalate privileges on PDFsam Enhanced installations by exploiting an insecure OpenSSL confi...
Dec 23, 2025This vulnerability allows attackers to execute arbitrary code by planting malicious DLL files that the ASPECT configuration toolset loads without prop...
May 22, 2025Dell PowerScale OneFS contains an uncontrolled search path vulnerability that allows high-privileged local attackers to execute arbitrary code by mani...
Mar 4, 2026This vulnerability allows local attackers to execute arbitrary code or access sensitive files by placing a malicious DLL in the same directory as the ...
Feb 24, 2026This vulnerability allows arbitrary code execution when PsySH (a PHP developer console) automatically loads a malicious .psysh.php file from the curre...
Jan 30, 2026CVE-2025-33231 is a DLL hijacking vulnerability in NVIDIA Nsight Systems for Windows that allows attackers to execute arbitrary code by placing malici...
Jan 20, 2026This CVE describes a Search Order Hijacking vulnerability in Altera Quartus Prime's Nios II Command Shell modules on Windows. Attackers can place mali...
Jan 7, 2026About CWE-427 (CWE-427)
Our database tracks 401 CVEs classified as CWE-427, with 7 rated critical and 286 rated high severity. The average CVSS score for CWE-427 vulnerabilities is 7.5.
External reference: View CWE-427 on MITRE CWE →
Monitor CWE-427 Vulnerabilities
Get alerted when new CWE-427 CVEs affect your infrastructure.
Start Monitoring Free