Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Elastic Ci Stack HIGH 7.8
CVE-2023-43116

A symbolic link following vulnerability in Buildkite Elastic CI for AWS versions prior to 6.7.1 and 5.22.5 allows the buildkite-agent user to change …

Fix: 5.22.5 / 6.7.1+
Fix from $1,950 2023-12-22
Windows 11 23h2 HIGH 7.8
CVE-2023-36391EPSS 7%

Local Security Authority Subsystem Service Elevation of Privilege Vulnerability

Fix: 10.0.22631.2861+
Fix from $1,950 2023-12-12
Windows 10 1507 HIGH 7.8
CVE-2023-35633EPSS 9%

Windows Kernel Elevation of Privilege Vulnerability

Fix: 10.0.10240.20345+
Fix from $1,950 2023-12-12
Azure Connected Machine Agent HIGH 7.3
CVE-2023-35624

Azure Connected Machine Agent Elevation of Privilege Vulnerability

Fix: 1.37+
Fix from $1,950 2023-12-12
Secure Enterprise Client HIGH 8.1
CVE-2023-28868

Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to delete arbitrary files on the operating system by creating a symbo…

Fix: 12.22+
Fix from $1,950 2023-12-09
Secure Enterprise Client MEDIUM 6.5
CVE-2023-28869

Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers read the contents of arbitrary files on the operating system by creat…

Fix: 12.22+
Fix from $1,600 2023-12-09
Endpoint Security Suite Enterprise HIGH 7.3
CVE-2023-39246

Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server version prior to 11.8.1 contain an Insecure Operation o…

Fix: 11.8.1+
Fix from $1,950 2023-11-16
Rooms HIGH 7.8
CVE-2023-43590

Link following in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct an escalation of privilege via local access.

Fix: 5.16.0+
Fix from $1,950 2023-11-15
Windows 10 1507 HIGH 7.8
CVE-2023-36705

Windows Installer Elevation of Privilege Vulnerability

Fix: 10.0.10240.20308 / 10.0.14393.6452+
Fix from $1,950 2023-11-14
Windows 11 21h2 HIGH 7.1
CVE-2023-36399EPSS 8%

Windows Storage Elevation of Privilege Vulnerability

Fix: 10.0.22000.2600 / 10.0.22621.2715+
Fix from $1,950 2023-11-14
Windows 10 1507 HIGH 7.0
CVE-2023-36394EPSS 7%

Windows Search Service Elevation of Privilege Vulnerability

Fix: 10.0.10240.20308 / 10.0.14393.6452+
Fix from $1,950 2023-11-14
Windows 10 1809 HIGH 7.8
CVE-2023-36047

Windows Authentication Elevation of Privilege Vulnerability

Fix: 10.0.17763.5122 / 10.0.19041.3693+
Fix from $1,950 2023-11-14
Windows 11 21h2 HIGH 7.1
CVE-2023-36046

Windows Authentication Denial of Service Vulnerability

Fix: 10.0.22000.2600 / 10.0.22621.2715+
Fix from $1,950 2023-11-14
Froxlor HIGH 8.8
CVE-2023-6069

Improper Link Resolution Before File Access in GitHub repository froxlor/froxlor prior to 2.1.0.

Fix: 2.1.0+
Fix from $1,950 2023-11-10
Swtpm HIGH 7.1
CVE-2020-28407

In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file…

Fix: 0.4.2+
Fix from $1,950 2023-11-03
Vagrant HIGH 7.8
CVE-2023-5834

HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, introducing potential for unauth…

Fix: 2.4.0+
Fix from $1,950 2023-10-27
Tvip 10000 Firmware HIGH 7.5
CVE-2018-17559

Due to incorrect access control, unauthenticated remote attackers can view the /video.mjpg video stream of certain ABUS TVIP cameras.

No fix yet
Fix from $1,950 2023-10-26
macOS HIGH 7.5
CVE-2023-42844

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. A…

Fix: 12.7.1 / 13.6.1+
Fix from $1,950 2023-10-25
Cloudbees Cd HIGH 8.1
CVE-2023-46654

Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the expected directory during the cleanup process of th…

Fix: after 1.1.32
Fix from $1,950 2023-10-25
Cloudbees Cd MEDIUM 6.5
CVE-2023-46655

Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the directory from which artifacts are published during…

Fix: after 1.1.32
Fix from $1,600 2023-10-25
Client Connector HIGH 7.3
CVE-2023-28797

Zscaler Client Connector for Windows before 4.1 writes/deletes a configuration file inside specific folders on the disk. A malicious user can replace…

Fix: 4.1+
Fix from $1,950 2023-10-23
Azure Network Watcher HIGH 7.8
CVE-2023-36737

Azure Network Watcher VM Agent Elevation of Privilege Vulnerability

Fix: 1.4.2798.3+
Fix from $1,950 2023-10-10
Windows 10 1507 HIGH 7.8
CVE-2023-36711

Windows Runtime C++ Template Library Elevation of Privilege Vulnerability

Fix: 10.0.10240.20232 / 10.0.14393.6351+
Fix from $1,950 2023-10-10
Windows 10 1809 HIGH 7.8
CVE-2023-36723

Windows Container Manager Service Elevation of Privilege Vulnerability

Fix: 10.0.17763.4974 / 10.0.19041.3570+
Fix from $1,950 2023-10-10
365 Apps HIGH 7.0
CVE-2023-36568

Microsoft Office Click-To-Run Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2023-10-10
Client HIGH 8.4
CVE-2023-45159

1E Client installer can perform arbitrary file deletion on protected files.   A non-privileged user could provide a symbolic link or Windows junctio…

Mitigation only
Fix from $1,950 2023-10-05
Ipados MEDIUM 5.5
CVE-2023-41968

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, i…

Fix: 10.0 / 12.7+
Fix from $1,600 2023-09-27
Leap HIGH 7.8
CVE-2023-32182

A Improper Link Resolution Before File Access ('Link Following') vulnerability in SUSE SUSE Linux Enterprise Desktop 15 SP5 postfix, SUSE SUSE Linux …

No fix yet
Fix from $1,950 2023-09-19
Visual Studio 2022 CRITICAL 9.8
CVE-2023-36758

Visual Studio Elevation of Privilege Vulnerability

Fix: after 17.7.4
Fix from $2,300 2023-09-12
Jgit HIGH 8.8
CVE-2023-4759

Arbitrary File Overwrite in Eclipse JGit <= 6.6.0 In Eclipse JGit, all versions <= 6.6.0.202305301015-r, a symbolic link present in a specially craf…

Fix: 5.13.3.202401111512-r / 6.6.0.202305301015+
Fix from $1,950 2023-09-12