Filtered by CWE-491
Total 5 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-63685 1 Quark 1 Cloud Drive 2025-11-24 9.8 Critical
Quark Cloud Drive v3.23.2 has a DLL Hijacking vulnerability. This vulnerability stems from the insecure loading of system libraries. Specifically, the application does not validate the path or signature of [regsvr32.exe] it loads. An attacker can place a crafted malicious DLL in the application's startup directory, which will be loaded and executed when the user launches the program.
CVE-2025-60425 1 Nagios 1 Fusion 2025-11-05 8.6 High
Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authentication mechanism is enabled, allowing attackers to perform a session hijacking attack.
CVE-2025-55622 1 Reolink 1 Reolink 2025-10-02 6.5 Medium
Reolink v4.54.0.4.20250526 was discovered to contain a task hijacking vulnerability due to inappropriate taskAffinity settings. NOTE: this is disputed by the Supplier because it is intentional behavior to ensure a predictable user experience.
CVE-2023-28260 1 Microsoft 2 .net, Visual Studio 2022 2025-01-23 7.8 High
.NET DLL Hijacking Remote Code Execution Vulnerability
CVE-2024-39069 1 Ifood 1 Order Manager 2024-11-21 7.8 High
An issue in ifood Order Manager v3.35.5 'Gestor de Peddios.exe' allows attackers to execute arbitrary code via a DLL hijacking attack.