Vulnerability index

Browse CVEs

1,369 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Unclassified MEDIUM 6.4
CVE-2026-47699

Confidential Containers Guest Components provides guest tools and components for confidential container workloads. From 0.16.0 until 0.20.0, a crafte…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 7.1
CVE-2026-17106

The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem o…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 8.1
CVE-2026-19693

extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an ar…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified MEDIUM 6.1
CVE-2026-74796

OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious sym…

No fix yet
Fix from $4,000 2026-08-16
Unclassified HIGH 7.5
CVE-2026-19909

PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execu…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 8.1
CVE-2026-70460

rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks with…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.1
CVE-2026-63426

During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an authenticated local user …

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.8
CVE-2026-53803

rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a pred…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.3
CVE-2026-53799

rsync before 3.5.0 contains a symlink race condition vulnerability that allows local attackers to cause rsync to apply arbitrary ACLs or extended att…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.9
CVE-2026-53801

rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's directory scanning logic that allows attackers to cause the sender…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.3
CVE-2026-53796

rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the non-daemon receiver's destination directory h…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 8.1
CVE-2026-53795

rsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the intended destination tree by speci…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.4
CVE-2026-53793

rsync before 3.5.0 contains a path confinement bypass vulnerability that allows remote clients to escape the intended inner-module root confinement b…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.1
CVE-2026-53784

rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intended module root when use chroo…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.1
CVE-2026-53785

rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the intended destination directory t…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.1
CVE-2026-53783

rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows a…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.0
CVE-2026-15994

During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Lenovo Commercial Vantage that …

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.1
CVE-2026-12036

An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could allow a loc…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.2
CVE-2026-73613

filebrowser versions before 2.63.19 contain an out-of-scope file deletion vulnerability in the TUS upload cache eviction mechanism that allows authen…

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.9
CVE-2026-63293

A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or un…

No fix yet
Fix from $5,750 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-63294

A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of craf…

No fix yet
Fix from $5,750 2026-08-12
Onedrive MEDIUM 6.7
CVE-2026-65680

Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.

No fix yet
Fix from $4,000 2026-08-11
Windows 11 26h1 MEDIUM 5.5
CVE-2026-72971

Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized att…

Fix: 10.0.28000.2704+
Fix from $4,000 2026-08-11
Windows 11 24h2 MEDIUM 5.5
CVE-2026-70348

Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.

Fix: 10.0.26100.9106 / 10.0.26200.9106+
Fix from $4,000 2026-08-11
Windows 10 21h2 HIGH 7.8
CVE-2026-62832

Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges lo…

Fix: 10.0.19044.7663 / 10.0.19045.7663+
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-62812

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

No fix yet
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-62803

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-62807

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

No fix yet
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-62776

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

No fix yet
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-62761

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

No fix yet
Fix from $4,900 2026-08-11