Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Tablet Driver Installer HIGH 7.8
CVE-2023-27529

Wacom Tablet Driver installer prior to 6.4.2-1 (for macOS) contains an improper link resolution before file access vulnerability. When a user is tric…

Fix: 6.4.2-1+
Fix from $1,950 2023-05-25
Windows Sysmon HIGH 7.8
CVE-2023-29343

SysInternals Sysmon for Windows Elevation of Privilege Vulnerability

Fix: 14.16+
Fix from $1,950 2023-05-09
Desktop HIGH 7.1
CVE-2022-34292

Docker Desktop for Windows before 4.6.0 allows attackers to overwrite any file through a symlink attack on the hyperv/create dockerBackendV2 API by c…

Fix: 4.6.0+
Fix from $1,950 2023-04-27
Desktop MEDIUM 6.3
CVE-2022-38730

Docker Desktop for Windows before 4.6 allows attackers to overwrite any file through the windowscontainers/start dockerBackendV2 API by controlling t…

Fix: 4.6.0+
Fix from $1,600 2023-04-27
Desktop HIGH 7.1
CVE-2022-31647

Docker Desktop before 4.6.0 on Windows allows attackers to delete any file through the hyperv/destroy dockerBackendV2 API via a symlink in the DataFo…

Fix: 4.6.0+
Fix from $1,950 2023-04-27
Cloud Agent MEDIUM 6.3
CVE-2023-28141

An NTFS Junction condition exists in the Qualys Cloud Agent for Windows platform in versions before 4.8.0.31. Attackers may write files to arbitrary …

Fix: 4.8.0.31+
Fix from $1,600 2023-04-18
Junos MEDIUM 6.8
CVE-2023-28972

An Improper Link Resolution Before File Access vulnerability in console port access of Juniper Networks Junos OS on NFX Series allows an attacker to …

Mitigation only
Fix from $1,600 2023-04-17
Windows 10 1507 HIGH 7.1
CVE-2023-28222

Windows Kernel Elevation of Privilege Vulnerability

Fix: 10.0.10240.19869 / 10.0.14393.5850+
Fix from $1,950 2023-04-11
Driver HIGH 7.3
CVE-2022-38604

Wacom Driver 6.3.46-1 for Windows and lower was discovered to contain an arbitrary file deletion vulnerability.

No fix yet
Fix from $1,950 2023-04-11
Driver MEDIUM 5.9
CVE-2022-43293

Wacom Driver 6.3.46-1 for Windows was discovered to contain an arbitrary file write vulnerability via the component \Wacom\Wacom_Tablet.exe.

No fix yet
Fix from $1,600 2023-04-11
Warp HIGH 7.8
CVE-2023-0652

Due to a hardlink created in the ProgramData folder during the repair process of the software, the installer (MSI) of WARP Client for Windows (<= 202…

Fix: 2023.3.381.0+
Fix from $1,950 2023-04-06
Warp HIGH 7.8
CVE-2023-1412

An unprivileged (non-admin) user can exploit an Improper Access Control vulnerability in the Cloudflare WARP Client for Windows (<= 2022.12.582.0) to…

Fix: 2023.3.381.0+
Fix from $1,950 2023-04-05
Emc Powerscale Onefs HIGH 7.8
CVE-2023-25940

Dell PowerScale OneFS version 9.5.0.0 contains improper link resolution before file access vulnerability in isi_gather_info. A high privileged local …

Patch available
Fix from $1,950 2023-04-04
Cs141 Firmware HIGH 7.5
CVE-2022-47188

There is an arbitrary file reading vulnerability in Generex UPS CS141 below 2.06 version. An attacker, making use of the default credentials, could u…

Fix: 2.06+
Fix from $1,950 2023-03-31
Runc HIGH 7.8
CVE-2023-28642

runc is a CLI tool for spawning and running containers according to the OCI specification. It was found that AppArmor can be bypassed when `/proc` in…

Fix: 1.1.5+
Fix from $1,950 2023-03-29
Adwcleaner HIGH 7.8
CVE-2023-28892

Malwarebytes AdwCleaner 8.4.0 runs as Administrator and performs an insecure file delete operation on C:\AdwCleaner\Logs\AdwCleaner_Debug.log in whic…

Fix: after 8.4.0
Fix from $1,950 2023-03-29
Malwarebytes HIGH 7.8
CVE-2023-26088

In Malwarebytes before 4.5.23, a symbolic link may be used delete any arbitrary file on the system by exploiting the local quarantine system. It can …

Fix: 4.5.23+
Fix from $1,950 2023-03-23
Cloudflared HIGH 7.8
CVE-2023-1314

A vulnerability has been discovered in cloudflared's installer (<= 2023.3.0) for Windows 32-bits devices that allows a local attacker with no adminis…

Fix: 2023.3.1+
Fix from $1,950 2023-03-21
Onedrive HIGH 7.8
CVE-2023-24930

Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability

Fix: 23.020.0125.0002+
Fix from $1,950 2023-03-14
Total Protection MEDIUM 5.5
CVE-2023-24577

McAfee Total Protection prior to 16.0.50 allows attackers to elevate user privileges due to Improper Link Resolution via registry keys. This could en…

Fix: 16.0.50+
Fix from $1,600 2023-03-13
Apex One HIGH 7.8
CVE-2023-25145

A link following vulnerability in the scanning function of Trend Micro Apex One agent could allow a local attacker to escalate privileges on affected…

Fix: 14.0.11960+
Fix from $1,950 2023-03-10
Apex One HIGH 7.8
CVE-2023-25146

A security agent link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to quarantine a file, delete the origina…

Fix: 14.0.11960+
Fix from $1,950 2023-03-10
Apex One HIGH 7.8
CVE-2023-25148

A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to exploit the vulnerability by changing a specifi…

Fix: 14.0.11960+
Fix from $1,950 2023-03-10
Rax30 Firmware MEDIUM 6.8
CVE-2023-27850

NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a file sharing mechanism that allows users with access to this feature to access arbitrar…

Fix: 1.0.10.94+
Fix from $1,600 2023-03-10
Mac Os X MEDIUM 5.5
CVE-2022-22582EPSS 18%

A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Securit…

Fix: 11.6.5 / 12.3+
Fix from $1,600 2023-02-27
Razer Central HIGH 7.8
CVE-2022-45697

Arbitrary File Delete vulnerability in Razer Central before v7.8.0.381 when handling files in the Accounts directory.

Fix: 7.8.0.381+
Fix from $1,950 2023-02-27
Eternal Terminal MEDIUM 6.3
CVE-2023-23558

In Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp. For example, a local attacker can create /tmp/.sentry-native-etserver with mode…

Patch available
Fix from $1,600 2023-02-16
Visual Studio 2017 MEDIUM 5.6
CVE-2023-21567

Visual Studio Denial of Service Vulnerability

Fix: 15.9.52 / 16.11.24+
Fix from $1,600 2023-02-14
Git MEDIUM 5.5
CVE-2023-22490

Git is a revision control system. Using a specially-crafted repository, Git prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7,…

Fix: 2.30.8 / 2.31.7+
Fix from $1,600 2023-02-14
.net Framework MEDIUM 5.0
CVE-2023-21722

.NET Framework Denial of Service Vulnerability

Patch available
Fix from $1,600 2023-02-14