Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Windows 10 HIGH 7.1
CVE-2022-21997

Windows Print Spooler Elevation of Privilege Vulnerability

No fix yet
Fix from $1,950 2022-02-09
Windows 10 1507 HIGH 7.8
CVE-2022-21999 KEVEPSS 42%

Windows Print Spooler Elevation of Privilege Vulnerability

Fix: 10.0.10240.19204 / 10.0.14393.4946+
Fix from $1,950 2022-02-09
Juce HIGH 7.8
CVE-2021-23521

This affects the package juce-framework/JUCE before 6.1.5. This vulnerability is triggered when a malicious archive is crafted with an entry containi…

Fix: 6.1.5+
Fix from $1,950 2022-01-31
Factory Watchman HIGH 7.8
CVE-2022-21944

A UNIX Symbolic Link (Symlink) Following vulnerability in the systemd service file for watchman of openSUSE Backports SLE-15-SP3, Factory allows loca…

Fix: after 4.9.1
Fix from $1,950 2022-01-26
Cortex Xdr Agent HIGH 7.1
CVE-2022-0012

An improper link resolution before file access vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables a lo…

Fix: 5.0.12 / 6.1.9+
Fix from $1,950 2022-01-12
Windows 10 1507 HIGH 7.0
CVE-2022-21919 KEV

Windows User Profile Service Elevation of Privilege Vulnerability

Fix: 10.0.10240.19177 / 10.0.14393.4886+
Fix from $1,950 2022-01-11
Windows 10 HIGH 7.8
CVE-2022-21895

Windows User Profile Service Elevation of Privilege Vulnerability

Mitigation only
Fix from $1,950 2022-01-11
Windows 10 HIGH 7.8
CVE-2022-21838

Windows Cleanup Manager Elevation of Privilege Vulnerability

Mitigation only
Fix from $1,950 2022-01-11
Apex One HIGH 7.1
CVE-2021-45442

A link following denial-of-service vulnerability in Trend Micro Worry-Free Business Security (on prem only) could allow a local attacker to overwrite…

Patch available
Fix from $1,950 2022-01-10
Apex One HIGH 7.8
CVE-2021-45231

A link following privilege escalation vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1…

Patch available
Fix from $1,950 2022-01-10
Apex One HIGH 7.1
CVE-2021-44024

A link following denial-of-service vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1 an…

Patch available
Fix from $1,950 2022-01-10
Tew 827dru Firmware MEDIUM 6.8
CVE-2021-20153

Trendnet AC2600 TEW-827DRU version 2.08B01 contains a symlink vulnerability in the bittorrent functionality. If enabled, the bittorrent functionality…

Mitigation only
Fix from $1,600 2021-12-30
Iris HIGH 8.8
CVE-2021-23772

This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12. The unsafe handling of file names …

Fix: after 12.1.8
Fix from $1,950 2021-12-24
Antivirus\+ Security 2021 HIGH 7.1
CVE-2021-44023

A link following denial-of-service (DoS) vulnerability in the Trend Micro Security (Consumer) 2021 familiy of products could allow an attacker to abu…

Fix: after 17.0
Fix from $1,950 2021-12-16
Windows 10 HIGH 7.3
CVE-2021-43237

Windows Setup Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-12-15
Windows 10 HIGH 7.8
CVE-2021-43238

Windows Remote Access Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-12-15
Windows 10 Update Assistant MEDIUM 5.0
CVE-2021-42297

Windows 10 Update Assistant Elevation of Privilege Vulnerability

Patch available
Fix from $1,600 2021-11-24
Quagga HIGH 7.8
CVE-2021-44038

An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-o…

Fix: after 1.2.4
Fix from $1,950 2021-11-19
Codemeter Runtime HIGH 7.1
CVE-2021-41057

In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions.

Fix: 7.30a / 8.0+
Fix from $1,950 2021-11-14
Windows 10 1507 MEDIUM 5.5
CVE-2021-41379 KEVEPSS 20%

Windows Installer Elevation of Privilege Vulnerability

Fix: 10.0.10240.19119 / 10.0.14393.4770+
Fix from $1,600 2021-11-10
Gravityzone MEDIUM 6.1
CVE-2021-3641

Improper Link Resolution Before File Access ('Link Following') vulnerability in the EPAG component of Bitdefender Endpoint Security Tools for Windows…

Fix: after 7.1.2.33
Fix from $1,600 2021-11-09
Jenkins HIGH 8.1
CVE-2021-21686

File path filters in the agent-to-controller security subsystem of Jenkins 2.318 and earlier, LTS 2.303.2 and earlier do not canonicalize paths, allo…

Fix: 2.303.3 / 2.319+
Fix from $1,950 2021-11-04
Jenkins CRITICAL 9.8
CVE-2021-21691

Creating symbolic links is possible without the 'symlink' agent-to-controller access control permission in Jenkins 2.318 and earlier, LTS 2.303.2 and…

Fix: 2.303.3 / 2.319+
Fix from $2,300 2021-11-04
Jenkins HIGH 8.8
CVE-2021-21695

FilePath#listFiles lists files outside directories that agents are allowed to access when following symbolic links in Jenkins 2.318 and earlier, LTS …

Fix: 2.303.3 / 2.319+
Fix from $1,950 2021-11-04
Emui HIGH 7.5
CVE-2021-22488

There is an Unauthorized file access vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability by modifying soft links may tam…

Mitigation only
Fix from $1,950 2021-10-28
Chrome HIGH 7.8
CVE-2021-37969

Inappropriate implementation in Google Updater in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to perform local privilege…

Fix: 94.0.4606.54+
Fix from $1,950 2021-10-08
Supportassist Client Consumer HIGH 7.1
CVE-2021-36286

Dell SupportAssist Client Consumer versions 3.9.13.0 and any versions prior to 3.9.13.0 contain an arbitrary file deletion vulnerability that can be …

Fix: after 3.9.13.0
Fix from $1,950 2021-09-28
Meetings HIGH 7.8
CVE-2021-34408

The Zoom Client for Meetings for Windows in all versions before version 5.3.2 writes log files to a user writable directory as a privileged user duri…

Fix: 5.3.2+
Fix from $1,950 2021-09-27
Sd Wan HIGH 7.1
CVE-2021-1612

A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to overwrite arbitrary files on the local system…

Fix: 17.3.4+
Fix from $1,950 2021-09-23
Endpoint Security HIGH 7.8
CVE-2021-31843

Improper privileges management vulnerability in McAfee Endpoint Security (ENS) Windows prior to 10.7.0 September 2021 Update allows local users to ac…

Fix: 10.7.0+
Fix from $1,950 2021-09-17