Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Powerscale Onefs MEDIUM 6.0
CVE-2024-25953

Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged atta…

Fix: 9.5.0.8 / 9.7.0.2+
Fix from $1,600 2024-03-28
Unclassified HIGH 7.9
CVE-2024-29188

WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The custom action behind WiX's `RemoveFolderEx`…

Patch available
Fix from $1,950 2024-03-24
Xbox Gaming Services HIGH 8.8
CVE-2024-28916

Xbox Gaming Services Elevation of Privilege Vulnerability

Fix: 19.87.13001.0+
Fix from $1,950 2024-03-21
Unclassified HIGH 8.6
CVE-2024-1753

A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build co…

Mitigation only
Fix from $1,950 2024-03-18
365 Apps HIGH 7.8
CVE-2024-26199

Microsoft Office Elevation of Privilege Vulnerability

No fix yet
Fix from $1,950 2024-03-12
Windows 10 1507 HIGH 7.0
CVE-2024-21432

Windows Update Stack Elevation of Privilege Vulnerability

Fix: 10.0.10240.20526 / 10.0.14393.6796+
Fix from $1,950 2024-03-12
macOS MEDIUM 5.5
CVE-2024-23285

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sonoma 14.4. An app may be able to create symlinks to prote…

Fix: 14.4+
Fix from $1,600 2024-03-08
Workforce Access HIGH 7.1
CVE-2024-0068

Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows File Manipulation.This issue af…

Fix: 8.7.1+
Fix from $1,950 2024-02-29
Ipad Os HIGH 7.8
CVE-2023-42942

This issue was addressed with improved handling of symlinks. This issue is fixed in watchOS 10.1, macOS Sonoma 14.1, tvOS 17.1, iOS 16.7.2 and iPadOS…

Fix: 10.1 / 13.6.1+
Fix from $1,950 2024-02-21
Azure File Sync MEDIUM 5.3
CVE-2024-21397

Microsoft Azure File Sync Elevation of Privilege Vulnerability

Fix: 16.2.0.0+
Fix from $1,600 2024-02-13
Azure Connected Machine Agent HIGH 7.3
CVE-2024-21329

Azure Connected Machine Agent Elevation of Privilege Vulnerability

Fix: 1.38+
Fix from $1,950 2024-02-13
Nomad HIGH 7.5
CVE-2024-1329

HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file write on the host as the Nomad c…

Fix: 1.5.14 / 1.6.7+
Fix from $1,950 2024-02-08
Display Manager MEDIUM 6.6
CVE-2023-32474

Dell Display Manager application, version 2.1.1.17 and prior, contain an insecure operation on windows junction/mount point. A local malicious user c…

Fix: 2.1.1.21+
Fix from $1,600 2024-02-06
Update Package Framework HIGH 7.1
CVE-2023-32454

DUP framework version 4.9.4.36 and prior contains insecure operation on Windows junction/Mount point vulnerability. A local malicious standard user c…

Fix: after 4.9.4.36
Fix from $1,950 2024-02-06
Engrampa CRITICAL 9.6
CVE-2023-52138

Engrampa is an archive manager for the MATE environment. Engrampa is found to be vulnerable to a Path Traversal vulnerability that can be leveraged t…

Fix: 1.26.2+
Fix from $2,300 2024-02-05
Enterprise Linux MEDIUM 5.3
CVE-2023-7216

A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a…

No fix yet
Fix from $1,600 2024-02-05
Apex One HIGH 7.8
CVE-2023-52090

A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. …

Fix: 14.0.12849+
Fix from $1,950 2024-01-23
Apex One HIGH 7.8
CVE-2023-52091

An anti-spyware engine link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installat…

Fix: 14.0.12849+
Fix from $1,950 2024-01-23
Apex One HIGH 7.8
CVE-2023-52092

A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. …

Fix: 14.0.12849+
Fix from $1,950 2024-01-23
Apex One HIGH 7.8
CVE-2023-52094

An updater link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to abuse the updater to delete an arbitrary fo…

Fix: 14.0.12849+
Fix from $1,950 2024-01-23
Deep Security HIGH 7.8
CVE-2023-52338

A link following vulnerability in the Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent could allow a l…

Mitigation only
Fix from $1,950 2024-01-23
Apex One HIGH 7.8
CVE-2023-47192

An agent link vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations.…

Fix: 14.0.12737+
Fix from $1,950 2024-01-23
Workforce Access HIGH 7.8
CVE-2023-6335

Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on Windows allows User-Controlled Filename.This…

Fix: 8.7+
Fix from $1,950 2024-01-16
Workforce Access HIGH 7.8
CVE-2023-6336

Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows User-Controlled Filename.This i…

Fix: 8.7+
Fix from $1,950 2024-01-16
Paydroid HIGH 7.8
CVE-2023-42137

PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high privileges by us…

Fix: after 8.1.0_sagittarius_11.1.50_20230614
Fix from $1,950 2024-01-15
Security Verify Access HIGH 7.8
CVE-2023-31003

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1)…

Fix: 10.0.0.7+
Fix from $1,950 2024-01-11
Visual Studio HIGH 7.8
CVE-2024-20656

Visual Studio Elevation of Privilege Vulnerability

Fix: 15.9.59 / 16.11.33+
Fix from $1,950 2024-01-09
Anti Malware Engine HIGH 7.8
CVE-2024-0206

A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local user to pot…

Mitigation only
Fix from $1,950 2024-01-09
Iprint\&scan MEDIUM 5.5
CVE-2023-51654

Improper link resolution before file access ('Link Following') issue exists in iPrint&Scan Desktop for Windows versions 11.0.0 and earlier. A symlink…

Fix: after 11.0.0
Fix from $1,600 2023-12-26
Secure Enterprise Client HIGH 8.8
CVE-2023-28872

Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privileges by creating a symbolic li…

Fix: 13.10+
Fix from $1,950 2023-12-25