Vulnerability index

Browse CVEs

1,369 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Windows 10 1809 HIGH 7.8
CVE-2026-61358

Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker t…

Fix: 10.0.17763.9115 / 10.0.19044.7663+
Fix from $4,900 2026-08-11
Unclassified HIGH 7.1
CVE-2026-72694

A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can expl…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 5.1
CVE-2025-30240

The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By placing a crafted symbolic li…

No fix yet
Fix from $4,000 2026-08-10
Unclassified HIGH 7.8
CVE-2026-63622

A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnera…

No fix yet
Fix from $4,900 2026-08-10
Unclassified MEDIUM 6.5
CVE-2026-71964

CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component that allows authenticated atta…

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 6.5
CVE-2026-70622

tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read …

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 5.5
CVE-2026-15059

Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.

No fix yet
Fix from $4,000 2026-08-10
Unclassified HIGH 8.8
CVE-2026-19429

Jenkins FilePath.untarFrom() does not validate symlink targets in extracted TAR archives, even in versions patched for CVE-2026-33001 and CVE-2026-70…

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 7.1
CVE-2026-71556

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, st…

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 8.7
CVE-2026-71476

Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx self-hosted HTTP remote cache ex…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 6.3
CVE-2026-19008

A vulnerability was identified in mf-yang openclaw-cn up to 0.2.1. This issue affects the function assertNoSymlinkEscape of the file src/agents/sandb…

No fix yet
Fix from $1,600 2026-08-06
Unclassified CRITICAL 9.1
CVE-2026-20310

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehen…

No fix yet
Fix from $2,300 2026-08-05
Unclassified HIGH 7.8
CVE-2026-12410

Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-privileged attacker to escala…

No fix yet
Fix from $1,950 2026-08-05
Monitor Driver HIGH 7.8
CVE-2026-40717

Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged atta…

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 5.8
CVE-2026-67433

Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In version 6.0.0, the logfile c…

No fix yet
Fix from $1,600 2026-07-29
Unclassified HIGH 7.8
CVE-2026-13268

G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate p…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 6.5
CVE-2026-13723

A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrary files on macOS APFS by expl…

No fix yet
Fix from $1,600 2026-07-29
macOS MEDIUM 5.5
CVE-2026-43765

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An a…

Fix: 14.8.8 / 15.7.8+
Fix from $1,600 2026-07-27
Unclassified CRITICAL 9.2
CVE-2026-12503

Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A6…

No fix yet
Fix from $2,300 2026-07-24
Unclassified MEDIUM 6.3
CVE-2026-16552

A flaw was found in systemd-tmpfiles. When processing a tmpfiles.d configuration entry that writes to a file, systemd-tmpfiles can follow a symbolic …

No fix yet
Fix from $1,600 2026-07-22
Unclassified MEDIUM 5.5
CVE-2026-65065

Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The se…

No fix yet
Fix from $1,600 2026-07-21
Unclassified MEDIUM 6.2
CVE-2026-64613

Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_NOFOLLOW. The segment is created …

No fix yet
Fix from $1,600 2026-07-21
Sparkle MEDIUM 6.1
CVE-2026-47121

Sparkle is a software update framework for macOS. Prior to version 2.9.2, `Autoupdate/SUBinaryDeltaApply.m` enforces `relativePath.pathComponents con…

Fix: 2.9.2+
Fix from $1,600 2026-07-21
Unclassified MEDIUM 6.3
CVE-2026-44509

Rsync is a file-copying tool that uses a delta-transfer algorithm to synchronize remote and local files. In versions prior to 3.4.3, previous bug fix…

No fix yet
Fix from $1,600 2026-07-20
Buildkit HIGH 7.5
CVE-2026-15788

BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cac…

Fix: 0.31.2+
Fix from $1,950 2026-07-20
Unclassified HIGH 8.7
CVE-2026-8170

The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize paths and follow symbolic links …

No fix yet
Fix from $1,950 2026-07-20
Network Ai MEDIUM 5.5
CVE-2026-58414

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recursively collects files using …

Fix: 5.12.2+
Fix from $1,600 2026-07-20
Unclassified MEDIUM 5.3
CVE-2026-16077

A vulnerability was found in AstrBotDevs AstrBot up to 4.25.5. Impacted is the function _normalize_rw_path of the file astrbot/core/tools/computer_to…

No fix yet
Fix from $1,600 2026-07-18
Unclassified HIGH 7.1
CVE-2026-50163

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 validates a hardlink target relat…

No fix yet
Fix from $1,950 2026-07-17
Unclassified MEDIUM 5.9
CVE-2026-53535

Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the git-sync feature clones a user-configured Git repository into a …

No fix yet
Fix from $1,600 2026-07-16