Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Windows 10 1507 HIGH 7.8
CVE-2025-21204EPSS 7%

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
macOS CRITICAL 9.8
CVE-2025-30457

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. …

Fix: 13.7.5 / 14.7.5+
Fix from $2,300 2025-03-31
macOS MEDIUM 5.5
CVE-2025-24278

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. …

Fix: 13.7.5 / 14.7.5+
Fix from $1,600 2025-03-31
Unclassified HIGH 7.5
CVE-2024-12905

An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal").…

Patch available
Fix from $1,950 2025-03-27
Edge Update HIGH 7.8
CVE-2025-29795

Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges…

Fix: 1.3.195.45+
Fix from $1,950 2025-03-23
Gpt Academic HIGH 8.8
CVE-2024-12390

A vulnerability in binary-husky/gpt_academic version git 310122f allows for remote code execution. The application supports the extraction of user-pr…

No fix yet
Fix from $1,950 2025-03-20
Unclassified HIGH 7.1
CVE-2024-12216

A vulnerability in the `ImageClassificationDataset.from_csv()` API of the `dmlc/gluon-cv` repository, version 0.10.0, allows for arbitrary file write…

Mitigation only
Fix from $1,950 2025-03-20
Gpt Academic HIGH 8.8
CVE-2024-10986

GPT Academic version 3.83 is vulnerable to a Local File Read (LFI) vulnerability through its HotReload function. This function can download and extra…

No fix yet
Fix from $1,950 2025-03-20
Platform HIGH 7.8
CVE-2025-1683

Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an attacker with local unprivile…

Fix: 25.3+
Fix from $1,950 2025-03-12
Windows Server 2016 HIGH 7.1
CVE-2025-25008

Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.7876 / 10.0.17763.7009+
Fix from $1,950 2025-03-11
Gpt Academic HIGH 7.5
CVE-2025-25185

GPT Academic provides interactive interfaces for large language models. In 3.91 and earlier, GPT Academic does not properly account for soft links. A…

Patch available
Fix from $1,950 2025-03-03
Meeting Software Development Kit HIGH 8.8
CVE-2024-45418

Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to conduct an escalation of priv…

Fix: 6.1.5+
Fix from $1,950 2025-02-25
Supportassist Os Recovery HIGH 7.8
CVE-2025-22480

Dell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability. A low-privileged attacker with local access c…

Fix: 5.5.13.1+
Fix from $1,950 2025-02-13
Anyconnect Secure Mobility Client MEDIUM 5.6
CVE-2020-3432

A vulnerability in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS could allow an authenticated, local attacker to co…

Fix: 4.9.00086+
Fix from $1,600 2025-02-12
Windows 10 1507 HIGH 7.1
CVE-2025-21419

Windows Setup Files Cleanup Elevation of Privilege Vulnerability

Fix: 10.0.10240.20915 / 10.0.14393.7785+
Fix from $1,950 2025-02-11
Windows 10 1507 HIGH 7.8
CVE-2025-21420

Windows Disk Cleanup Tool Elevation of Privilege Vulnerability

Fix: 10.0.10240.20915 / 10.0.14393.7785+
Fix from $1,950 2025-02-11
Windows 10 1507 HIGH 7.1
CVE-2025-21391 KEV

Windows Storage Elevation of Privilege Vulnerability

Fix: 10.0.10240.20915 / 10.0.14393.7785+
Fix from $1,950 2025-02-11
Windows 10 1507 HIGH 7.8
CVE-2025-21373

Windows Installer Elevation of Privilege Vulnerability

Fix: 10.0.10240.20915 / 10.0.14393.7785+
Fix from $1,950 2025-02-11
Pc Manager HIGH 7.8
CVE-2025-21322

Microsoft PC Manager Elevation of Privilege Vulnerability

Fix: 3.15.4.0+
Fix from $1,950 2025-02-11
Windows 10 1507 MEDIUM 6.0
CVE-2025-21347

Windows Deployment Services Denial of Service Vulnerability

Fix: 10.0.10240.20915 / 10.0.14393.7785+
Fix from $1,600 2025-02-11
Azure Network Watcher MEDIUM 6.0
CVE-2025-21188

Azure Network Watcher VM Extension Elevation of Privilege Vulnerability

Fix: 1.4.3563.1+
Fix from $1,600 2025-02-11
Remote Application Server HIGH 7.8
CVE-2025-0413

Parallels Desktop Technical Data Reporter Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to esca…

Fix: 19.4.3.2-25228 / 19.4.3-25221+
Fix from $1,950 2025-02-05
Meeting Software Development Kit MEDIUM 5.0
CVE-2025-0146

Symlink following in the installer for Zoom Workplace App for macOS before 6.2.10 may allow an authenticated user to conduct a denial of service via …

Fix: 6.2.10+
Fix from $1,600 2025-01-30
macOS MEDIUM 5.5
CVE-2025-24103

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. …

Fix: 13.7.3 / 14.7.3+
Fix from $1,600 2025-01-27
Ipados MEDIUM 5.5
CVE-2025-24104

This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4. Restoring a maliciously …

Fix: 17.7.4 / 18.3+
Fix from $1,600 2025-01-27
Go Slug CRITICAL 9.1
CVE-2025-0377

HashiCorp’s go-slug library is vulnerable to a zip-slip style attack when a non-existing user-provided path is extracted from the tar entry.

Fix: 0.16.3+
Fix from $2,300 2025-01-21
Simplehelp HIGH 7.2
CVE-2024-57728 KEVEPSS 7%

SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted …

Fix: 5.5.8+
Fix from $1,950 2025-01-15
Windows 10 1507 HIGH 7.3
CVE-2025-21331

Windows Installer Elevation of Privilege Vulnerability

Fix: 10.0.10240.20890 / 10.0.14393.7699+
Fix from $1,950 2025-01-14
Windows 10 1507 MEDIUM 5.5
CVE-2025-21274

Windows Event Tracing Denial of Service Vulnerability

Fix: 10.0.10240.20890 / 10.0.14393.7699+
Fix from $1,600 2025-01-14
Apex One HIGH 7.8
CVE-2024-52050

A LogServer arbitrary file creation vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installatio…

Fix: 14.0.14203 / 2019.13140+
Fix from $1,950 2024-12-31