CWE-427: CWE-427

401
Total CVEs
7
Critical
286
High
7.5
Avg CVSS

Yearly Trend

2026
36
2025
151
2024
88
2023
45
2022
26

Top Affected Vendors

1 Intel 37
2 Acronis 13
3 Dell 11
4 Mailenable 10
5 Lenovo 8
6 Microsoft 8
7 Adobe 8
8 Trendmicro 7
9 Siemens 7
10 Nvidia 6

All CWE-427 CVEs (401)

CVE-2025-24039
7.3

This CVE describes an elevation of privilege vulnerability in Visual Studio Code where an attacker could execute arbitrary code with higher privileges...

Feb 11, 2025
CVE-2025-21206
7.3

This vulnerability in Visual Studio Installer allows attackers to elevate privileges on Windows systems. An authenticated attacker could execute arbit...

Feb 11, 2025
CVE-2024-57426
7.3

NetMod VPN Client 5.3.1 is vulnerable to DLL injection, allowing attackers to execute arbitrary code by placing malicious DLLs in directories where th...

Feb 6, 2025
CVE-2024-30376
7.3

This vulnerability allows local attackers to escalate privileges on systems running vulnerable versions of Famatech Advanced IP Scanner. Attackers who...

Nov 22, 2024
CVE-2024-47942
7.3

Solid Edge SE2024 versions before V224.0 Update 9 contain a DLL hijacking vulnerability that allows attackers to execute arbitrary code by placing a m...

Nov 12, 2024
CVE-2024-49391
7.3

This CVE describes a local privilege escalation vulnerability in Acronis Cyber Files for Windows due to DLL hijacking. Attackers with local access can...

Oct 17, 2024
CVE-2024-45246
7.3

This CVE describes an uncontrolled search path element vulnerability in Diebold Nixdorf products, allowing attackers to execute arbitrary code by plac...

Oct 6, 2024
CVE-2024-20430
7.3

This vulnerability allows authenticated local attackers to execute arbitrary code with SYSTEM privileges on Windows systems running vulnerable Cisco M...

Sep 12, 2024
CVE-2024-34019
7.3

This CVE describes a local privilege escalation vulnerability in Acronis Snap Deploy for Windows due to DLL hijacking. Attackers with local access can...

Aug 29, 2024
CVE-2024-34017
7.3

This CVE describes a local privilege escalation vulnerability in Acronis Snap Deploy for Windows due to DLL hijacking. Attackers with local access can...

Aug 29, 2024
CVE-2024-37142
7.3

Dell Peripheral Manager versions before 1.7.6 have a DLL hijacking vulnerability where attackers can place malicious DLLs in locations the software se...

Jul 31, 2024
CVE-2024-32857
7.3

Dell Peripheral Manager versions before 1.7.6 have a DLL hijacking vulnerability where attackers can place malicious DLLs in locations the application...

Jul 31, 2024
CVE-2024-37130
7.3

Dell OpenManage Server Administrator (OMSA) versions 11.0.1.0 and prior contain a local privilege escalation vulnerability via XSL hijacking. A local ...

Jun 11, 2024
CVE-2023-22818
7.3

This vulnerability allows attackers with local access to execute arbitrary code by placing malicious DLLs in the same folder as the SanDisk Security I...

Nov 15, 2023
CVE-2023-44220
7.3

This CVE describes a DLL search order hijacking vulnerability in SonicWall NetExtender Windows client versions 10.2.336 and earlier. A local attacker ...

Oct 27, 2023
CVE-2023-45248
7.3

This CVE describes a DLL hijacking vulnerability in Acronis Cyber Protect products on Windows that allows local attackers to escalate privileges. An a...

Oct 9, 2023
CVE-2023-3662
7.3

This vulnerability in CODESYS Development System allows attackers to execute arbitrary binaries from the current working directory with the user's pri...

Aug 3, 2023
CVE-2022-48224
7.3

This vulnerability allows standard users to replace files in the Acuant AcuFill SDK installation directory due to insecure permissions. When these fil...

Apr 4, 2023
CVE-2023-26266
7.3

This vulnerability in AFL++ 4.05c allows attackers to execute arbitrary code by exploiting the CmpLog component's use of the current working directory...

Feb 21, 2023
CVE-2021-38410
7.3

This vulnerability allows attackers to perform DLL hijacking in AVEVA PCS Portal by placing malicious DLLs in locations the software searches. It affe...

Jul 27, 2022
CVE-2021-42923
7.3

ShowMyPC 3606 on Windows has a DLL hijack vulnerability where attackers can place malicious code in a specific temporary directory file (wodVPN.dll) t...

Jul 18, 2022
CVE-2022-32223
7.3

Node.js on Windows is vulnerable to DLL hijacking when OpenSSL is installed with a specific configuration file path. This allows attackers to execute ...

Jul 14, 2022
CVE-2022-0192
7.3

This DLL search path vulnerability in Lenovo PCManager allows attackers to place malicious DLLs in directories searched by the application, potentiall...

Apr 22, 2022
CVE-2021-44226
7.3

This vulnerability allows local privilege escalation in Razer Synapse software. An unprivileged user can create a directory and place malicious DLLs b...

Mar 23, 2022
CVE-2021-44206
7.3

This CVE describes a DLL hijacking vulnerability in Acronis Media Builder service that allows local attackers to escalate privileges on Windows system...

Feb 4, 2022
CVE-2021-35982
7.3

This CVE describes a DLL hijacking vulnerability in Adobe Acrobat Reader DC where a local attacker with non-administrative privileges can plant a mali...

Sep 29, 2021
CVE-2021-28636
7.3

This vulnerability allows an attacker to execute arbitrary code on a victim's system by placing a malicious DLL in the C:/ folder and tricking the use...

Aug 20, 2021
CVE-2021-31840
7.3

This vulnerability allows authenticated local attackers on Windows systems with McAfee Agent to perform DLL preloading attacks using unsigned DLLs, le...

Jun 10, 2021
CVE-2021-0090
7.3

This vulnerability in Intel Driver & Support Assistant (DSA) allows authenticated local users to escalate privileges by exploiting an uncontrolled sea...

Jun 9, 2021
CVE-2020-8702
7.3

This vulnerability in Intel Processor Diagnostic Tool allows authenticated local users to escalate privileges by exploiting an uncontrolled search pat...

Jun 9, 2021
CVE-2024-2637
7.2

This CVE describes an Uncontrolled Search Path Element vulnerability in multiple B&R Industrial Automation products that allows an authenticated local...

May 14, 2024
CVE-2023-40352
7.2

This vulnerability in McAfee Safe Connect allows attackers with existing system privileges to escalate their privileges by loading arbitrary DLLs. It ...

Aug 21, 2023
CVE-2025-66835
7.1

TrueConf Client 8.5.2 is vulnerable to DLL hijacking where attackers can place a malicious wfapi.dll file to execute arbitrary code. This affects loca...

Dec 30, 2025
CVE-2026-2492
7.0

This vulnerability allows local attackers to escalate privileges on TensorFlow installations by exploiting an insecure plugin loading mechanism. Attac...

Feb 20, 2026
CVE-2025-0712
7.0

This CVE describes an uncontrolled search path element vulnerability in Elastic Beats Windows installer that allows local privilege escalation. Attack...

Jul 30, 2025
CVE-2025-2272
7.0

This CVE describes an uncontrolled search path element vulnerability in Forcepoint FIE Endpoint that allows attackers to escalate privileges, inject c...

May 22, 2025
CVE-2024-41817
7.0

CVE-2024-41817 is a path injection vulnerability in ImageMagick's AppImage version where empty paths in MAGICK_CONFIGURE_PATH and LD_LIBRARY_PATH envi...

Jul 29, 2024
CVE-2024-38330
7.0

This vulnerability in IBM System Management for i allows a local user to escalate privileges by exploiting an unqualified library program call. An att...

Jul 8, 2024
CVE-2024-1182
7.0

This is a DLL hijacking vulnerability in Mitsubishi Electric's GENESIS and ICONICS industrial control software suites. A local attacker can execute ar...

Jul 4, 2024
CVE-2022-34396
7.0

Dell OpenManage Server Administrator (OMSA) versions 10.3.0.0 and earlier contain a DLL injection vulnerability that allows local authenticated attack...

Feb 1, 2023
CVE-2021-1386
7.0

This vulnerability allows authenticated local attackers to perform DLL hijacking attacks on affected Cisco security products for Windows. Attackers ca...

Apr 8, 2021
CVE-2021-21008
7.0

CVE-2021-21008 is a path traversal vulnerability in Adobe Animate that allows arbitrary code execution when a user opens a malicious file. Attackers c...

Jan 13, 2021
CVE-2021-21010
7.0

CVE-2021-21010 is an uncontrolled search path vulnerability in Adobe InCopy for Windows that allows arbitrary code execution when a user opens a malic...

Jan 13, 2021
CVE-2025-14405
6.8

This vulnerability allows physically-present attackers to escalate privileges on PDFsam Enhanced installations by exploiting an insecure OpenSSL confi...

Dec 23, 2025
CVE-2024-13946
6.8

This vulnerability allows attackers to execute arbitrary code by planting malicious DLL files that the ASPECT configuration toolset loads without prop...

May 22, 2025
CVE-2026-22270
6.7

Dell PowerScale OneFS contains an uncontrolled search path vulnerability that allows high-privileged local attackers to execute arbitrary code by mani...

Mar 4, 2026
CVE-2026-3091
6.7

This vulnerability allows local attackers to execute arbitrary code or access sensitive files by placing a malicious DLL in the same directory as the ...

Feb 24, 2026
CVE-2026-25129
6.7

This vulnerability allows arbitrary code execution when PsySH (a PHP developer console) automatically loads a malicious .psysh.php file from the curre...

Jan 30, 2026
CVE-2025-33231
6.7

CVE-2025-33231 is a DLL hijacking vulnerability in NVIDIA Nsight Systems for Windows that allows attackers to execute arbitrary code by placing malici...

Jan 20, 2026
CVE-2025-14625
6.7

This CVE describes a Search Order Hijacking vulnerability in Altera Quartus Prime's Nios II Command Shell modules on Windows. Attackers can place mali...

Jan 7, 2026

About CWE-427 (CWE-427)

Our database tracks 401 CVEs classified as CWE-427, with 7 rated critical and 286 rated high severity. The average CVSS score for CWE-427 vulnerabilities is 7.5.

External reference: View CWE-427 on MITRE CWE →

Monitor CWE-427 Vulnerabilities

Get alerted when new CWE-427 CVEs affect your infrastructure.

Start Monitoring Free