Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Driver HIGH 7.8
CVE-2023-32163

Wacom Drivers for Windows Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges o…

Mitigation only
Fix from $1,950 2023-09-06
Cyber Protect Home Office HIGH 7.8
CVE-2022-46869

Local privilege escalation during installation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Home Of…

Fix: 40278+
Fix from $1,950 2023-08-31
La5570 Firmware HIGH 7.5
CVE-2023-34723

An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows attackers to gain sensitive information via /config/system.conf.

No fix yet
Fix from $1,950 2023-08-25
Chrome HIGH 7.8
CVE-2019-13689

Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform arbitrary read/write via a…

Fix: 75.0.3770.80+
Fix from $1,950 2023-08-25
Ghost MEDIUM 6.5
CVE-2023-40028EPSS 68%

Ghost is an open source content management system. Versions prior to 5.59.1 are subject to a vulnerability which allows authenticated users to upload…

Fix: 5.59.1+
Fix from $1,600 2023-08-15
Windows Defender HIGH 7.8
CVE-2023-38175

Microsoft Windows Defender Elevation of Privilege Vulnerability

Fix: 1.1.23060.3001+
Fix from $1,950 2023-08-08
Windows 10 CRITICAL 9.8
CVE-2023-36903

Windows System Assessment Tool Elevation of Privilege Vulnerability

Fix: 10.0.10240.20107 / 10.0.14393.6167+
Fix from $2,300 2023-08-08
Unrar HIGH 7.5
CVE-2022-48579

UnRAR before 6.2.3 allows extraction of files outside of the destination folder via symlink chains.

Fix: 6.2.3+
Fix from $1,950 2023-08-07
Nomachine CRITICAL 9.1
CVE-2023-39107

An arbitrary file overwrite vulnerability in NoMachine Free Edition and Enterprise Client for macOS before v8.8.1 allows attackers to overwrite root-…

Fix: 8.8.1+
Fix from $2,300 2023-08-04
Firefox MEDIUM 6.5
CVE-2023-4052

The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, any files in that directory would be recursively…

Fix: 115.1 / 116.0+
Fix from $1,600 2023-08-01
Firefox MEDIUM 6.5
CVE-2023-4053

A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This co…

Fix: 116.0+
Fix from $1,600 2023-08-01
Windows 10 1507 HIGH 7.8
CVE-2023-36874 KEVEPSS 43%

Windows Error Reporting Service Elevation of Privilege Vulnerability

Fix: 10.0.10240.20048 / 10.0.14393.6085+
Fix from $1,950 2023-07-11
Windows 10 21h2 HIGH 7.1
CVE-2023-35347

Microsoft Install Service Elevation of Privilege Vulnerability

Fix: 10.0.19041.3208 / 10.0.19045.3208+
Fix from $1,950 2023-07-11
Windows 10 1607 HIGH 7.8
CVE-2023-35353

Connected User Experiences and Telemetry Elevation of Privilege Vulnerability

Fix: 10.0.14393.6085 / 10.0.17763.4645+
Fix from $1,950 2023-07-11
Windows 10 1507 HIGH 7.8
CVE-2023-35342

Windows Image Acquisition Elevation of Privilege Vulnerability

Fix: 10.0.10240.20048 / 10.0.14393.6085+
Fix from $1,950 2023-07-11
Windows 10 1607 HIGH 7.8
CVE-2023-35320

Connected User Experiences and Telemetry Elevation of Privilege Vulnerability

Fix: 10.0.14393.6085 / 10.0.17763.4645+
Fix from $1,950 2023-07-11
365 Apps HIGH 7.8
CVE-2023-33148

Microsoft Office Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2023-07-11
Windows 10 1507 HIGH 7.8
CVE-2023-32053

Windows Installer Elevation of Privilege Vulnerability

Fix: 10.0.10240.20048 / 10.0.14393.6085+
Fix from $1,950 2023-07-11
Windows 10 1809 CRITICAL 9.8
CVE-2023-32056

Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability

Fix: 10.0.17763.4645 / 10.0.19041.3208+
Fix from $2,300 2023-07-11
Firefox MEDIUM 6.5
CVE-2023-37206

Uploading files which contain symlinks may have allowed an attacker to trick a user into submitting sensitive data to a malicious website. This vulne…

Fix: 115.0+
Fix from $1,600 2023-07-05
Anti Exploit HIGH 7.1
CVE-2023-27469

Malwarebytes Anti-Exploit 4.4.0.220 is vulnerable to arbitrary file deletion and denial of service via an ALPC message in which FullFileNamePath lack…

Fix: after 4.4.0.220
Fix from $1,950 2023-06-30
Apex One MEDIUM 5.5
CVE-2023-32556

A link following vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to disclose sensitive informa…

Fix: 14.0.12105+
Fix from $1,600 2023-06-26
Alienware Update HIGH 7.3
CVE-2023-28065

Dell Command | Update, Dell Update, and Alienware Update versions 4.8.0 and prior contain an Insecure Operation on Windows Junction / Mount Point vul…

Fix: 4.9.0+
Fix from $1,950 2023-06-23
Alienware Update HIGH 7.1
CVE-2023-28071

Dell Command | Update, Dell Update, and Alienware Update versions 4.9.0, A01 and prior contain an Insecure Operation on Windows Junction / Mount Poin…

Fix: 4.9.0+
Fix from $1,950 2023-06-23
Windows 10 21h2 HIGH 7.8
CVE-2023-32012

Windows Container Manager Service Elevation of Privilege Vulnerability

Fix: 10.0.19044.3087 / 10.0.19045.3087+
Fix from $1,950 2023-06-14
Windows 10 1507 HIGH 8.1
CVE-2023-29351

Windows Group Policy Elevation of Privilege Vulnerability

Fix: 10.0.10240.19983 / 10.0.14393.5989+
Fix from $1,950 2023-06-14
Renderdoc HIGH 7.8
CVE-2023-33865

RenderDoc before 1.27 allows local privilege escalation via a symlink attack. It relies on the /tmp/RenderDoc directory regardless of ownership.

Fix: 1.27+
Fix from $1,950 2023-06-07
Chrome HIGH 7.8
CVE-2023-2939

Insufficient data validation in Installer in Google Chrome on Windows prior to 114.0.5735.90 allowed a local attacker to perform privilege escalation…

Fix: 114.0.5735.90+
Fix from $1,950 2023-05-30
Minecraft HIGH 8.8
CVE-2023-33245

Minecraft through 1.19 and 1.20 pre-releases before 7 (Java) allow arbitrary file overwrite, and possibly code execution, via crafted world data that…

Fix: after 1.19
Fix from $1,950 2023-05-30
Imapsync MEDIUM 6.5
CVE-2023-34204

imapsync through 2.229 uses predictable paths under /tmp and /var/tmp in its default mode of operation. Both of these are typically world-writable, a…

Fix: after 2.229
Fix from $1,600 2023-05-30