Vulnerability index

Browse CVEs

1,369 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Tmp MEDIUM 5.3
CVE-2025-54798

tmp is a temporary file and directory creator for node.js. In versions 0.2.3 and below, tmp is vulnerable to an arbitrary temporary file / directory …

Fix: 0.2.4+
Fix from $1,600 2025-08-07
Encryption HIGH 7.8
CVE-2025-36611

Dell Encryption and Dell Security Management Server, versions prior to 11.11.0, contain an Improper Link Resolution Before File Access ('Link Followi…

Fix: 11.11.0.1 / 11.11.0.2+
Fix from $1,950 2025-07-30
macOS MEDIUM 6.5
CVE-2025-43252

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sequoia 15.6. A website may be able to access …

Fix: 15.6+
Fix from $1,600 2025-07-30
Ipados CRITICAL 9.8
CVE-2025-43220

This issue was addressed with improved validation of symlinks. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS V…

Fix: 13.7.7 / 14.7.7+
Fix from $2,300 2025-07-30
Unclassified HIGH 8.5
CVE-2025-23267

NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could cause a link following by usi…

Mitigation only
Fix from $1,950 2025-07-17
Unclassified HIGH 8.6
CVE-2025-7012

An issue in Cato Networks' CatoClient for Linux, before version 5.5, allows a local attacker to escalate privileges to root by exploiting improper sy…

Mitigation only
Fix from $1,950 2025-07-13
Password Manager HIGH 7.8
CVE-2025-52837

Trend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could …

Fix: 5.8.0.1330+
Fix from $1,950 2025-07-10
Git HIGH 8.0
CVE-2025-48384 KEV

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full acc…

Fix: 2.43.7 / 2.44.4+
Fix from $1,950 2025-07-08
Pc Manager HIGH 7.8
CVE-2025-49738

Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

Fix: 3.17.4.0+
Fix from $1,950 2025-07-08
Visual Studio HIGH 8.8
CVE-2025-49739

Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.

Fix: 15.9.75 / 16.11.49+
Fix from $1,950 2025-07-08
Windows 10 1507 HIGH 7.3
CVE-2025-49680

Improper link resolution before file access ('link following') in Windows Performance Recorder allows an authorized attacker to deny service locally.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08
Windows 10 1507 HIGH 7.8
CVE-2025-48820

Improper link resolution before file access ('link following') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges…

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08
Windows 10 1607 HIGH 7.8
CVE-2025-48799

Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8246 / 10.0.17763.7558+
Fix from $1,950 2025-07-08
Azure Service Fabric MEDIUM 6.0
CVE-2025-21195

Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevate privileges locally.

Fix: 10.1+
Fix from $1,600 2025-07-08
Unclassified HIGH 8.8
CVE-2025-41666

A low privileged remote attacker with file access can replace a critical file used by the watchdog to get read, write and execute access to any file …

Mitigation only
Fix from $1,950 2025-07-08
Unclassified HIGH 8.8
CVE-2025-41667

A low privileged remote attacker with file access can replace a critical file used by the arp-preinit script to get read, write and execute access to…

Mitigation only
Fix from $1,950 2025-07-08
Unclassified HIGH 8.8
CVE-2025-41668

A low privileged remote attacker with file access can replace a critical file or folder used by the service security-profile to get read, write and e…

Mitigation only
Fix from $1,950 2025-07-08
Unclassified HIGH 7.3
CVE-2025-53109

Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versions of Filesystem prior to 0.6…

Patch available
Fix from $1,950 2025-07-02
System Information Reporter HIGH 7.1
CVE-2025-3771

A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin local user to overwrite system f…

Fix: after 1.0.3
Fix from $1,950 2025-06-26
Unclassified CRITICAL 9.3
CVE-2025-52936

Improper Link Resolution Before File Access ('Link Following') vulnerability in yrutschle sslh.This issue affects sslh: before 2.2.2.

Patch available
Fix from $2,300 2025-06-23
Deep Security Agent HIGH 7.8
CVE-2025-30640

A link following vulnerability in Trend Micro Deep Security 20.0 agents could allow a local attacker to escalate privileges on affected installations…

Fix: 20.0.1+
Fix from $1,950 2025-06-17
Deep Security Agent HIGH 7.8
CVE-2025-30641

A link following vulnerability in the anti-malware solution portion of Trend Micro Deep Security 20.0 agents could allow a local attacker to escalate…

Fix: 20.0.1+
Fix from $1,950 2025-06-17
Deep Security Agent MEDIUM 5.5
CVE-2025-30642

A link following vulnerability in Trend Micro Deep Security 20.0 agents could allow a local attacker to create a denial of service (DoS) situation on…

Fix: 20.0.1+
Fix from $1,600 2025-06-17
Apex One HIGH 7.8
CVE-2025-49156

A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalation privileges on affected installation…

Fix: 14.0.0.14002 / 14.0.14492+
Fix from $1,950 2025-06-17
Apex One HIGH 7.8
CVE-2025-49157

A link following vulnerability in the Trend Micro Apex One Damage Cleanup Engine could allow a local attacker to escalation privileges on affected in…

Fix: 14.0.0.14002 / 14.0.14492+
Fix from $1,950 2025-06-17
Go MEDIUM 5.5
CVE-2025-0913

os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, O…

Fix: 1.23.10 / 1.24.4+
Fix from $1,600 2025-06-11
Windows 10 1507 HIGH 7.8
CVE-2025-33075

Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21034 / 10.0.14393.8148+
Fix from $1,950 2025-06-10
Windows 10 1507 HIGH 7.3
CVE-2025-32721

Improper link resolution before file access ('link following') in Windows Recovery Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21034 / 10.0.14393.8148+
Fix from $1,950 2025-06-10
Syncbackfree HIGH 7.3
CVE-2025-5474

2BrightSparks SyncBackFree Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges …

Mitigation only
Fix from $1,950 2025-06-06
Encryption HIGH 7.8
CVE-2025-36564

Dell Encryption Admin Utilities versions prior to 11.10.2 contain an Improper Link Resolution vulnerability. A local malicious user could potentially…

Fix: 11.10.2+
Fix from $1,950 2025-06-03