Vulnerability index

Browse CVEs

1,369 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Ipados MEDIUM 6.3
CVE-2025-43448

This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS S…

Fix: 14.8.2 / 15.7.2+
Fix from $1,600 2025-11-04
macOS MEDIUM 5.5
CVE-2025-43394

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An a…

Fix: 14.8.2 / 15.7.2+
Fix from $1,600 2025-11-04
Ipados MEDIUM 5.5
CVE-2025-43379

This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14…

Fix: 14.8.2 / 15.7.2+
Fix from $1,600 2025-11-04
macOS MEDIUM 5.5
CVE-2025-43288

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An app may be able to bypas…

Fix: 15.7+
Fix from $1,600 2025-11-04
Synapse HIGH 7.8
CVE-2025-9870

Razer Synapse 3 RazerPhilipsHueUninstall Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escala…

Fix: 3.10.730.71519+
Fix from $1,950 2025-10-29
Synapse HIGH 7.8
CVE-2025-9871

Razer Synapse 3 Chroma Connect Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privile…

Fix: 3.10.730.71519+
Fix from $1,950 2025-10-29
Synapse HIGH 7.8
CVE-2025-9869

Razer Synapse 3 Macro Module Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privilege…

Fix: 3.10.730.71519+
Fix from $1,950 2025-10-29
Unclassified HIGH 7.8
CVE-2025-12341

A vulnerability was detected in ermig1979 AntiDupl up to 2.3.12. Impacted is an unknown function of the file AntiDupl.NET.WinForms.exe of the compone…

Mitigation only
Fix from $1,950 2025-10-28
Unclassified HIGH 8.6
CVE-2025-26625

Git LFS is a Git extension for versioning large files. In Git LFS versions 0.5.2 through 3.7.0, when populating a Git repository's working tree with …

Patch available
Fix from $1,950 2025-10-17
Xbox Gaming Services HIGH 7.8
CVE-2025-59281

Improper link resolution before file access ('link following') in XBox Gaming Services allows an authorized attacker to elevate privileges locally.

Fix: 31.105.17001.0+
Fix from $1,950 2025-10-14
Windows 11 24h2 HIGH 7.8
CVE-2025-59241

Improper link resolution before file access ('link following') in Windows Health and Optimized Experiences Service allows an authorized attacker to e…

Fix: 10.0.26100.6899 / 10.0.26200.6899+
Fix from $1,950 2025-10-14
.net HIGH 7.3
CVE-2025-55247

Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.

Fix: 8.0.21 / 9.0.10+
Fix from $1,950 2025-10-14
Unclassified HIGH 7.8
CVE-2025-62363

yt-grabber-tui is a terminal user interface application for downloading videos. In versions before 1.0-rc, the application allows users to configure …

Patch available
Fix from $1,950 2025-10-13
Unclassified MEDIUM 6.2
CVE-2025-62364

text-generation-webui is an open-source web interface for running Large Language Models. In versions through 3.13, a Local File Inclusion vulnerabili…

Patch available
Fix from $1,600 2025-10-13
Unclassified HIGH 8.5
CVE-2025-9968

A link following vulnerability exists in the UnifyScanner component of Armoury Crate. This vulnerability may be triggered by creating a specially cra…

Mitigation only
Fix from $1,950 2025-10-13
Kiwire MEDIUM 5.4
CVE-2025-11190

The Kiwire Captive Portal contains an open redirection issue via the login-url parameter, allowing an attacker to redirect users to an attacker contr…

Mitigation only
Fix from $1,600 2025-10-10
Desktopcommandermcp HIGH 7.0
CVE-2025-11489

A security vulnerability has been detected in wonderwhy-er DesktopCommanderMCP up to 0.2.13. This vulnerability affects the function isPathAllowed of…

Fix: after 0.2.13
Fix from $1,950 2025-10-08
Unclassified HIGH 7.8
CVE-2025-11462

Improper Link Resolution Before File Access in the AWS VPN Client for macOS versions 1.3.2- 5.2.0 allows a local user to execute code with elevated p…

Mitigation only
Fix from $1,950 2025-10-07
Virtual Appliance Application HIGH 8.4
CVE-2025-34191

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.843 and Application prior to 20.0.1923 (macOS/Linux client deploym…

Fix: 20.0.1923 / 22.0.843+
Fix from $1,950 2025-09-19
Virtual Appliance Application HIGH 7.8
CVE-2025-34194

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior to 25.1.1413 (Windows client de…

No fix yet
Fix from $1,950 2025-09-19
Xbox Gaming Services HIGH 7.8
CVE-2025-55245

Improper link resolution before file access ('link following') in Xbox allows an authorized attacker to elevate privileges locally.

Fix: 30.104.13001.0+
Fix from $1,950 2025-09-09
Autoupdate HIGH 7.8
CVE-2025-55317

Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges loca…

Fix: 4.80+
Fix from $1,950 2025-09-09
Roo Code MEDIUM 6.5
CVE-2025-58373

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability where .rooignore p…

Fix: 3.26.0+
Fix from $1,600 2025-09-05
Alienware Command Center HIGH 7.8
CVE-2025-43726

Dell Alienware Command Center 5.x (AWCC), versions prior to 5.10.2.0, contains an Improper Link Resolution Before File Access ('Link Following')" vul…

Fix: 5.10.2.0+
Fix from $1,950 2025-09-02
macOS MEDIUM 5.5
CVE-2024-54554

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be able to access sensitive user d…

Fix: 15.1+
Fix from $1,600 2025-08-29
N8n MEDIUM 6.5
CVE-2025-57749

n8n is a workflow automation platform. Before 1.106.0, a symlink traversal vulnerability was discovered in the Read/Write File node in n8n. While the…

Fix: 1.106.0+
Fix from $1,600 2025-08-20
Backupper Workstation HIGH 7.3
CVE-2025-8612

AOMEI Backupper Workstation Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges…

Mitigation only
Fix from $1,950 2025-08-20
Unclassified HIGH 7.3
CVE-2025-5296

CWE-59: Improper Link Resolution Before File Access ('Link Following') vulnerability exists that could cause arbitrary data to be written to protect…

Mitigation only
Fix from $1,950 2025-08-18
Go Getter HIGH 7.5
CVE-2025-8959

HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designate…

Fix: 1.7.9+
Fix from $1,950 2025-08-15
Unclassified HIGH 8.4
CVE-2025-43490

A potential security vulnerability has been identified in the HPAudioAnalytics service included in the HP Hotkey Support software, which might allow …

Mitigation only
Fix from $1,950 2025-08-15